Entra.Chat

Hacking Entra ID: Bypassing AppLocks & Creating โ€˜Immortalโ€™ Users


Listen Later

In this episode, I sit down with security researcher Katie Knowles to unpack the hidden layers of identity systems inside Microsoft Entra. We get into real-world attack paths like backdooring service principals, restricted administrative units that can accidentally create unstoppable accounts, and OAuth phishing in Copilot Studio.

Katie also shares how she approaches deep technical research, what defenders often overlook, and why identity security is only becoming more complex. This is one of those conversations where you walk away thinking differently.

Subscribe with your favorite podcast player or watch on YouTube ๐Ÿ‘‡

About Katie Knowles

Katie Knowles is a Senior Security Researcher at Datadog specializing in Microsoft Azure and Entra ID security. She has extensive experience across security engineering, penetration testing, and incident response. Katie is known for her thorough research that connects complex technical vulnerabilities to practical defensive guidance, publishing regularly on Datadog Security Labs and speaking at major security conferences.

LinkedIn - https://www.linkedin.com/in/kaknowles/

๐Ÿ”— Related Links

* Katieโ€™s Datadog security posts - https://securitylabs.datadoghq.com/articles/?author=Katie_Knowles

* Katieโ€™s personal blog - https://kknowl.es

* Katieโ€™s conference talks - https://kknowl.es/external-content/

* Creating immutable users through a bug in Entra ID restricted administrative units - https://securitylabs.datadoghq.com/articles/creating-immutable-users-entra-id-administrative-units/

* I SPy: Escalating to Entra IDโ€™s Global Admin with a first-party app - https://securitylabs.datadoghq.com/articles/i-spy-escalating-to-entra-id-global-admin/

* CoPhish: Using Microsoft Copilot Studio as a wrapper for OAuth phishing - https://securitylabs.datadoghq.com/articles/cophish-using-microsoft-copilot-studio-as-a-wrapper/

๐Ÿ“— Chapters

02:08 The Immortal User Bug in Restricted Admin Units

04:23 Attacker Impact: The Un-deletable Malicious Account

05:59 Hacking First-Party Apps & Bypassing AppLock

09:29 How She Found the AppLock Bypass

11:16 A Day in the Life of a Security Researcher

14:20 Phishing with Copilot Studio & OAuth

17:00 Top Tips for App Governance & Security

21:45 The Hidden Risk of Azure Key Vault Access Policies

28:55 App Registrations vs. Service Principals Explained

41:48 The Future: Agent IDs & The New Trust Model

Podcast Apps

๐ŸŽ™๏ธ Entra.Chat - https://entra.chat

๐ŸŽง Apple Podcast โ†’ https://entra.chat/apple

๐Ÿ“บ YouTube โ†’ https://entra.chat/youtube

๐Ÿ“บ Spotify โ†’ https://entra.chat/spotify

๐ŸŽง Overcast โ†’ https://entra.chat/overcast

๐ŸŽง Pocketcast โ†’ https://entra.chat/pocketcast

๐ŸŽง Others โ†’ https://entra.chat/rss

Merillโ€™s socials

๐Ÿ“บ YouTube โ†’ youtube.com/@merillx

๐Ÿ‘” LinkedIn โ†’ linkedin.com/in/merill

๐Ÿค Twitter โ†’ twitter.com/merill

๐Ÿ•บ TikTok โ†’ tiktok.com/@merillf

๐Ÿฆ‹ Bluesky โ†’ bsky.app/profile/merill.net

๐Ÿ˜ Mastodon โ†’ infosec.exchange/@merill

๐Ÿงต Threads โ†’ threads.net/@merillf

๐Ÿค– GitHub โ†’ github.com/merill



Get full access to Entra.News - Your weekly dose of Microsoft Entra at entra.news/subscribe
...more
View all episodesView all episodes
Download on the App Store

Entra.ChatBy Merill Fernando

  • 5
  • 5
  • 5
  • 5
  • 5

5

4 ratings


More shows like Entra.Chat

View all
Defensive Security Podcast - Malware, Hacking, Cyber Security & Infosec by Jerry Bell and Andrew Kalat

Defensive Security Podcast - Malware, Hacking, Cyber Security & Infosec

371 Listeners

Risky Business by Patrick Gray

Risky Business

376 Listeners

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast) by Johannes B. Ullrich

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

638 Listeners

The Amp Hour Electronics Podcast by The Amp Hour (Chris Gammell and David L Jones)

The Amp Hour Electronics Podcast

232 Listeners

CyberWire Daily by N2K Networks

CyberWire Daily

1,021 Listeners

Microsoft Cloud IT Pro Podcast by Ben Stegink, Scott Hoag

Microsoft Cloud IT Pro Podcast

64 Listeners

Cybersecurity Today by Jim Love

Cybersecurity Today

177 Listeners

Hacking Humans by N2K Networks

Hacking Humans

314 Listeners

CISO Series Podcast by David Spark, Mike Johnson, and Andy Ellis

CISO Series Podcast

189 Listeners

Defense in Depth by David Spark, Steve Zalewski, Geoff Belknap

Defense in Depth

74 Listeners

Practical 365 Podcast - Microsoft 365, Copilot & Cybersecurity News & Discussions by Practical 365

Practical 365 Podcast - Microsoft 365, Copilot & Cybersecurity News & Discussions

9 Listeners

The Azure Security Podcast by Michael Howard, Sarah Young, Gladys Rodriguez and Mark Simos

The Azure Security Podcast

23 Listeners

Cyber Security Headlines by CISO Series

Cyber Security Headlines

136 Listeners

Blue Security by Andy Jaw & Adam Brewer

Blue Security

15 Listeners

Risky Bulletin by risky.biz

Risky Bulletin

46 Listeners