
Sign up to save your podcasts
Or


In this episode, I sit down with security researcher Katie Knowles to unpack the hidden layers of identity systems inside Microsoft Entra. We get into real-world attack paths like backdooring service principals, restricted administrative units that can accidentally create unstoppable accounts, and OAuth phishing in Copilot Studio.
Katie also shares how she approaches deep technical research, what defenders often overlook, and why identity security is only becoming more complex. This is one of those conversations where you walk away thinking differently.
Subscribe with your favorite podcast player or watch on YouTube ๐
About Katie Knowles
Katie Knowles is a Senior Security Researcher at Datadog specializing in Microsoft Azure and Entra ID security. She has extensive experience across security engineering, penetration testing, and incident response. Katie is known for her thorough research that connects complex technical vulnerabilities to practical defensive guidance, publishing regularly on Datadog Security Labs and speaking at major security conferences.
LinkedIn - https://www.linkedin.com/in/kaknowles/
๐ Related Links
* Katieโs Datadog security posts - https://securitylabs.datadoghq.com/articles/?author=Katie_Knowles
* Katieโs personal blog - https://kknowl.es
* Katieโs conference talks - https://kknowl.es/external-content/
* Creating immutable users through a bug in Entra ID restricted administrative units - https://securitylabs.datadoghq.com/articles/creating-immutable-users-entra-id-administrative-units/
* I SPy: Escalating to Entra IDโs Global Admin with a first-party app - https://securitylabs.datadoghq.com/articles/i-spy-escalating-to-entra-id-global-admin/
* CoPhish: Using Microsoft Copilot Studio as a wrapper for OAuth phishing - https://securitylabs.datadoghq.com/articles/cophish-using-microsoft-copilot-studio-as-a-wrapper/
๐ Chapters
02:08 The Immortal User Bug in Restricted Admin Units
04:23 Attacker Impact: The Un-deletable Malicious Account
05:59 Hacking First-Party Apps & Bypassing AppLock
09:29 How She Found the AppLock Bypass
11:16 A Day in the Life of a Security Researcher
14:20 Phishing with Copilot Studio & OAuth
17:00 Top Tips for App Governance & Security
21:45 The Hidden Risk of Azure Key Vault Access Policies
28:55 App Registrations vs. Service Principals Explained
41:48 The Future: Agent IDs & The New Trust Model
Podcast Apps
๐๏ธ Entra.Chat - https://entra.chat
๐ง Apple Podcast โ https://entra.chat/apple
๐บ YouTube โ https://entra.chat/youtube
๐บ Spotify โ https://entra.chat/spotify
๐ง Overcast โ https://entra.chat/overcast
๐ง Pocketcast โ https://entra.chat/pocketcast
๐ง Others โ https://entra.chat/rss
Merillโs socials
๐บ YouTube โ youtube.com/@merillx
๐ LinkedIn โ linkedin.com/in/merill
๐ค Twitter โ twitter.com/merill
๐บ TikTok โ tiktok.com/@merillf
๐ฆ Bluesky โ bsky.app/profile/merill.net
๐ Mastodon โ infosec.exchange/@merill
๐งต Threads โ threads.net/@merillf
๐ค GitHub โ github.com/merill
By Merill Fernando5
44 ratings
In this episode, I sit down with security researcher Katie Knowles to unpack the hidden layers of identity systems inside Microsoft Entra. We get into real-world attack paths like backdooring service principals, restricted administrative units that can accidentally create unstoppable accounts, and OAuth phishing in Copilot Studio.
Katie also shares how she approaches deep technical research, what defenders often overlook, and why identity security is only becoming more complex. This is one of those conversations where you walk away thinking differently.
Subscribe with your favorite podcast player or watch on YouTube ๐
About Katie Knowles
Katie Knowles is a Senior Security Researcher at Datadog specializing in Microsoft Azure and Entra ID security. She has extensive experience across security engineering, penetration testing, and incident response. Katie is known for her thorough research that connects complex technical vulnerabilities to practical defensive guidance, publishing regularly on Datadog Security Labs and speaking at major security conferences.
LinkedIn - https://www.linkedin.com/in/kaknowles/
๐ Related Links
* Katieโs Datadog security posts - https://securitylabs.datadoghq.com/articles/?author=Katie_Knowles
* Katieโs personal blog - https://kknowl.es
* Katieโs conference talks - https://kknowl.es/external-content/
* Creating immutable users through a bug in Entra ID restricted administrative units - https://securitylabs.datadoghq.com/articles/creating-immutable-users-entra-id-administrative-units/
* I SPy: Escalating to Entra IDโs Global Admin with a first-party app - https://securitylabs.datadoghq.com/articles/i-spy-escalating-to-entra-id-global-admin/
* CoPhish: Using Microsoft Copilot Studio as a wrapper for OAuth phishing - https://securitylabs.datadoghq.com/articles/cophish-using-microsoft-copilot-studio-as-a-wrapper/
๐ Chapters
02:08 The Immortal User Bug in Restricted Admin Units
04:23 Attacker Impact: The Un-deletable Malicious Account
05:59 Hacking First-Party Apps & Bypassing AppLock
09:29 How She Found the AppLock Bypass
11:16 A Day in the Life of a Security Researcher
14:20 Phishing with Copilot Studio & OAuth
17:00 Top Tips for App Governance & Security
21:45 The Hidden Risk of Azure Key Vault Access Policies
28:55 App Registrations vs. Service Principals Explained
41:48 The Future: Agent IDs & The New Trust Model
Podcast Apps
๐๏ธ Entra.Chat - https://entra.chat
๐ง Apple Podcast โ https://entra.chat/apple
๐บ YouTube โ https://entra.chat/youtube
๐บ Spotify โ https://entra.chat/spotify
๐ง Overcast โ https://entra.chat/overcast
๐ง Pocketcast โ https://entra.chat/pocketcast
๐ง Others โ https://entra.chat/rss
Merillโs socials
๐บ YouTube โ youtube.com/@merillx
๐ LinkedIn โ linkedin.com/in/merill
๐ค Twitter โ twitter.com/merill
๐บ TikTok โ tiktok.com/@merillf
๐ฆ Bluesky โ bsky.app/profile/merill.net
๐ Mastodon โ infosec.exchange/@merill
๐งต Threads โ threads.net/@merillf
๐ค GitHub โ github.com/merill

371 Listeners

376 Listeners

638 Listeners

232 Listeners

1,021 Listeners

64 Listeners

177 Listeners

314 Listeners

189 Listeners

74 Listeners

9 Listeners

23 Listeners

136 Listeners

15 Listeners

46 Listeners