Entra.Chat

I found a bug that could hack ANY Microsoft 365 tenant - Here's what happened


Listen Later

In this episode, I chat with Dirk-jan Mollema, the legendary researcher behind some of the most important discoveries in Microsoft identity security.

We go deep into how curiosity led him from tinkering with web tools to uncovering one of the biggest Entra ID vulnerabilities ever found.

He shares the story behind the CVE that rocked the cloud world, the stress of realizing what heโ€™d uncovered, and the mindset that drives his relentless research. If youโ€™ve ever wondered what it feels like to find a bug that could break the internetโ€”this oneโ€™s for you.

PS: If you like this episode please leave a review on Apple Podcast or Spotify ๐Ÿ™

Subscribe with your favorite podcast player or watch on YouTube ๐Ÿ‘‡

About Dirk-jan Mollema

Dirk-Jan Mollema is a security researcher and consultant specializing in Microsoft Entra ID (Azure AD) and Active Directory security. He is the creator of popular offensive security tools including ROADtools and ROADrecon.

With seven years of Entra research and nearly a decade in AD security, Dirk-Jan has discovered numerous critical vulnerabilities and has played an important role in helping improve Microsoftโ€™s cloud security posture. He provides training and consulting services through his company Outsider Security.

Twitter โ†’ https://twitter.com/_dirkjan

LinkedIn โ†’ https://www.linkedin.com/in/dirkjanm

Contact โ†’ https://outsidersecurity.nl

๐Ÿ”— Related Links

* One Token to rule them all - obtaining Global Admin in every Entra ID tenant via Actor tokens - https://dirkjanm.io/obtaining-global-admin-in-every-entra-id-tenant-with-actor-tokens

* Dirk-Janโ€™s Blog - https://dirkjanm.io

* ROADtools - https://github.com/dirkjanm/ROADtools

๐Ÿ“— Chapters

00:00 Intro

02:11 Guest Journey into Security

07:13 Building ROADtools and ROADrecon

09:53 Research Tools & Methods

14:05 Top Discoveries Ranked

17:01 Windows Hello & PRT Deep Dive

26:07 The Cross-Tenant Actor Token Bug

35:34 Ethical Dilemmas of Big Finds

38:24 Disclosure, Impact & Community

45:59 Future Research & Intune Tips

53:58 Training, Consulting & Closing

Podcast Apps

๐ŸŽ™๏ธ Entra.Chat - https://entra.chat

๐ŸŽง Apple Podcast โ†’ https://entra.chat/apple

๐Ÿ“บ YouTube โ†’ https://entra.chat/youtube

๐Ÿ“บ Spotify โ†’ https://entra.chat/spotify

๐ŸŽง Overcast โ†’ https://entra.chat/overcast

๐ŸŽง Pocketcast โ†’ https://entra.chat/pocketcast

๐ŸŽง Others โ†’ https://entra.chat/rss

Merillโ€™s socials

๐Ÿ“บ YouTube โ†’ youtube.com/@merillx

๐Ÿ‘” LinkedIn โ†’ linkedin.com/in/merill

๐Ÿค Twitter โ†’ twitter.com/merill

๐Ÿ•บ TikTok โ†’ tiktok.com/@merillf

๐Ÿฆ‹ Bluesky โ†’ bsky.app/profile/merill.net

๐Ÿ˜ Mastodon โ†’ infosec.exchange/@merill

๐Ÿงต Threads โ†’ threads.net/@merillf

๐Ÿค– GitHub โ†’ github.com/merill



Get full access to Entra.News - Your weekly dose of Microsoft Entra at entra.news/subscribe
...more
View all episodesView all episodes
Download on the App Store

Entra.ChatBy Merill Fernando

  • 5
  • 5
  • 5
  • 5
  • 5

5

4 ratings


More shows like Entra.Chat

View all
Defensive Security Podcast - Malware, Hacking, Cyber Security & Infosec by Jerry Bell and Andrew Kalat

Defensive Security Podcast - Malware, Hacking, Cyber Security & Infosec

371 Listeners

Risky Business by Patrick Gray

Risky Business

376 Listeners

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast) by Johannes B. Ullrich

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

652 Listeners

The Amp Hour Electronics Podcast by The Amp Hour (Chris Gammell and David L Jones)

The Amp Hour Electronics Podcast

232 Listeners

CyberWire Daily by N2K Networks

CyberWire Daily

1,022 Listeners

Microsoft Cloud IT Pro Podcast by Ben Stegink, Scott Hoag

Microsoft Cloud IT Pro Podcast

64 Listeners

Cybersecurity Today by Jim Love

Cybersecurity Today

177 Listeners

Hacking Humans by N2K Networks

Hacking Humans

314 Listeners

CISO Series Podcast by David Spark, Mike Johnson, and Andy Ellis

CISO Series Podcast

189 Listeners

Defense in Depth by David Spark, Steve Zalewski, Geoff Belknap

Defense in Depth

74 Listeners

Practical 365 Podcast - Microsoft 365, Copilot & Cybersecurity News & Discussions by Practical 365

Practical 365 Podcast - Microsoft 365, Copilot & Cybersecurity News & Discussions

9 Listeners

The Azure Security Podcast by Michael Howard, Sarah Young, Gladys Rodriguez and Mark Simos

The Azure Security Podcast

23 Listeners

Cyber Security Headlines by CISO Series

Cyber Security Headlines

136 Listeners

Blue Security by Andy Jaw & Adam Brewer

Blue Security

15 Listeners

Risky Bulletin by risky.biz

Risky Bulletin

46 Listeners