
Sign up to save your podcasts
Or


In this episode, I chat with Dirk-jan Mollema, the legendary researcher behind some of the most important discoveries in Microsoft identity security.
We go deep into how curiosity led him from tinkering with web tools to uncovering one of the biggest Entra ID vulnerabilities ever found.
He shares the story behind the CVE that rocked the cloud world, the stress of realizing what heโd uncovered, and the mindset that drives his relentless research. If youโve ever wondered what it feels like to find a bug that could break the internetโthis oneโs for you.
PS: If you like this episode please leave a review on Apple Podcast or Spotify ๐
Subscribe with your favorite podcast player or watch on YouTube ๐
About Dirk-jan Mollema
Dirk-Jan Mollema is a security researcher and consultant specializing in Microsoft Entra ID (Azure AD) and Active Directory security. He is the creator of popular offensive security tools including ROADtools and ROADrecon.
With seven years of Entra research and nearly a decade in AD security, Dirk-Jan has discovered numerous critical vulnerabilities and has played an important role in helping improve Microsoftโs cloud security posture. He provides training and consulting services through his company Outsider Security.
Twitter โ https://twitter.com/_dirkjan
LinkedIn โ https://www.linkedin.com/in/dirkjanm
Contact โ https://outsidersecurity.nl
๐ Related Links
* One Token to rule them all - obtaining Global Admin in every Entra ID tenant via Actor tokens - https://dirkjanm.io/obtaining-global-admin-in-every-entra-id-tenant-with-actor-tokens
* Dirk-Janโs Blog - https://dirkjanm.io
* ROADtools - https://github.com/dirkjanm/ROADtools
๐ Chapters
00:00 Intro
02:11 Guest Journey into Security
07:13 Building ROADtools and ROADrecon
09:53 Research Tools & Methods
14:05 Top Discoveries Ranked
17:01 Windows Hello & PRT Deep Dive
26:07 The Cross-Tenant Actor Token Bug
35:34 Ethical Dilemmas of Big Finds
38:24 Disclosure, Impact & Community
45:59 Future Research & Intune Tips
53:58 Training, Consulting & Closing
Podcast Apps
๐๏ธ Entra.Chat - https://entra.chat
๐ง Apple Podcast โ https://entra.chat/apple
๐บ YouTube โ https://entra.chat/youtube
๐บ Spotify โ https://entra.chat/spotify
๐ง Overcast โ https://entra.chat/overcast
๐ง Pocketcast โ https://entra.chat/pocketcast
๐ง Others โ https://entra.chat/rss
Merillโs socials
๐บ YouTube โ youtube.com/@merillx
๐ LinkedIn โ linkedin.com/in/merill
๐ค Twitter โ twitter.com/merill
๐บ TikTok โ tiktok.com/@merillf
๐ฆ Bluesky โ bsky.app/profile/merill.net
๐ Mastodon โ infosec.exchange/@merill
๐งต Threads โ threads.net/@merillf
๐ค GitHub โ github.com/merill
By Merill Fernando5
44 ratings
In this episode, I chat with Dirk-jan Mollema, the legendary researcher behind some of the most important discoveries in Microsoft identity security.
We go deep into how curiosity led him from tinkering with web tools to uncovering one of the biggest Entra ID vulnerabilities ever found.
He shares the story behind the CVE that rocked the cloud world, the stress of realizing what heโd uncovered, and the mindset that drives his relentless research. If youโve ever wondered what it feels like to find a bug that could break the internetโthis oneโs for you.
PS: If you like this episode please leave a review on Apple Podcast or Spotify ๐
Subscribe with your favorite podcast player or watch on YouTube ๐
About Dirk-jan Mollema
Dirk-Jan Mollema is a security researcher and consultant specializing in Microsoft Entra ID (Azure AD) and Active Directory security. He is the creator of popular offensive security tools including ROADtools and ROADrecon.
With seven years of Entra research and nearly a decade in AD security, Dirk-Jan has discovered numerous critical vulnerabilities and has played an important role in helping improve Microsoftโs cloud security posture. He provides training and consulting services through his company Outsider Security.
Twitter โ https://twitter.com/_dirkjan
LinkedIn โ https://www.linkedin.com/in/dirkjanm
Contact โ https://outsidersecurity.nl
๐ Related Links
* One Token to rule them all - obtaining Global Admin in every Entra ID tenant via Actor tokens - https://dirkjanm.io/obtaining-global-admin-in-every-entra-id-tenant-with-actor-tokens
* Dirk-Janโs Blog - https://dirkjanm.io
* ROADtools - https://github.com/dirkjanm/ROADtools
๐ Chapters
00:00 Intro
02:11 Guest Journey into Security
07:13 Building ROADtools and ROADrecon
09:53 Research Tools & Methods
14:05 Top Discoveries Ranked
17:01 Windows Hello & PRT Deep Dive
26:07 The Cross-Tenant Actor Token Bug
35:34 Ethical Dilemmas of Big Finds
38:24 Disclosure, Impact & Community
45:59 Future Research & Intune Tips
53:58 Training, Consulting & Closing
Podcast Apps
๐๏ธ Entra.Chat - https://entra.chat
๐ง Apple Podcast โ https://entra.chat/apple
๐บ YouTube โ https://entra.chat/youtube
๐บ Spotify โ https://entra.chat/spotify
๐ง Overcast โ https://entra.chat/overcast
๐ง Pocketcast โ https://entra.chat/pocketcast
๐ง Others โ https://entra.chat/rss
Merillโs socials
๐บ YouTube โ youtube.com/@merillx
๐ LinkedIn โ linkedin.com/in/merill
๐ค Twitter โ twitter.com/merill
๐บ TikTok โ tiktok.com/@merillf
๐ฆ Bluesky โ bsky.app/profile/merill.net
๐ Mastodon โ infosec.exchange/@merill
๐งต Threads โ threads.net/@merillf
๐ค GitHub โ github.com/merill

371 Listeners

376 Listeners

652 Listeners

232 Listeners

1,022 Listeners

64 Listeners

177 Listeners

314 Listeners

189 Listeners

74 Listeners

9 Listeners

23 Listeners

136 Listeners

15 Listeners

46 Listeners