This session is for members.

Subscribe or log in to watch every GoSec session.

Subscribe Log in

This recording is not available yet.

Votre tenant Azure est-il sécurisé par défaut ?

Download resources

About this session

Charles F. Hamilton, director of offensive security at CYPFER, walks through why an out-of-the-box Microsoft Entra ID (Azure) tenant is easier to compromise than most administrators assume. He opens with device code phishing: sending a legitimate Microsoft device-login link, capturing the code the victim enters, and receiving a token scoped to whatever application and resource the attacker requests, most often Microsoft Office or Microsoft Graph. He shows how default tenant settings let any standard user read other users' data, register applications, and consent to unverified third-party apps, then demonstrates hosting a look-alike application inside the victim's own tenant to dodge the 'unverified' warning. A live example covers a conditional access MFA exception, meant for one automation account, that silently exempts every Microsoft Graph request from MFA, a gap Microsoft patched in March 2026 but that still applies wherever the old exception was never updated. He also covers hunting leaked client secrets in GitHub history, pivoting refresh tokens across Microsoft's own applications without leaving log traces, and AI assistants surfacing passwords buried in SharePoint. He closes with hardening steps: disable device code flow, audit consented apps, review MFA exceptions, rotate exposed secrets, and revoke tokens once an attack is detected.

Un tenant Microsoft Entra ID (Azure) fraîchement provisionné reste vulnérable tant que sa configuration par défaut n'est pas revue. Charles F. Hamilton, directeur sécurité offensive chez CYPFER, expose les chemins d'attaque qu'elle laisse ouverts : le device code phishing, qui détourne un lien de connexion légitime de Microsoft pour intercepter un jeton d'accès; le consentement à des applications tierces non vérifiées, que tout utilisateur standard peut accorder sans supervision; une exception d'accès conditionnel MFA qui, mal circonscrite, exempte des requêtes entières vers Microsoft Graph; et la découverte de secrets client oubliés sur GitHub ou de mots de passe exposés que des assistants IA retrouvent dans SharePoint. La session propose aussi des mesures concrètes de durcissement : désactiver le device code flow, auditer les applications consenties, réviser les exceptions MFA et faire la rotation des secrets exposés.

Key takeaways

  • Disable the Azure device code authentication flow unless a specific business case needs it; it is one of the easiest phishing vectors to run and one of the easiest to turn off.
  • Audit every third-party application already consented to in your tenant, and require admin approval for unverified apps instead of letting users accept consent prompts themselves.
  • Review conditional access MFA policies for exceptions scoped to a single automation account or application; such exceptions can silently exempt any request for a given resource, such as Microsoft Graph, from MFA.
  • Search your own GitHub history for leaked client secrets, for example commits that remove strings like 'client secret', and rotate any secret that was ever exposed, even briefly.
  • Revoke tokens immediately after detecting suspicious authentication; blocking the entry point does nothing if the attacker's existing access or refresh token is left valid.

Speakers

Charles F. Hamilton
Charles F. Hamilton
Director Offensive Security · CYPFER
Charles Hamilton is a Red Teamer with over twelve years of experience delivering offensive testing services for various government clients and commercial sectors. In recent years, Charles has specialized in covert Red Team operations targeting… Read moreRead less

Charles Hamilton is a Red Teamer with over twelve years of experience delivering offensive testing services for various government clients and commercial sectors. In recent years, Charles has specialized in covert Red Team operations targeting complex and highly secured environments. These operations have enabled him to refine his skills in stealthily navigating client networks without detection. Since 2014, he has been the founder and operator of the RingZer0 Team website, a platform dedicated to teaching hacking fundamentals. The RingZer0 community currently boasts over 50,000 members worldwide. Charles is also a prolific toolsmith and trainer who has delivered this training more than 20 times, both online and onsite. He is a speaker in the InfoSec industry, known under the handle

Resources

Photos

Tags

More from GoSec 2026

Also from Charles F. Hamilton

On the same topic