Hoppa till huvudinnehåll

LEARN, CONNECT, BUILD

Microsoft Reactor

Gå med i Microsoft Reactor och interagera med utvecklare live

Är du redo att komma igång med AI och de senaste teknikerna? Microsoft Reactor tillhandahåller evenemang, utbildning och communityresurser som hjälper utvecklare, entreprenörer och nystartade företag att bygga vidare på AI-teknik med mera. Följ med!

LEARN, CONNECT, BUILD

Microsoft Reactor

Gå med i Microsoft Reactor och interagera med utvecklare live

Är du redo att komma igång med AI och de senaste teknikerna? Microsoft Reactor tillhandahåller evenemang, utbildning och communityresurser som hjälper utvecklare, entreprenörer och nystartade företag att bygga vidare på AI-teknik med mera. Följ med!

Gå tillbaka

Identity Wars: The Conditional Access Battlefield

7 maj, 2025 | 2:00 em - 5:00 em (UTC) Samordnad universell tid

Plats: Tel Aviv

Adress: Derech Menachem Begin 144, Tel Aviv-Yafo 'Midtown' Floor 50

  • Format:
  • alt##In personPersonligen (Tel Aviv)

Område: Handläggare

Språk: Hebreiska

The Conditional Access Policy (CAP) in Microsoft Entra ID is one of the most powerful enforcement layers in the identity protection stack.
It’s powerful, but imperfect—creating a playground for red teams.

This meetup will bridge the attacker mindset and defender best practices in a practical, real-world format. From offensive simulations to defensive hardening, we’ll uncover what’s happening behind the policies.

In a nutshell - Attacking & Defending Entra ID Conditional Access.

Why Attend?

This isn’t a typical 101 meetup. It’s a live and technical demo focused on how attackers think and how defenders can evolve. Whether you build or break policies, you’ll leave with new insights and practical takeaways.

The meetup will be part of the new cooperation with Workplace Ninja.

AGENDA

17:15 > Pizzas and Beers - Break the ice
18:00 > Entra ID CAP - Defender Mode by Ofir Gavish
18:45 > Entra ID CAP - Attacker Mode by Elli Shlomo
19:30 > Detection and Hunting with Kusto by Ofir and Elli
20:00 > Closing

What You’ll Learn

How attackers bypass Conditional Access using real-world techniques like Device Code Flow and Access token.
How to detect and respond to suspicious sign-ins and CA policy gaps.
Best practices for designing resilient and adaptive Conditional Access policies.
Red team demos + blue team playbooks = full-spectrum identity defense.
Audience: Red Teamers, Blue Teamers, SOC Analysts, Cloud Security Engineers, Identity Architects, and everyone who wants to improve IAM security - especially in Entra ID CAP.

Speakers

Elli Shlomo – Microsoft Security MVP, Head of Security Research | Guardz
Ofir Gavish - Microsoft Intune MVP | Cloud Infrastructure Team Lead | Essence Group
NOTES

Content Level - 300-400
​The event is physical at the Microsoft Reactor TLV
​​The event will not be streamed or recorded

Delar av denna sida kan vara maskin- eller AI-översatta.