Sign in

Dirk-jan

@dirkjanm.io
2K followers 66 following 80 posts

Hacker at outsidersecurity.nl. Researches Entra ID, AD and occasionally Windows security. I write open source security tools and do blogs/talks to educate others on these topics. Blog: dirkjanm.io

PostsRepliesMedia
Dirk-jan @dirkjanm.io · 14/09/2026
Friday afternoon (vibe)coding project that was on my to-do for a while: obtaining Entra ID tokens from an endpoint by asking the WAM. This alternative to using the PRT cookie follows the legitimate SSO flow used by apps like Teams to obtain tokens. Code: github.com/dirkjanm/ask...
github.com
GitHub - dirkjanm/askWAM: Ask the Web Account Manager (WAM) for Entra ID tokens
Ask the Web Account Manager (WAM) for Entra ID tokens - dirkjanm/askWAM
1103
Dirk-jan @dirkjanm.io · 20/08/2026
📢 The next edition of my offensive Entra ID security class just opened up for registration! November 16-19 in The Hague, Netherlands. In this 4-day class we deep dive into Entra ID security, tokens, oauth2 and Conditional Access. More info and reg: events.outsidersecurity.nl/entra-26-11/
events.outsidersecurity.nl
Training: Offensive Entra ID (Azure AD) and Hybrid AD security
Nov. 16 – 19, 2026
021
Dirk-jan @dirkjanm.io · 05/08/2026
✈️ blog to kick off BH/DC week: Borrowing Windows Hello keys for authentication and persistence. dirkjanm.io/borrowing-wi...
dirkjanm.io
Borrowing Windows Hello keys for authentication and persistence
Most research into Windows Hello focuses on the mechanics in use when authenticating to the local device. As an Entra ID researcher, I’ve always been more interested in how these keys are used to auth...
150
Dirk-jan @dirkjanm.io · 22/06/2026
I just wrote a new blog on bypassing CA policies in Entra ID that have a resource exclusion, and why you probably want to enable baseline enforcement if you have such policies. Enjoy! dirkjanm.io/bypassing-co...
dirkjanm.io
Bypassing Conditional Access policies that have a resource exclusion
There is a documented enforcement gap in Conditional Access policies that apply to “all resources” but have an exclusion for at least one resource. What is not documented, is that this gap is much lar...
063
Dirk-jan @dirkjanm.io · 17/03/2026
It appears that Microsoft removed the discovery of all domains in a tenant through ACS, a technique that I shared at my BH/DC talks last summer (though probably not many people spotted the reference). I found it out during a live demo of course 🙃
082
Dirk-jan @dirkjanm.io · 12/03/2026
The next public edition of my "Offensive Entra ID" course will take place from June 8th to 11th in The Hague! Tickets are now available via events.outsidersecurity.nl/entra-26-07/. Last time the tickets sold out in a few weeks, so don't wait too long if you want to secure a spot.
events.outsidersecurity.nl
Training: Offensive Entra ID (Azure AD) and Hybrid AD security
June 8 – 11, 2026
050
Dirk-jan @dirkjanm.io · 17/02/2026
Since I was bored on a plane I decided to revisit some of the Windows Hello tradecraft and finally implemented browser based FIDO2 auth using WHFB keys in roadtx. Thanks @fabian.bader.cloud and @nathanmcnulty.com for the inspiration!
061
Dirk-jan @dirkjanm.io · 06/02/2026
Next week at WWHF Mile High I'll present a major update to roadrecon, with some awesome features I wanted to add for a while! Friday 9am in track 1 for those attending 😀
095
Dirk-jan @dirkjanm.io · 26/01/2026
I can't believe Microsoft killed one of my favorite labs in my Entra ID training 😭. The Azure CLI and Azure PowerShell are no longer FOCI clients. On a serious note: good for security!
181
Reposted by Dirk-jan
Insomni'hack @1ns0mn1h4ck.bsky.social · 12/01/2026
Master identity attack & defense with Dirk-jan at the workshop "Offensive Entra ID (Azure AD) & Hybrid AD Security". Hands-on training for identity pentesters & defenders at #INSO2026. Get your ticket: ow.ly/Qzgm50XVAAJ #InsomniHack #Cybersecurity #Infosec #Cyberworkshops
033
Reposted by Dirk-jan
Fabian Bader @fabian.bader.cloud · 27/11/2025
@_dirkjan and my joint talk at #TROOPERS25 is now available on YouTube. "Finding Entra ID CA Bypasses - the structured way" @wearetroopers.bsky.social youtu.be/yYQBeDFEkps
youtu.be
TROOPERS25: Finding Entra ID CA Bypasses - The Structured Way
YouTube video by TROOPERS IT Security Conference
063
Reposted by Dirk-jan
Jim Sykora @jimsycurity.adminsdholder.com · 31/10/2025
Note: Work related I do Active Directory stuff for a living. Security research to be more specific. One of my favorite niche AD topics is AdminSDHolder. It's even my vanity domain. I wrote a 159 pg book about AdminSDHolder. I'm kinda proud of it. specterops.io/resources/ad...
specterops.io
AdminSDHolder Misconceptions & Misconfigurations - SpecterOps
AdminSDHolder is an object and associated process in Active Directory Domain Services (AD DS) that helps protect specific sensitive and highly privileged accounts from being manipulated. This topic is...
1153
Dirk-jan @dirkjanm.io · 27/10/2025
Seems Microsoft is doing some app and permission cleanups and tenant restrictions lately. RIP Microsoft Planner FOCI client.
050
Reposted by Dirk-jan
Merill Fernando 💚 @merill.net · 24/10/2025
Dirk-jan Mollema found one of the most severe vulnerabilities ever discovered in Microsoft Entra ID. One that could have compromised every tenant in the cloud. In this episode, we unpack the story, the stress, and the mindset behind responsible disclosure. 🔥
1133
Dirk-jan @dirkjanm.io · 17/09/2025
I've been researching the Microsoft cloud for almost 7 years now. A few months ago that research resulted in the most impactful vulnerability I will probably ever find: a token validation flaw allowing me to get Global Admin in any Entra ID tenant. Blog: dirkjanm.io/obtaining-gl...
dirkjanm.io
One Token to rule them all - obtaining Global Admin in every Entra ID tenant via Actor tokens
While preparing for my Black Hat and DEF CON talks in July of this year, I found the most impactful Entra ID vulnerability that I will probably ever find. One that could have allowed me to compromise ...
98737
Dirk-jan @dirkjanm.io · 01/09/2025
📢 New date for my "Offensive Entra ID security" course: December 8-11th 2025. This will be the last event this year. The previous events sold out quite fast so don't wait too long if you want to attend! 😀 events.outsidersecurity.nl/entra-25-12/
events.outsidersecurity.nl
Training: Offensive Entra ID (Azure AD) and Hybrid AD security
Dec. 8th – 11th, 2025
061
Dirk-jan @dirkjanm.io · 26/08/2025
It seems there now is a BOF implementation of ADSyncDecrypt to dump Entra ID connect creds 👀 github.com/Paradoxis/AD...
github.com
GitHub - Paradoxis/ADSyncDump-BOF: The ADSyncDump BOF is a port of Dirkjan Mollema's adconnectdump.py / ADSyncDecrypt into a Beacon Object File (BOF) with zero dependencies.
The ADSyncDump BOF is a port of Dirkjan Mollema's adconnectdump.py / ADSyncDecrypt into a Beacon Object File (BOF) with zero dependencies. - Paradoxis/ADSyncDump-BOF
080
Dirk-jan @dirkjanm.io · 20/08/2025
If you didn't find my Black Hat / Def Con slides yet, they are available on dirkjanm.io/talks . Also includes the demo videos where I use actor tokens from on-prem to access SharePoint online and get Global Admin.
dirkjanm.io
Presentations and external blogs
Dirk-jan’s personal blog, mostly containing research on topics I find interesting, such as (Azure) Active Directory internals, protocols and vulnerabilities.
030
Reposted by Dirk-jan
Katie Knowles @siigil.bsky.social · 14/08/2025
🎉 Exciting news: The Office 365 Exchange Online SP privilege escalation we documented in "I SPy" is no longer possible! We've updated the post to reflect this. Thanks to Eli Guy for the tip on this one: securitylabs.datadoghq.com/articles/i-s...
securitylabs.datadoghq.com
I SPy: Escalating to Entra ID's Global Admin with a first-party app | Datadog Security Labs
Backdooring Microsoft's applications is far from over. Adding service principal credentials to these apps to escalate privileges and obfuscate activities has been seen in nation-state attacks, and led...
1111
Dirk-jan @dirkjanm.io · 06/08/2025
The ADSyncCertDump tool is now part of the adconnectdump tools and can be used to extract SP credentials from Entra ID connect hosts. I will cover that during my BH/DC talks today and Friday! Tool is heavily based on Shwmae by @ethicalchaos.bsky.social Link: github.com/dirkjanm/adc...
github.com
GitHub - dirkjanm/adconnectdump: Dump Azure AD Connect credentials for Azure AD and Active Directory
Dump Azure AD Connect credentials for Azure AD and Active Directory - dirkjanm/adconnectdump
052
Dirk-jan @dirkjanm.io · 30/07/2025
It's been almost a year since my last blog... So, here is a new one: Extending AD CS attack surface to the cloud with Intune certificates. Also includes ESC1 over Intune (in some cases). dirkjanm.io/extending-ad... Oh, and a new tool for SCEP: github.com/dirkjanm/sce...
dirkjanm.io
Extending AD CS attack surface to the cloud with Intune certificates
Active Directory Certificate Services (AD CS) attack surface is pretty well explored in Active Directory itself, with *checks notes* already 16 “ESC” attacks being publicly described. Hybrid attack pa...
0159
Dirk-jan @dirkjanm.io · 25/07/2025
For those like me who prefer to stay in the terminal and want to call REST APIs like the Microsoft Graph without complicated commands or copy/pasting tokens: roadtx now has a graphrequest command to perform simple requests against these APIs and parse the JSON.
2181
Reposted by Dirk-jan
modzero @modzero.bsky.social · 29/06/2025
Teammate Leonid discovered a leaked credential that allowed anyone unauthorized access to all Microsoft tenants of orgs that use Synology's "Active Backup for Microsoft 365" (ABM), including sensitive data like Teams channel messages. 🤓 #synology #disclosure #modzero modzero.com/en/blog/when...
modzero.com
When Backups Open Backdoors: Accessing Sensitive Cloud Data via
12214
Dirk-jan @dirkjanm.io · 03/07/2025
Got word from MSRC that the product team reevaluated their initial duplicate/not-a-vuln decision and will actually be fixing this validation flaw in EAM 😂
1130
Reposted by Dirk-jan
Fabian Bader @fabian.bader.cloud · 26/06/2025
One of the results of the joined research with @dirkjanm.io is entrascopes.com Basically the yellow pages for Microsoft first party apps. #TROOPERS25
2256
Dirk-jan @dirkjanm.io · 24/06/2025
Last two weeks I talked about BYO Identity Providers in Entra ID and backdoors to External Auth Methods to bypass MFA. Only possible because MSFT doesn't implement the mandatory OIDC security measures. Slides with optional dark mode on: dirkjanm.io/talks/
dirkjanm.io
Presentations and external blogs
Dirk-jan’s personal blog, mostly containing research on topics I find interesting, such as (Azure) Active Directory internals, protocols and vulnerabilities.
1115
Reposted by Dirk-jan
Fabian Bader @fabian.bader.cloud · 22/06/2025
Rerunning my test scenarios for the #TROOPERS25 presentation...
041
Dirk-jan @dirkjanm.io · 10/06/2025
Received the news today that my talk "Advanced Active Directory to Entra ID lateral movement techniques" was also accepted for @defcon.bsky.social 🎉 hope to see everyone there!
0265
Dirk-jan @dirkjanm.io · 30/05/2025
Since we now can use Entra ID connect sync with a service principal, I thought I'd look into the new security measures. On hosts without a TPM, we can dump the cert+key. On hosts with TPM (second picture) we can use the key to create an auth assertion for roadtx to req tokens.
1152
Dirk-jan @dirkjanm.io · 16/05/2025
I'll be returning to #BHUSA @blackhatevents.bsky.social this summer for a brand talk about moving laterally from AD to Entra ID. I don't think I've ever been this excited about a talk, with lots of cool stuff to share 🎢 😄.
Advanced Active Directory to Entra ID Lateral Movement Techniques
Dirk-jan Mollema  |  Security Researcher, Outsider Security
Format: 40-Minute Briefings
Tracks: Cloud Security, Enterprise Security

Is there a security boundary between Active Directory and Entra ID in a hybrid environment? The answer to this question, while still somewhat unclear, has changed over the past few years as there has been more hardening of how much "the cloud" trusts data from on-premises. The reason for this is that many threat actors, including APTs, have been making use of known lateral movement techniques to compromise the cloud.

In this talk, we will take a deep dive together into Entra ID and hybrid trust internals. We will introduce several new lateral movement techniques that allow us to bypass authentication, MFA and stealthily exfiltrate data using on-premises AD as a starting point, even in environments where the classical techniques didn't work. All these techniques are new, not really vulnerabilities, but part of the design. Several of them have been remediated with recent hardening efforts by Microsoft. Very few of them leave useful logs behind when abused. As you would expect, none of these "features" are documented.

Join me for a wild ride into Entra ID internals, undocumented authentication flows and tenant compromise from on-premises AD.
1151
Reposted by Dirk-jan
Dr Nestori Syynimaa @drazuread.com · 18/04/2025
Just pushed a new versions for #AADInternals and AADInternals-Endpoint modules! Some bug fixes plus support for: 1️⃣ Microsoft Authentication Library (MSAL) 2️⃣ Token Protection 3️⃣ Continuous Access Evaluation (CAE)
1155
Dirk-jan @dirkjanm.io · 16/04/2025
Just found something super useful for my research...... In my own notes from 2023 😅 how I found it back then and why I didn't do anything with it remains a complete mystery.
0120
Dirk-jan @dirkjanm.io · 10/04/2025
Two new Entra ID training opportunities in the next few months! I will give another 4-day edition of my public training July 7-10 in The Hague, NL. I will also return to RomHack (Rome, IT) this year for a training Sept 23-27 😀 Info and ticket links: outsidersecurity.nl/training/
outsidersecurity.nl
Outsider Security - Training
Outsider Security - Training in Entra ID (Azure AD) and Active Directory security.
020
Reposted by Dirk-jan
Max Andreacchi @atomicchonk.bsky.social · 29/03/2025
Spent the evening deep diving into MCPs and started a new project: roadrecon_mcp_server! This #MCP takes the web GUI output from the awesome ROADtools by @dirkjanm.io and offers tools to Claude (or your #AI agent of choice) to interact with the data: github.com/atomicchonk/...
github.com
GitHub - atomicchonk/roadrecon_mcp_server: Claude MCP server to perform analysis on ROADrecon data
Claude MCP server to perform analysis on ROADrecon data - atomicchonk/roadrecon_mcp_server
2115
Dirk-jan @dirkjanm.io · 27/03/2025
Automatic browser SSO with a PRT on a victim device over an Outflank C2 implant 🥰 using ROADtools and some hackery from Max Grim.
0163
Reposted by Dirk-jan
Dr Nestori Syynimaa @drazuread.com · 11/03/2025
My @disobeyfi.bsky.social talk is finally out! Link to video and slides available at aadinternals.com/talks And yes, @notmynick.bsky.social used some weird filter, I'm not that fat nor old 😜
1165
Dirk-jan @dirkjanm.io · 09/03/2025
Small detour on the way to Insomni'hack! @1ns0mn1h4ck.bsky.social
A picture of snowy swiss mountains with a blue sky
190
Dirk-jan @dirkjanm.io · 20/02/2025
It appears Microsoft quietly mitigated most of the risk of the "Intune company portal" device compliance CA bypass by restricting the scope of Azure AD graph tokens issued to this app, making them almost useless for most abuse scenarios. Thx @domchell.bsky.social for the heads up.
0299
Dirk-jan @dirkjanm.io · 18/02/2025
Normally you can't auth to Entra ID connected webapps with bearer tokens. But if Teams can open SharePoint/OneDrive with an access token, I guess so can we. roadtx now supports opening SharePoint with access tokens in the embedded browser 😀
1198
Reposted by Dirk-jan
Nathan McNulty @nathanmcnulty.com · 12/02/2025
I don't know who needs to hear this, but there is no such thing as securing BYOD, especially non-mobile OSs You may limit damage your regular users can cause, but you are not keeping out an attacker when you accept a model that allows access from unknown, unmanaged devices
2304
Dirk-jan @dirkjanm.io · 07/02/2025
ROADtools update: I just released roadlib v1.0! This version drops the adal dependency, all auth flows are now implemented natively 🎉 This was mostly a personal goal, but it helps with adding new features, such as forcing MFA during device code auth independent of CA policies 😀
23111
Dirk-jan @dirkjanm.io · 29/01/2025
I'm still not seeing the mandatory Azure portal MFA we were supposed to get in October / 2nd half 2024 (depending on the source you read). Anyone know the timeline when this will *actually* be rolled out?
560
Dirk-jan @dirkjanm.io · 22/01/2025
Since redirect URLs are tricky, roadtx now includes redirect URLs for many first-party apps and uses them automatically. Demo below shows the interactiveauth module being used for the complaint device CA bypass with the "interactiveauth" module and the "companyportal" client ID alias.
1136
Dirk-jan @dirkjanm.io · 21/01/2025
After some time off to recharge outside, now back to work (and research) this week!
2603
Reposted by Dirk-jan
Andy Robbins @andyrobbins.bsky.social · 15/01/2025
In Part 1 of my Intune Attack Paths series, I discuss the fundamental components and mechanics of Intune that lead to the emergence of attack paths: posts.specterops.io/intune-attac...
posts.specterops.io
Intune Attack Paths — Part 1
Intune is an attractive system for adversaries to target…
34319
Reposted by Dirk-jan
Scoubi @scoubi.bsky.social · 14/01/2025
Today is the last day to submit to #SkiCon2025 Get your submission in if you have anything interesting to share with the community! www.skicon.org/cfp/ Tickets are also on sale : www.skicon.org/tickets/ Please reshare for reach!
skicon.org
CFP
Submit What are we looking for Bring your passion, period. While we have reccomendations on the CFP form, this is failry dynamic. Strongest topics rise to the top, as it should always be. You got this...
012
Reposted by Dirk-jan
Compass Security @compass-security.com · 10/01/2025
👏 Huge thanks to @dirkjanm.io for an exceptional Azure & Entra security training! The nitty-gritty, and real-world examples resonated strongly among our class of 25 security analysts. Thank you! #microsoft #azure #entra #cyber #security #training #cybersecurity
092
Reposted by Dirk-jan
XPN @xpnsec.com · 07/01/2025
Achievement unlocked, my first blog with SpecterOps 🤗 This post looks at ADFS OAuth2 support, Device Registration, Enterprise PRT, and a brain dump of things that I didn’t want to leave sat on Notion. buff.ly/4j41VQU
buff.ly
ADFS — Living in the Legacy of DRS
It’s no secret that Microsoft have been trying to move customers away from ADFS for a while. Short of slapping a “deprecated” label on it…
23618
Dirk-jan @dirkjanm.io · 07/01/2025
Off to a good start in the new year (Part 2). I was awarded the Microsoft MVP status a few days ago for my community contributions in the Microsoft security space. Super grateful for everyone who helped along the way to get me there! ❤️
4400
Reposted by Dirk-jan
mpgn @mpgn.bsky.social · 06/01/2025
So you want to exploit ADCS ESC8 with only netexec and ntlmrelayx ? Fear not my friend, I will show you how to do it 👇 NetExec now supports "Pass-the-Cert" as an authentication method, thanks to @dirkjanm.io original work on PKINITtools ⛱️
0147