Sign in

Eric Woodruff

@ericonidentity.com
1.6K followers 495 following 69 posts

Entra nerd currently @ #Semperis. Parent. Partner. MS Security MVP. Views are those of my cat.

PostsRepliesMedia
Reposted by Eric Woodruff
Help Net Security @helpnetsecurity.com · 26/05/2026
What happens when security teams inherit identity 🔗 Read more: www.helpnetsecurity.com/2026/05/26/e... #identitysecurity #CISO #cybersecurity @ericonidentity.com
helpnetsecurity.com
What happens when security teams inherit identity - Help Net Security
Eric Woodruff on identity security, the challenges surrounding identity platforms, non-human identities, and AI.
011
Eric Woodruff @ericonidentity.com · 29/05/2026
Seeing new attributes pop-up is a strong signal that something is brewing in Entra ID. Ever wish this could be surfaced in an automated way? Enter changes.entra.ms - An automated system that scrapes #Entra for changes on a daily basis. #EntraID #infosec #mvpbuzz
020
Eric Woodruff @ericonidentity.com · 18/11/2025
Anthropic - AI can do cyber without much human. Me - AI can you help me with this research:
000
Eric Woodruff @ericonidentity.com · 03/09/2025
I’ve been finding the #Entra Usage & Insights report useless lately when it comes to #passkey reporting. Why? It’s broken. It’s concerning that this seems to be an ongoing issue that isn’t tenant specific and Microsoft hasn’t caught it. #EntraID ericonidentity.com/2025/09/02/e...
ericonidentity.com
Entra Useless Insights Report - Eric on Identity
Exploring the Entra Usage & Insights report on MFA usage, and the issues with the reports lack of accuracy, as well as a workaround.
030
Reposted by Eric Woodruff
Karl Fosaaen @kfosaaen.bsky.social · 01/07/2025
I have a new post out on the @netspi.bsky.social blog today. This one is on extracting sensitive information from the Azure Load Testing service. www.netspi.com/blog/technic...
netspi.com
Extracting Sensitive Information from Azure Load Testing
Learn how Azure Load Testing's JMeter JMX and Locust support enables code execution, metadata queries, reverse shells, and Key Vault secret extraction vulnerabilities.
132
Reposted by Eric Woodruff
Kat Traxler @nanook.bsky.social · 30/06/2025
Quote of the day: “MSFT has architected themselves into this corner” #fwdcloudsec25 @ericonidentity.com
ericonidentity.com
Home - Eric on Identity
This blog is about all things identity and identity adjacent. Right now, the focus is primarily on Azure AD and the Microsoft identity world, but it could have potential to expand in the future.
021
Eric Woodruff @ericonidentity.com · 29/06/2025
Going right from @wearetroopers.bsky.social in Heidelberg to @fwdcloudsec.org in Denver ✈️ - from one excellent conference to another! I’m looking forward to speaking Monday @ 2:00pm in track 1 on the dangers of #nOAuth, with some new and tweaked slides and talking points! #Entra #EntraID
A photo taken from a train, near Heidelberg Germany, of a crop field with some brown green grass and a hazy blue sky with a tint of orange from the sunrise. There is a reflection on the window of myself somewhat from inside the train car.
130
Reposted by Eric Woodruff
Dr Nestori Syynimaa @drazuread.com · 25/06/2025
nOAuth revisited by @ericonidentity.com at @wearetroopers.bsky.social
032
Eric Woodruff @ericonidentity.com · 25/06/2025
At @wearetroopers.bsky.social I dropped new research on #nOAuth, an abuse of #EntraID that allows you to spoof users in vulnerable SaaS applications. The attack is still alive and well. You can read all about it here: #Entra #M365 #infosec www.semperis.com/blog/noauth-...
semperis.com
New nOAuth Abuse Alert: Entra Cross-Tenant Saas Apps at Risk
Think nOAuth abuse is old news? We wish. Our recent testing shows that nearly 10% of apps in the Microsoft Entra Gallery remain vulnerable.
021
Eric Woodruff @ericonidentity.com · 23/06/2025
On the way to #TROOPERS25. The short flight is down… just waiting for the long one to Frankfurt. Looking forward to talking about #nOAuth with #Entra… sadly it’s still a thing 😑 #EntraID #infosec @wearetroopers.bsky.social
A photo taken from an airplane of the. There are small white fluffy clouds scattered below and a slightly hazy blue sky with white wisps above them.
110
Reposted by Eric Woodruff
Anthony J. Fontanez @ajf8729.com · 30/04/2025
Did you know you can send LAPS passwords to Entra on Server OS? Neither did @adamgrosstx.bsky.social or I until yesterday! Just need to hybrid join the server(s) and set the GPO to backup to "AAD"! Neat!
2154
Eric Woodruff @ericonidentity.com · 22/03/2025
Obligatory photo from airplane en route to the #mvpsummit
A picture taken from inside an airplane out the airplane window. The plane is on the ground, and the picture shows the jet bridge for the next gate with some workers outside. It’s still dark outside.
060
Reposted by Eric Woodruff
Jake Hildreth @dotdot.horse · 09/03/2025
The last two months have been a chaotic whirlwind of emotions and activity. I needed to talk about it, so I did: jakehildreth.github.io/blog/2025/03...
jakehildreth.github.io
New Job! New MVP?
Hi.
171
Reposted by Eric Woodruff
Jake Hildreth @dotdot.horse · 02/03/2025
Yesterday morning, I woke up to an email from Microsoft with the subject "Congratulations on your Microsoft MVP award". I immediately thought it was a phish, but I dug a bit further. It's real! 🤯 I was selected as an MVP in "PowerShell" and "Identity & Access"!
3504
Reposted by Eric Woodruff
MC2MC @mc2mc.be · 25/02/2025
📢 To all attendees, sponsors, and speakers of MC2MC Connect! 📸 We have uploaded all the event photos to the Gallery page on the MC2MC Connect website, so you can look back and relive the day! 🔗 connect.mc2mc.be/gallery/ #MC2MC #ConnectMC2MC #MC2MCConnect
071
Eric Woodruff @ericonidentity.com · 20/02/2025
If you work in, around, near, adjacent, or so on, to #identity, including #infosec and #Entra, you should fill out the #IDPro skills survey. It takes five minutes and really helps in understanding the industry landscape. www.surveymonkey.com/r/L9QB6T2
surveymonkey.com
IDPro 2025 Skills, Programs, and Diversity Survey
Take this survey powered by surveymonkey.com. Create your own surveys for free.
040
Eric Woodruff @ericonidentity.com · 20/02/2025
I received an interesting #M365 subscription email the other week, that turned out to be a scam. I figured I'd pick it apart, and found it curious enough to share the details. #entra #infosec #m365security #azure ericonidentity.com/2025/02/20/a...
ericonidentity.com
An interesting M365 billing scam - Eric on Identity
A look at a recent spam scam email that I received, trying to understand what mechanism the attacker is using to deliver the scam email.
040
Reposted by Eric Woodruff
MC2MC @mc2mc.be · 28/01/2025
We’re pleased to announce the next speaker for MC2MC Connect: @ericonidentity.com 🚀 In this session, Eric will dive deep into the most common questions about app registrations, enterprise apps, and service principals. 🔍🛡️ 🔗 tinyurl.com/5dxvnsn4 #MC2MC #ConnectMC2MC
032
Reposted by Eric Woodruff
Jason Koebler @jasonkoebler.bsky.social · 22/01/2025
Zuckerberg "loved" an AI slop image on a spam page that also posts AI images of children with amputations, elderly people, fake images of graves, links offsite to ad-loaded pages, etc. Exciting stuff for me www.404media.co/zuckerberg-l...
404media.co
Zuckerberg 'Loves' AI Slop Image From Spam Account That Posts Amputated Children
Zuckerberg seems to enjoy the spam that has taken over his flagship product.
917733
Eric Woodruff @ericonidentity.com · 16/01/2025
If you consume multi-tenant apps in #EntraID, and they’ve been granted consent to do things in your tenant, you can spy on the auth choices your vendor makes - secrets or certs - in the logs available in your #Entra tenant. #infosec #m365 #azure ericonidentity.com/2025/01/13/s...
ericonidentity.com
Spying on your ISVs credential choices - Eric on Identity
Examining Entra ID sign-in and graph activity logs to determine what type of credentials your ISVs use in their multi-tenant applications.
0101
Eric Woodruff @ericonidentity.com · 09/01/2025
With all the speaking I burnt and crashed a bit towards the end of 2024. I plan on writing about the speaking experience… but first hoping to get back into writing more as I research stuff. Hope to have both a personal blog and Semperis blog article out this week 🤞.
270
Eric Woodruff @ericonidentity.com · 04/01/2025
Looking forward to when I can talk about the more interesting case 👀 #MSRC #Entra
A screenshot of a portion of an email from MSRC for the 2024 W4 leaderboard with two valid cases totaling 75 points.
140
Eric Woodruff @ericonidentity.com · 13/12/2024
Great advice; received a variant of this last week that had an old password I used to use in it 😅
000
Reposted by Eric Woodruff
Dirk-jan @dirkjanm.io · 12/12/2024
Want to run roadrecon, but a device compliance policy is getting in your way? You can use the Intune Company Portal client ID, which is a hardcoded and undocumented exclusion in CA for device compliance. It has user_impersonation rights on the AAD Graph 😃
34520
Reposted by Eric Woodruff
Steve Syfuhs @syfuhs.net · 06/12/2024
Oh by the way
NTLM v1 is removed from the latest version of Windows
910035
Eric Woodruff @ericonidentity.com · 05/12/2024
The Moynihan Train Hall Starbucks is an absolute machine of efficiency.
000
Reposted by Eric Woodruff
Merill Fernando 💚 @merill.net · 08/11/2024
🦋 Introducing bluesky.ms 👏 = A crowdsourced database of anyone and everyone in the Microsoft community on Bluesky. 👉 Add yourself and anyone you know today 👈 🫂 All are welcome. This is my v1, I'll add options to directly follow from the site itself but first 👇 LET'S FILL IT UP! 🙏
bluesky.ms
Search bluesky.ms
Use this page to search for the Microsoft community on bluesky.ms.
58606266
Reposted by Eric Woodruff
Jake Williams @malwarejake.bsky.social · 28/11/2024
It is the biggest con in cyber security, hands down. There is *no data* that it changes cyber security *outcomes.* I theorize that most people intuitively know this, but because "improving click rate" is easy to track (and game), many performatively champion it as a "good metric" for security.
208512
Reposted by Eric Woodruff
Blue Team Con @blueteamcon.com · 24/11/2024
Blue Team Con 2025. Training + Conference. September 4-7. Fairmont Chicago. www.blueteamcon.com
02613
Eric Woodruff @ericonidentity.com · 27/11/2024
Which do I pick for SSO?!? #EntraID vs #AzureAD
A screenshot from a login screen with two SSO buttons, one for Azure AD, one for Entra ID
351
Eric Woodruff @ericonidentity.com · 26/11/2024
Looking forward to that fresh MSRC case smell…
media.tenor.com
a woman in a tie dye shirt is dancing in front of an elite daily advertisement
Alt: a woman in a tie dye shirt is dancing in front of an elite daily advertisement
130
Reposted by Eric Woodruff
Thomas Naunheim @naunheim.cloud · 26/11/2024
Celebrating 4 years of the "#MicrosoftEntra Attack & Defense Playbook" 🔐 ☁️ community project! Last week, @samilamppu.bsky.social and I took the opportunity to record a video about the journey of this project, from research to writing process. #MVPBuzz #TechCommunity www.youtube.com/watch?v=fBD1...
youtube.com
Microsoft Entra ID Attack & Defense Playbook with Sami Lamppu
YouTube video by Thomas Naunheim
2173
Reposted by Eric Woodruff
Pete Birkinshaw @binaryape.bsky.social · 25/11/2024
If you use SimpleSAMLphp get ready to patch or update on 1st or 2nd December
022
Reposted by Eric Woodruff
Fabian Bader @fabian.bader.cloud · 21/11/2024
Device-bound #passkeys in #EntraID are finally GA aka.ms/Ignite2024/entra #AiTM #Security #FIDO2
25913
Eric Woodruff @ericonidentity.com · 21/11/2024
When you’re cleaning up your lab and trying to recall what the server you named trashcan was for… 🧐
150
Reposted by Eric Woodruff
Jef Kazimer 😶‍🌫️ 🆔 @jeftek.com · 21/11/2024
I created a starter pack for those just joining Bluesky to follow some great people talking #microsoft #identity and #security to get you started! Follow and Share! #msignite go.bsky.app/FkPKwkK
34913
Eric Woodruff @ericonidentity.com · 19/11/2024
For those that *really* miss the old AAD portal: rc-aad.portal.azure.com#view/Microso... #Entra #EntraID
1110
Eric Woodruff @ericonidentity.com · 18/11/2024
Still hard to not laugh when you see Microsoft apps having to resort to these naming conventions in your #Entra tenant 😅
160
Eric Woodruff @ericonidentity.com · 12/11/2024
Haven’t been around these parts in a while. En route to #HIPConf24, where I’ll be presenting on #UnOauthorized tomorrow, as well as joining a panel with Thomas Naunheim on workload identities, and having some good hallway conversations. Looking forward to seeing folks! #Entra #EntraID #infosec
260
Eric Woodruff @ericonidentity.com · 08/08/2024
I've been quiet on here for a while, but wanted to share the blog that details much of UnOAuthorized from my #bhusa talk yesterday. #blackhat #blackhat2024 #EntraID #azure #microsoft365 #microsoft #infosec www.semperis.com/blog/unoauth...
semperis.com
Privilege Elevation in Entra ID: UnOAuthorized | Semperis Research
Recent Semperis security research findings reveal a past potential for privilege elevation in Entra ID. Learn more in this article.
011
Eric Woodruff @ericonidentity.com · 10/03/2024
The obligatory starting my journey to the MVP Summit picture 😜😎 #mvpbuzz
020
Eric Woodruff @ericonidentity.com · 25/10/2023
When you spend a lot of personal time and effort to speak at a conference in a vendor-neutral spot that you had to really put the work in to earn, the conference management team should in turn exclude you from the list of attendees that they give to sponsors. #infosec #cybersecurity #conferences
120
Reposted by Eric Woodruff
HotCakeX @hotcakex.bsky.social · 24/09/2023
Just published a new post: How to Securely Connect to Azure VMs and Use RDP Bastion, Virtual Network Gateway, VPN, Azure Cloud PowerShell and more #CyberSecurity github.com/HotCakeX/Har...
github.com
How to Securely Connect to Azure VMs and Use RDP
Harden Windows Safely, Securely using Official Supported Microsoft methods and proper explanation | Always up-to-date and works with the latest build of Windows | Provides tools and Guides for Pers...
041
Eric Woodruff @ericonidentity.com · 15/09/2023
Reminder to anyone who has purchased a new #iPhone and uses #passwordless or the #microsoft authenticator app for #mfa for corporate #office365 or #EntraID iPhone backups/transfers will not rehydrate the app. Make sure you have a backup strong auth method. #m365 #azuread #azure #aad #infosec
An image of a man sitting down with a teal plaid shirt on, opening a gift box and inside it is the identical teal plaid shirt to what he is wearing. The main is labeled "iPhone Users", the shirt he is wearing is labeled "iPhone 11" and the shirt in the box is labeled "iPhone 12"
021
Reposted by Eric Woodruff
P(aul) Frazee @pfrazee.com · 15/09/2023
as punishment for requesting gifs, we have broken images
1001546313
Eric Woodruff @ericonidentity.com · 15/09/2023
Worst idea I've seen all day #okta #infosec #activedirectory #identity
A screenshot of a piece of Okta documentation on configuring the Okta AD agent, with the highlighted text in question stating " The Okta AD agent Management Utility also includes the option of adding the OktaService account to the Domain Admins group"
240
Eric Woodruff @ericonidentity.com · 08/09/2023
The #Google #chrome response to #Microsoft #edge in the war to make the shittiest browser with the recent ad privacy changes...
100
Eric Woodruff @ericonidentity.com · 30/08/2023
If you've been living under the impression that 100% of all configuration changes in Entra ID are audited, or audited with value, you'd be wrong. A dive into a recent analysis of what's not there in #EntraID. #aad #mvpbuzz #entra #azuread #infosec #m365 ericonidentity.com/2023/08/29/d...
ericonidentity.com
Dude, Where's My Audit Logs?
If you believe that every change to Entra ID is thoroughly audited, you may want to give this article a look through.
141
Eric Woodruff @ericonidentity.com · 27/08/2023
If you’re at #BlueTeamCon and want to understand why #passkeys / #FIDO2 are #phishing resistant, and why most other forms of #MFA are not, come by the unconference room Sunday on lunch at 12:20pm. Will include a live demo of #evilginx in action. #BlueTeamCon2023 #mvpbuzz #infosec
010
Eric Woodruff @ericonidentity.com · 11/08/2023
If you're in the #NYC area come see me and a bunch of other fabulous folks speak about #identity #security August 23-24 at HIP Global 2023 I'll have a session on #phishing and strong #authentication with #EntraID. #AAD #infosec #MVPBuzz #azuread #m365 #microsoft #hipconf accelevents.com
000