Sign in

Fabian Bader

@fabian.bader.cloud
2.4K followers 368 following 318 posts

#Security #Azure #EntraID #XDR #MDE #Identity #M365 #AD #PKI #KQL Microsoft MVP Tweets and opinions are my own

PostsRepliesMedia
Reposted by Fabian Bader
Microsoft Exchange @msftexchange.bsky.social · 14/05/2026
Addressing Exchange Server May 2026 vulnerability CVE-2026-42897 | Microsoft Community Hub! 🦋 techcommunity.microsoft.com/blog/Exchang...
techcommunity.microsoft.com
Addressing Exchange Server May 2026 vulnerability CVE-2026-42897 | Microsoft Community Hub
We wanted to tell you how to address the Exchange Server May 2026 vulnerability CVE-2026-42897.  
074
Fabian Bader @fabian.bader.cloud · 11/05/2026
In my latest blog "Now You See Me: AADGraphActivityLogs" I explore the newly released Azure AD Graph logs and demonstrate how you can detect tools like ROADtools and AADinternals that rely on this API and have been under the radar for defenders so far. cloudbrothers.info/en/aadgrapha...
cloudbrothers.info
Now You See Me: AADGraphActivityLogs
KQL hunting queries for the new AADGraphActivityLogs table to detect Entra ID reconnaissance tooling based on UserAgent, RequestUri, and volume.
071
Fabian Bader @fabian.bader.cloud · 12/03/2026
My Disobey talk "Are passkeys as secure as you think" is now available on YouTube youtu.be/DQ4dnXibaoM?...
090
Fabian Bader @fabian.bader.cloud · 11/03/2026
Microsoft just announced official support to store device bound Passkeys for Entra ID in the Windows Hello container. No app, no external hardware key but built in support. Sadly no attestation while in preview. mc.merill.net/message/MC12... #Passkey #EntraID
mc.merill.net
MC1247893 - Microsoft Entra passkeys on Windows now support phishing-resistant sign-in | Microsoft 365 Message Center Archive
Microsoft Entra passkeys on Windows enable phishing-resistant, passwordless sign-in using Windows Hello on Entra-protected resources, including unmanaged devices. Public preview starts mid-March 2026....
293
Reposted by Fabian Bader
Craig Chambers @plasticlicker.bsky.social · 16/02/2026
What are preferred methods to lock someone out of a remote Intune managed computer? Any that work well in a hybrid configuration? Our best solution to date is a push of a “deny local login” policy in advance and a forced reboot. @nathanmcnulty.com @merill.net @fabian.bader.cloud
021
Fabian Bader @fabian.bader.cloud · 13/01/2026
Today at 15:00 CET #YellowHat will start. It's a free live streamed conference around Microsoft Security and we have amazing speakers and topics lined up for you. Register now to reserve your free spot. yellowhat.live #XDR #EDR #Defender #Microsoft #Security
yellowhat.live
Yellowhat
Yellowhat is a cutting-edge cybersecurity event dedicated to Microsoft Security Technology, offering advanced deep-dive sessions (level 400+) for seasoned professionals. It brings together experts and...
131
Fabian Bader @fabian.bader.cloud · 06/01/2026
With the unified SOC experience there might be some ANRs you want to exclude from XDR correlation. Now you can! Either using the UI or add #DONT_CORR# at the beginning of the ANR description. learn.microsoft.com/en-us/defend...
learn.microsoft.com
Exclude analytics rules from correlation in Microsoft Defender XDR - Microsoft Defender XDR
Learn how to exclude specific analytics rules from the correlation engine to maintain static incident grouping behavior similar to Microsoft Sentinel.
010
Fabian Bader @fabian.bader.cloud · 02/01/2026
#ConsentFix is a great way for attackers to work around some protective layers but not all. @naunheim.cloud , @cbrhh.bsky.social and I wrote a blog post on detection and mitigations. Hope you find it useful and can adapt it to your environment. www.glueckkanja.com/de/posts/202...
083
Reposted by Fabian Bader
MC2MC @mc2mc.be · 12/12/2025
We’re thrilled to reveal our next MC2MC Connect speakers for February 5th in Antwerp: @fabian.bader.cloud @rogierdijkman.bsky.social ! 🎙️ ➡️Looking to explore the program or secure your spot? Check out: connect.mc2mc.be #MC2MC #ConnectMC2MC #ConnectMC2MC2026 #Connect #Collaborate #Create
041
Fabian Bader @fabian.bader.cloud · 27/11/2025
@_dirkjan and my joint talk at #TROOPERS25 is now available on YouTube. "Finding Entra ID CA Bypasses - the structured way" @wearetroopers.bsky.social youtu.be/yYQBeDFEkps
youtu.be
TROOPERS25: Finding Entra ID CA Bypasses - The Structured Way
YouTube video by TROOPERS IT Security Conference
063
Reposted by Fabian Bader
MC2MC @mc2mc.be · 20/11/2025
🚀 The speakers for MC2MC Connect 2026 are live! ➡️ Dive into Microsoft Cloud, Endpoint, Security, AI, FinOps & Architecture with top experts. 🎤 Speakers: connect.mc2mc.be/speakers-wid... 🎟️ Only a few early-bird tickets left: connect.mc2mc.be/tickets/ #MC2MC #ConnectMC2MC #ConnectMC2MC2026
053
Fabian Bader @fabian.bader.cloud · 18/11/2025
Custom data collection in Microsoft Defender for Endpoint was just announced in the November release notes. Documentation is already available learn.microsoft.com/en-us/defend... Predictive shielding sounds also very interesting... #MDE #XDR
020
Reposted by Fabian Bader
Expel @expelsecurity.bsky.social · 23/10/2025
Attackers found a clever way to abuse legitimate, digitally signed software to load malware and it's working. Expel Intel’s Marcus Hutchins (@malwaretech.com) breaks down a campaign that weaponizes Greenshot, a legit screenshot tool, to evade detection at multiple layers. 🧵
1287
Fabian Bader @fabian.bader.cloud · 21/10/2025
Microsoft Defender just got the September 2025 update ◽Improved core service startup behavior ◽ Security fixes for missing input validation of RPC services ◽Fixed threat exclusion handling ◽Restored performance optimization for network file access learn.microsoft.com/en-us/defend...
050
Reposted by Fabian Bader
Dirk-jan @dirkjanm.io · 17/09/2025
I've been researching the Microsoft cloud for almost 7 years now. A few months ago that research resulted in the most impactful vulnerability I will probably ever find: a token validation flaw allowing me to get Global Admin in any Entra ID tenant. Blog: dirkjanm.io/obtaining-gl...
dirkjanm.io
One Token to rule them all - obtaining Global Admin in every Entra ID tenant via Actor tokens
While preparing for my Black Hat and DEF CON talks in July of this year, I found the most impactful Entra ID vulnerability that I will probably ever find. One that could have allowed me to compromise ...
98737
Fabian Bader @fabian.bader.cloud · 13/09/2025
Did you ever asked yourself: What does Swiss cheese and Conditional Access have in common? Either way, if you want to learn about (un)documented Conditional Access Bypasses, then join me on Monday at the Workplace Ninja Summit 25 #WPninjas wpninjas25.sched.com/event/27VE4/...
wpninjas25.sched.com
Workplace Ninja Summit 2025: What does Swiss cheese and Conditional A...
View more about this event at Workplace Ninja Summit 2025
020
Fabian Bader @fabian.bader.cloud · 10/09/2025
Sentinel UEBA got a welcome set of new data sources ◽Defender XDR device logon events ◽Entra ID managed identity signin logs ◽Entra ID service principal signin logs ◽AWS CloudTrail ◽GCP audit logs ◽Okta MFA techcommunity.microsoft.com/blog/microso...
techcommunity.microsoft.com
Microsoft Sentinel’s AI-driven UEBA ushers in the next era of behavioral analytics | Microsoft Community Hub
Co-author - Ashwin Patil Security teams today face an overwhelming challenge: every data point is now a potential security signal and SOCs are drowning in...
020
Fabian Bader @fabian.bader.cloud · 22/08/2025
Token Protection in Microsoft Entra Conditional Access for Windows is now GA! 🎉 #EntraID #Token learn.microsoft.com/en-us/entra/...
061
Fabian Bader @fabian.bader.cloud · 15/08/2025
Two years ago I published a two part series on #MSGraph logs and how to use them for threat hunting. Now comes part 3 and the logs are finally available to the masses. #EntraID #KQL #Security cloudbrothers.info/en/detect-th...
cloudbrothers.info
Detect threats using GraphAPIAuditEvents - Part 3
For a long time now, defenders had the ability to monitor behavior of human- and workload identities in Entra tenants not only through AuditLogs but with high level of insight with the MicrosoftGraphA...
041
Reposted by Fabian Bader
Mobile Jon | Intune, W365, Entra, Security MVP @mobilejon.bsky.social · 11/08/2025
Recently, we announced the finalists for the most special of the #GoldenClippyAwards The #ChuckNorris award is for heroes in multiple areas: @nathanmcnulty.com @fabian.bader.cloud @bindertech.se @knudsenm.bsky.social@mortenknudsen.net Congratulate them/reshare for these rockstars! #MVPBuzz #WPNinjas
032
Fabian Bader @fabian.bader.cloud · 12/08/2025
Defender AV Platform v4.18.25070.5 ◽Enhanced Passive Mode Scanning Behavior ◽Improved Tamper Protection Handling ◽Digital Signature Verification Performance Boost ◽Refined ASR Rule Exclusion Processing #MDAV #MDE #ASR
051
Fabian Bader @fabian.bader.cloud · 24/07/2025
A rare, but highly welcome change. Microsoft changed the license requirement for Token protection from Entra ID P2 to P1. This will protect more customers in the long run and lead to a more secure ecosystem. learn.microsoft.com/en-us/entra/...
learn.microsoft.com
Microsoft Entra Conditional Access token protection explained - Microsoft Entra ID
Learn how to secure your environment with token protection in Microsoft Entra Conditional Access policies.
0104
Fabian Bader @fabian.bader.cloud · 20/07/2025
🚨 PSA - Zero day in SharePoint on-prem is actively exploited! ◽ Have Defender AV active ◽ Don't disable AMSI integration of SharePoint ◽ Keep an eye out for the alerts outlined in the article ◽ Look for post exploitation with the hunting query msrc.microsoft.com/blog/2025/07...
msrc.microsoft.com
Customer guidance for SharePoint vulnerability CVE-2025-53770 | MSRC Blog | Microsoft Security Response Center
Customer guidance for SharePoint vulnerability CVE-2025-53770
061
Reposted by Fabian Bader
Steve Syfuhs @syfuhs.net · 13/07/2025
Part 8053 of eleventy billion on our path to killing NTLM: way way way way way better auditing. support.microsoft.com/en-us/topic/...
support.microsoft.com
Overview of NTLM auditing enhancements in Windows 11, version 24H2 and Windows Server 2025 - Microsoft Support
Summary of new auditing features and deployment details
34612
Reposted by Fabian Bader
Thorsten Butz @thorsten.butz.io · 29/06/2025
What r u doing while cooking? That’s my distraction …. #PSConfEU 2915
042
Fabian Bader @fabian.bader.cloud · 29/06/2025
The latest on the Azure AD Graph retirement mentions two temporary outage tests and more guidance. If something stops working it might be because of those tests. #Entra #AADGraph techcommunity.microsoft.com/blog/microso...
techcommunity.microsoft.com
Azure AD Graph retirement
Migrate your applications using Azure AD Graph APIs scripts to Microsoft Graph before September 2025.
000
Fabian Bader @fabian.bader.cloud · 26/06/2025
One of the results of the joined research with @dirkjanm.io is entrascopes.com Basically the yellow pages for Microsoft first party apps. #TROOPERS25
2256
Reposted by Fabian Bader
Thorsten Butz @thorsten.butz.io · 23/06/2025
"One thing we have learned over years is that the world moves quickly, and building is easy but supporting is hard...." Sydney Smith 2025 #StateOfTheShell #PSConfEU 2025
052
Fabian Bader @fabian.bader.cloud · 22/06/2025
Rerunning my test scenarios for the #TROOPERS25 presentation...
041
Fabian Bader @fabian.bader.cloud · 25/05/2025
Pizza 🍕
A margarita pizza with mozzarella cheese
020
Reposted by Fabian Bader
Nathan McNulty @nathanmcnulty.com · 20/05/2025
Microsoft trying to be like @vxunderground, smh 😂
041
Reposted by Fabian Bader
Kyle Ehmke @kyleehmke.bsky.social · 19/05/2025
Suspicious domain m365sessionlogin[.]com was registered through Njalla on 5/18/25. Domain itself does not resolve, but subdomains login, logon, and office365 indicate hosting at 80.78.30[.]154.
183
Fabian Bader @fabian.bader.cloud · 14/05/2025
The unified IdentityInfo table is the most comprehensive way to identify users and their attributes in the unified SOC experience. You have to onboard your Sentinel workspace AND enable UEBA to take advantage of this in advanced hunting. #xdr #sentinel
031
Fabian Bader @fabian.bader.cloud · 09/05/2025
First time I made it on the @msftsecresponse leaderboard 🍾 msrc.microsoft.com/leaderboard
Made it on #58 of the MSRC leaderboard Q1 2025
290
Fabian Bader @fabian.bader.cloud · 07/05/2025
Planning for some days off from work. What to put in the duffle back beside a good book and some sunscreen? My new favorite card game of course. #FOCI #FamilyOfClientID
a card deck from the back, fanned out, reading "Family of Client IDs" with a tree in the middle
120
Fabian Bader @fabian.bader.cloud · 02/05/2025
Application Based Authentication on Microsoft Entra Connect Sync is near. With this change you will be able to use a TPM backed certificate in Entra Connect Sync for authentication. This is a welcome change to prevent the compromise of this high privileged account. #Entra #Certificate
0102
Reposted by Fabian Bader
Justin Grote @posh.guru · 27/04/2025
I made an Azure version microsoftedge.microsoft.com/addons/detai...
microsoftedge.microsoft.com
Azure X-Ray - Microsoft Edge AddonsYour Privacy Choices Opt-Out Icon
Make Microsoft Edge your own with extensions that help you personalize the browser and be more productive.
1104
Reposted by Fabian Bader
Clément Notin @cnotin.bsky.social · 24/04/2025
Here's (finally!) what I've found about this 😉 bsky.app/profile/cnot...
132
Reposted by Fabian Bader
Ugur Koc @ugurkoc.de · 25/04/2025
👀 Who is Nova? We will find out tomorrow 😉
031
Reposted by Fabian Bader
Merill Fernando 💚 @merill.net · 25/04/2025
Here's another Maester v1.2 teaser. We just added Severity for test results plus the ability to filter by Severity.
0101
Reposted by Fabian Bader
Nathan McNulty @nathanmcnulty.com · 19/04/2025
Looks like Lifecycle Workflows just added the ability to revoke session tokens 💪 Previously, we had to create our own custom extension (Logic App) to do this, so really nice to see it as a built-in task now :) learn.microsoft.com/...
1133
Fabian Bader @fabian.bader.cloud · 14/04/2025
Two new ASR rules are now generally available: ◽Block rebooting machine in Safe Mode ◽Block use of copied or impersonated system tools learn.microsoft.com/en-us/defend...
learn.microsoft.com
What's new in Microsoft Defender for Endpoint - Microsoft Defender for Endpoint
See what features are generally available (GA) in the latest release of Microsoft Defender for Endpoint, and security features in Windows 10 and Windows Server.
051
Fabian Bader @fabian.bader.cloud · 10/04/2025
Microsoft XDR Automatic attack disruption just got better. It now takes into account the device role and criticality to preserve key network functionality while protecting the assets. Plus IP address based containment of undiscovered devices! #XDR techcommunity.microsoft.com/blog/microso...
techcommunity.microsoft.com
Automatic attack disruption: Enhanced containment for critical assets and shadow IT | Microsoft Community Hub
Staying ahead of attackers is tough, as they constantly evolve and use advanced techniques like AI to exploit vulnerabilities. Protecting high-value assets...
030
Fabian Bader @fabian.bader.cloud · 09/04/2025
Happy to join the Workplace Ninja Summit 2025 together with @naunheim.cloud @oudendorp.nl @harjit.bsky.social interviewed us at the #MVPSummit youtu.be/DSYu-4tXaxI #WPNinjaSummit2025
youtu.be
Kicking Off WPNinja Summit 2025: Cybersecurity Insights with Thomas Naunheim & Fabian Bader
YouTube video by WorkPlace Ninja Summit
042
Reposted by Fabian Bader
PSHSummit @powershellsummit.org · 03/04/2025
Only 4️⃣ days until we come together for an epic PowerShell + DevOps experience! 🎉 💡 Learning ✅ 🤝 Networking ✅ 🚀 Growth ✅ 📢 Like, comment, and share to spread the excitement! #seattle #bellevue #powershell #techconference #devops #ai #innovation
0104
Reposted by Fabian Bader
Nathan McNulty @nathanmcnulty.com · 05/04/2025
This is awesome! Microsoft is killing off the ability for multi-tenant applications to authenticate in directories where a service principal has not been registered. learn.microsoft.com/... I'd like to automate discovery and remediation for admins, but I need help testing :)
learn.microsoft.com
Retire Service Principal-Less Authentication - Microsoft identity platform
Learn about the mitigation steps tenant administrators should perform for service principal-less authentication behavior deprecation.
2142
Fabian Bader @fabian.bader.cloud · 04/04/2025
Since it's already April, let's have a look at the top 10 passwords in Q1 2025. If yours is not part of the list, good for you 😅
020
Fabian Bader @fabian.bader.cloud · 02/04/2025
Transition to enhanced modeling of Threat Intelligence data in Microsoft #Sentinel by 31 July 2025 That's a tight schedule, better get started soon.
100
Fabian Bader @fabian.bader.cloud · 01/04/2025
Now in the official documentation. Session ID was long missing from the Entra Signin Logs outside of XDR but since early February 25 we can use it. It already has proven a powerful addition in detecting token theft.
0152