Sign in

Thomas Naunheim

@naunheim.cloud
849 followers 191 following 55 posts

#Microsoft MVP | #CloudSecurity Architect ☁️ | #Entra #AzureAD 🔑 + #AzureSecurity 🛡️ | #CommunityRocks | #Schaengel

PostsRepliesMedia
Thomas Naunheim @naunheim.cloud · 09/09/2026
Do you have your Control Plane under control? 🚨 #EntraOps 1.0 is now available 🚀 - an open-source platform to govern and monitor your Enterprise Access Model in #MicrosoftEntra: entraops.com. Here is what’s new in this release 👇
010
Thomas Naunheim @naunheim.cloud · 15/06/2026
Speaking at #TROOPERS26 next week and I can't wait. Joining @martinsohn.dk to talk about attack paths to #PAW and real-world risks of tiered admin models with #IntuneRBAC. Plus something we've been working on for months... See you in Heidelberg! www.troopers.de #EntraOps #Bloodhound
001
Thomas Naunheim @naunheim.cloud · 31/01/2026
[New blog post] Analyzing #MicrosoftEntra 🤖 Workload Identity Activity Through 🪙 Token-Based Hunting: I’ve published a #KQL function to hunt activities by tokens from non-human identities and share some experimental queries and insights in this article. www.cloud-architekt.net/token-huntin...
cloud-architekt.net
Analyzing Workload Identity Activity Through Token-Based Hunting
This post introduces the MicrosoftCloudWorkloadActivity KQL function and shows how to hunt token-based activity of workload identities across Microsoft cloud workloads. It covers key parameters, filte...
031
Reposted by Thomas Naunheim
Fabian Bader @fabian.bader.cloud · 02/01/2026
#ConsentFix is a great way for attackers to work around some protective layers but not all. @naunheim.cloud , @cbrhh.bsky.social and I wrote a blog post on detection and mitigations. Hope you find it useful and can adapt it to your environment. www.glueckkanja.com/de/posts/202...
083
Thomas Naunheim @naunheim.cloud · 02/11/2025
Had the great privilege and a lot of fun joining 🎙️#EntraChat together with my friend and MVP fellow @samilamppu.bsky.social! 🙏 Big thanks to @merill.net for having us - it was a pleasure to be part of the podcast. I hope everyone listening enjoyed it as much as we did recording it!
061
Thomas Naunheim @naunheim.cloud · 30/07/2025
3️⃣ 🛠️ Enhanced Enrichment Function Recently, I've released a #KQL function integrating #ExposureManagement and #EntraOps data to identify sensitive callers, actions, and targets. Updated to support parameters like IP Address and Token Identifier. 🔗 github.com/Cloud-Archit...
000
Thomas Naunheim @naunheim.cloud · 30/07/2025
2️⃣ 🔍 Normalized schema for shared queries Want to reuse existing queries or unify detection logic across both tables? I’ve published a #KQL function that normalizes the schema of GraphApiAuditEvents to match that of MicrosoftGraphActivityLogs. 🔗 github.com/Cloud-Archit...
100
Thomas Naunheim @naunheim.cloud · 30/07/2025
1️⃣ 🤔 Comparison Deep Dive What are the differences between GraphApiAuditEvents (XDR) and MicrosoftGraphActivityLogs (Diagnostic Logs in hashtag#MicrosoftSentinel)? I’ve built a comparison table outlining the differences in column availability and detail levels.
100
Thomas Naunheim @naunheim.cloud · 30/07/2025
The availability of GraphApiAuditEvents in #MicrosoftDefender brings significant value to every environment, enhancing capabilities for detecting and hunting #MicrosoftGraph API calls. In my recent research, I’ve created a few resources that I’m happy to share with the community.
100
Thomas Naunheim @naunheim.cloud · 17/07/2025
4. IsSensitiveTarget 🎯 The modified object is classified as critical (based on Exposure Management Critical Assets), and the applied rule details are displayed. In this case, the service principal has been assigned critical app permissions in Exchange Online.
000
Thomas Naunheim @naunheim.cloud · 17/07/2025
3. IsSensitiveAction ▶️ The Graph request includes a POST to the servicePrincipal endpoint, which is flagged as a sensitive modification. This logic is experimental and simplified, so it may result in inaccurate classification and should be used in combo with others indicators.
100
Thomas Naunheim @naunheim.cloud · 17/07/2025
2. IsHighSensitiveScope 🔑 However, the scope includes Application.ReadWrite.All, which has been identified as "Control Plane" by using EntraOps classification model.
100
Thomas Naunheim @naunheim.cloud · 17/07/2025
In the following example, several indicators are included that make this particular call interesting for further investigation: 1. IsSensitiveCaller 🗣️ A regular enterprise user (based on Exposure Management Critical Asset information) is calling Graph.
100
Thomas Naunheim @naunheim.cloud · 17/07/2025
I've created an experimental KQL function that enriches the data with details from #ExposureManagement and #EntraOps. This might help identify sensitive Graph Calls from the large volume of events in this table. 🔗 The query is available here: github.com/Cloud-Archit...
github.com
100
Thomas Naunheim @naunheim.cloud · 17/07/2025
🚀🔎 Track Sensitive Graph API Calls with my new #KQL Function for #MicrosoftDefenderXDR Microsoft has released the new advanced hunting table "GraphAPIAuditEvents" which offers great opportunities to investigate activities based on #MicrosoftGraph API calls.
132
Thomas Naunheim @naunheim.cloud · 17/05/2025
My session, “Defending Tier 0: Taking Control of Your Cloud’s Control Plane,” from last year’s #HIPConf is now available on YouTube. The session focused on securing privileged access and implementing a tiered administration model in #MicrosoftEntra. youtu.be/pVPEieHtOVM
youtu.be
Defending Tier 0: Taking Control of Your Cloud's Control Plane
YouTube video by Semperis
051
Thomas Naunheim @naunheim.cloud · 09/04/2025
I have integrated the classification model of #EntraOps to identify sensitive roles in #MicrosoftEntra, #MicrosoftGraph, and #AzureRBAC. This function offers a holistic view and report on SPs including details such as ownership and assigned Azure Roles (enriched by CSPM data). (2/2)
010
Thomas Naunheim @naunheim.cloud · 09/04/2025
I've published a #KQL function ("WorkloadIdentityInfoXDR") for #MicrosoftDefender to enhance details of #MicrosoftEntra #WorkloadID from various sources, incl. the new table "OAuthAppInfo" but also IdentityInfo table and #ExposureManagement. (1/2) 🔗 github.com/Cloud-Archit...
111
Thomas Naunheim @naunheim.cloud · 08/04/2025
Cloud #IdentitySummit 2025 is back! Save the date and join this community event with #IdentitySecurity, #MicrosoftEntra, and #CloudIdentity deep dive sessions in Dortmund, Germany. Call for Papers is open now: sessionize.com/cloud-identi... Stay tuned for more details: www.identitysummit.cloud
031
Thomas Naunheim @naunheim.cloud · 17/03/2025
Check out my community tool #EntraOps if you are interested to get a customized and detailed analysis of all permanent and PIM-managed role assignments in #EntraID, #Intune and #IdentityGovernance: www.cloud-architekt.net/entraops/
cloud-architekt.net
EntraOps Privileged EAM
Community project to classify, identify and protect your privileges based on Enterprise Access Model (EAM)
000
Thomas Naunheim @naunheim.cloud · 17/03/2025
There are some current limitations on this preview (for example, custom or scoped roles are not covered, data seems to be available in MDI tenants only). However, the new column offers some great capabilities at no additional implementation efforts.
100
Thomas Naunheim @naunheim.cloud · 17/03/2025
-🚨 Discovering alerts of privileged users with active or assigned roles, along with details on related roles and their highest access tier classification. - 🕓 Determine which eligible or active roles were assigned at a specific time, and compare them to their current status
100
Thomas Naunheim @naunheim.cloud · 17/03/2025
This enables powerful hunting queries, such as: -⚡️ Identifying assigned roles that include specific actions (e.g., reading BitLocker keys). - 🦸‍♂️ Listing all eligible assignments for Control Plane (Tier0) roles, including Microsoft role categories and assignment types (direct or indirect).
100
Thomas Naunheim @naunheim.cloud · 17/03/2025
IdentityInfo table in #MicrosoftDefender has been expanded to include eligible roles from #MicrosoftEntra. I’ve developed a #KQL function to get a summarized overview of all directory role assignments, enriched with details from my #EntraOps classification: github.com/Cloud-Archit...
140
Thomas Naunheim @naunheim.cloud · 08/03/2025
Thank you to everyone who joined my session in Amsterdam or via livestream! Huge thanks to the Yellowhat organizers for this incredible conference and for having me. I had an awesome time and can’t wait to see you all soon…
010
Thomas Naunheim @naunheim.cloud · 08/03/2025
I had the great pleasure of speaking about #MicrosoftEntra Token Hunting 🍪🔎 at #YellowHat 🚧👷‍♂️. You can find the slides from my session here: 📄 github.com/Cloud-Archit... All #KQL sample queries are available in my repo: 👨‍💻 github.com/Cloud-Archit...
172
Thomas Naunheim @naunheim.cloud · 26/02/2025
I have the great pleasure of joining a shared session with @samilamppu.bsky.social at the M365 Security & Compliance User Group tonight. Last preparations are now in full swing... You can find more details about the meetup and register for this free online event here: www.meetup.com/m365sandcug/...
030
Thomas Naunheim @naunheim.cloud · 11/02/2025
Interested to learn more? I'll be talking about token hunting at #Yellowhat and covering how to leverage these new sign-in details. More details about this free community event can be found here: yellowhat.live (3/3)
yellowhat.live
Yellowhat
Yellowhat is a cutting-edge cybersecurity event dedicated to Microsoft Security Technology, offering advanced deep-dive sessions (level 400+) for seasoned professionals. It brings together experts and...
010
Thomas Naunheim @naunheim.cloud · 11/02/2025
Previously, these details were only available in XDR Hunting table "AADSignInEventsBeta", Portal and/or Graph API. These added properties offer the opportunity to write new analytics rules and hunting queries, for example in the area of #TokenTheft. (2/3) learn.microsoft.com/en-us/azure/...
learn.microsoft.com
Azure Monitor Logs reference - SigninLogs - Azure Monitor
Reference for SigninLogs table in Azure Monitor Logs.
110
Thomas Naunheim @naunheim.cloud · 11/02/2025
Enhancements in #MicrosoftEntra (diagnostic) logs: Several interesting sign-in properties (including Session ID, status for Token Protection, or GSA traffic) have been added to the sign-in logs and available in #MicrosoftSentinel. (1/3)
132
Reposted by Thomas Naunheim
Ugur Koc @ugurkoc.de · 29/01/2025
I'm building a new home for IntuneBrew and would like to share my progress so far. IntuneBrew.com will serve as the project's landing page, featuring a Quick Start Guide and an overview of key features.
2114
Thomas Naunheim @naunheim.cloud · 29/01/2025
EntraOps repository: github.com/Cloud-Archit... Learn more about XSPM and Graph: Deep Dive blog post on XSPM by @samilamppu.bsky.social samilamppu.com/2024/04/25/m... Blog posts by @fabian.bader.cloud cloudbrothers.info/en/workshop-... cloudbrothers.info/en/find-late... Kusto Graph rocks! (3/3)
lnkd.in
LinkedIn
This link will take you to a page that’s not on LinkedIn
021
Thomas Naunheim @naunheim.cloud · 29/01/2025
This also shows the classification of the owner by identified privileges in EntraOps and applied rules in Critical Asset Management in XSPM. The query can be extended to analyze potential attack paths in combination with other edges. (2/3) KQL sample query: github.com/Cloud-Archit...
github.com
AzureSentinel/Hunting Queries/EID-PrivilegedIdentities/EntraOpsGraphPrivilegedObjectOwner at main · Cloud-Architekt/AzureSentinel
Sharing my KQL queries for Azure Sentinel. Contribute to Cloud-Architekt/AzureSentinel development by creating an account on GitHub.
100
Thomas Naunheim @naunheim.cloud · 29/01/2025
Do you like to know if ownership of privileged objects in #MicrosoftEntra has been delegated to lower privileged users? Graph semantics in KQL and XSPM allow building powerful queries and analyzing data as graphs. I've started to include data from #EntraOps to analyze delegated ownership. (1/3)
141
Thomas Naunheim @naunheim.cloud · 23/01/2025
Final touches and rehearsal for my #TECTalk on #TokenSecurity in #MicrosoftEntra tonight. I'll be discussing attack scenarios on various token types and how TPM, Token Protection, CAE & Global Secure Access can help prevent token theft. Register for the free webinar: www.quest.com/event/the-ex...
021
Thomas Naunheim @naunheim.cloud · 17/01/2025
How can you detect and mitigate #MicrosoftEntra Compliant Device Bypass in the #MicrosoftIntune Company Portal? What are the potential attack paths? @fabian.bader.cloud, @cbrhh.bsky.social and I had additional research and summarized our results in this blog post: www.glueckkanja.com/blog/securit...
glueckkanja.com
Compliant Device Bypass in Microsoft Intune – Detection, Response & Mitigation
In this blog post, glueckkanja's MVP Fabian Bader, Chris Brumm and Thomas Naunheim gather details about the Compliant Device Bypass in Microsoft Intune Company Portal. After additional research, they ...
1266
Thomas Naunheim @naunheim.cloud · 09/01/2025
📢 Stay tuned for a special announcement later this month if you are interested to learn more about the playbook project and content!
000
Thomas Naunheim @naunheim.cloud · 09/01/2025
#MicrosoftEntra Attack & Defense Playbook Update: @samilamppu.bsky.social and I have updated some content: 🔃 #EntraConnect: New capabilities by MDI sensor & XSPM 🎯 #AiTM: Attack scenarios on MDA sessions 🛡️ #MITRE: Updated TTP coverage & map Check out the latest version: github.com/Cloud-Archit...
github.com
GitHub - Cloud-Architekt/AzureAD-Attack-Defense: This publication is a collection of various common attack scenarios on Microsoft Entra ID (formerly known as Azure Active Directory) and how they can b...
This publication is a collection of various common attack scenarios on Microsoft Entra ID (formerly known as Azure Active Directory) and how they can be mitigated or detected. - Cloud-Architekt/Azu...
1106
Reposted by Thomas Naunheim
MC2MC @mc2mc.be · 20/12/2024
We’re excited to announce the next speakers for MC2MC Connect: @naunheim.cloud and @ugurkoc.de 🚀 In their session, they’ll show how to configure Platform SSO in Intune and highlight its benefits for user experience and security. 🎟️ tinyurl.com/5dxvnsn4 #MC2MC #ConnectMC2MC
043
Thomas Naunheim @naunheim.cloud · 17/12/2024
Am 11.04.2025 findet die #ExpertsLiveDE in Leipzig statt, mit vielen spannenden Vorträgen zu Cloud, Workplace, AI und Security. Ich freue mich sehr, dieses Jahr dabei sein zu dürfen und über #TokenTheft in #MicrosoftEntra sprechen zu dürfen. Weitere Infos sowie Tickets: www.expertslive.de
051
Reposted by Thomas Naunheim
Fabian Bader @fabian.bader.cloud · 02/12/2024
March 6th 2025 👷👷‍♀️👷‍♂️ #YellowHat yellowhat.live
yellowhat.live
Yellowhat | Cyber Conference
172
Thomas Naunheim @naunheim.cloud · 27/11/2024
Do you like to learn more about tokens and ways to protect them in #MicrosoftEntra? Join my #TECTalk on January 23rd to explore the various kind of token artifacts, post authentication attacks and mitigations to prevent #TokenTheft. Register for free at www.quest.com/event/the-ex...
092
Reposted by Thomas Naunheim
Merill Fernando 💚 @merill.net · 26/11/2024
So who wants a verified 'Microsoft' and 'Microsoft MVP' label on their profile and all the posts? I just finished setting up @bluesky.ms as a labelling service. Go subscribe to the label to start seeing labels on verified MVPs and Microsofties. 🧵👇
102466162
Thomas Naunheim @naunheim.cloud · 27/11/2024
New Release: #EntraOps 0.3.3! 🚀 This update includes bug fixes and enhancements to #MicrosoftSentinel workbooks and nested #MicrosoftEntra PIM for Groups. Get the latest version from the GitHub repository: github.com/Cloud-Archit...
0111
Thomas Naunheim @naunheim.cloud · 26/11/2024
Unfortunately, YouTube does not allow me to add links for videos on my brand new channel (yet). Here's the link to the GitHub repository: github.com/Cloud-Archit...
github.com
GitHub - Cloud-Architekt/AzureAD-Attack-Defense: This publication is a collection of various common attack scenarios on Microsoft Entra ID (formerly known as Azure Active Directory) and how they can b...
This publication is a collection of various common attack scenarios on Microsoft Entra ID (formerly known as Azure Active Directory) and how they can be mitigated or detected. - Cloud-Architekt/Azu...
0102
Thomas Naunheim @naunheim.cloud · 26/11/2024
Celebrating 4 years of the "#MicrosoftEntra Attack & Defense Playbook" 🔐 ☁️ community project! Last week, @samilamppu.bsky.social and I took the opportunity to record a video about the journey of this project, from research to writing process. #MVPBuzz #TechCommunity www.youtube.com/watch?v=fBD1...
youtube.com
Microsoft Entra ID Attack & Defense Playbook with Sami Lamppu
YouTube video by Thomas Naunheim
2173
Thomas Naunheim @naunheim.cloud · 25/11/2024
Next week, I have the great pleasure to speak together with @gregorreimling.bsky.social at APE XXL in Apenheul, NL. We'll be sharing best practices in various design areas of #Azure #EnterpriseScale. Get your tickets for a day full of #Azure breakout sessions and workshops: xxl.azure-ape.nl
020
Thomas Naunheim @naunheim.cloud · 23/11/2024
Sorry, missed your comment. I hope you enjoyed the game. See you next time… safe travels back home!
100
Thomas Naunheim @naunheim.cloud · 23/11/2024
MVPs 🤓 meets a MVP 🏀 @gregorreimling.bsky.social, @samilamppu.bsky.social
150
Thomas Naunheim @naunheim.cloud · 22/11/2024
Just wrapped up day 3 of #MSIgnite with @adrianritter.bsky.social, @okieselb.bsky.social and @ugurkoc.de. Our latest video covers all the recent announcements and sessions about SSE, Data Governance, Intune's AI management on macOS, and #Copilot. Tune in! youtu.be/wjri-1EvPSw?...
youtu.be
Microsoft Ignite 2024 - Day 3 Recap
YouTube video by Thomas Naunheim
092