Security / Microsoft Defender XDR / Sentinel / Copilot for Security
Entra ID Attack & Defense - Insights and learnings from the playbook project
📅 Wednesday, 27 May 2026🕐 07:15–08:05📍 Lille O
Over the past four years, we have investigated common cloud identity attack scenarios to explain necessary mitigation and detection techniques in Microsoft Entra ID.
In this session, we will share deep-dive insights into this community project, from our approach to shared research to surprising findings from our attack simulations and studies.
We’ll explore primary refresh tokens and other artifacts on Windows devices, privilege escalation paths involving the Microsoft Entra Connect sync server, and other common identity-related threats.
For each scenario, we’ll discuss practical mitigation strategies and demonstrate how to detect suspicious activity using both native Microsoft security capabilities and custom detections.


