Microsoft
Continuous Access …
This is a personal blog and all content herein is my own opinion and not that of my employer. Background Continuous Access Evaluation, or CAE, is one of those security controls with a wonderfully descriptive name. Access is not supposed to be evaluated only when you first authenticate. It is …
Daddy Issues: When APIM …
This is a personal blog and all content herein is my own opinion and not that of my employer. Introduction Sometimes security research starts with an exploit. Sometimes it starts with a much more boring question: “Where is the actual security boundary?” This one started with the latter. …
Silent Drip: When Sync …
Hero image generated by ChatGPT This is a personal blog and all content herein is my own opinion and not that of my employer. Background Microsoft Edge introduced Drop as part of its sidebar ecosystem as a quick, frictionless way to share notes and files between signed-in devices using OneDrive …
Announcing ISDF – Intune …
Hero image generated by ChatGPT This is a personal blog. All opinions are my own - not my employer’s. Earlier this year, I published OuttaTune – a deep dive into how Conditional Access (CA) depends on device-sourced metadata and the risks of trusting values that endpoints themselves can …
Turn On, Tune In, Cop …
Hero image generated by ChatGPT This is a personal blog. All opinions are my own - not my employer’s. Introduction This is a follow-up to my original post detailing a security flaw in Microsoft Intune’s Conditional Access (CA) filtering that allows local admin attackers to bypass CA policies by …
OuttaTune: Bypassing …
Hero Image generated by ChatGPT This is a personal blog and all content therein is my personal opinion and not that of my employer. Introduction This post details a security weakness in Microsoft Intune’s Conditional Access (CA) filtering, which allows attackers with local admin privileges to …