WEBINARS

Register for an upcoming live event or watch an on-demand webinar anytime!

Upcoming  Webinars

Privilege Escalation in Microsoft Entra ID Webinar 2025 - Register

Privilege Escalation in Microsoft Entra ID: Risks, Exploits, and Solutions

Microsoft Entra ID is central to securing access in Microsoft 365 and Azure, but recent findings reveal vulnerabilities that could let attackers escalate privileges to global admin. This webinar explores how attackers exploit OAuth 2.0 flows, service principal credentials, and misconfigurations to gain unauthorized access.

Learn how to identify and mitigate these threats with real-world examples, and discover practical strategies such as enforcing least privilege, hardening service principals, and strengthening Conditional Access. Stay ahead of evolving risks and secure your Entra ID environment.

Key Takeaways: 

  • Understand the technical details behind privilege escalation vulnerabilities in Microsoft Entra ID.
  • Learn how attackers exploit authentication flows and service principal permissions.
  • Discover best practices for securing your Entra ID environment against unauthorized privilege elevation.
Securing Microsoft Entra ID Applications Webinar 2025 - Register

Securing Microsoft ID Apps: Addressing the Threat of Misconfigured Permissions

Misconfigured app permissions in Microsoft Entra ID pose a significant security risk, enabling attackers to exploit applications with excessive or improperly assigned privileges. This session will delve into the vulnerabilities associated with misconfigurations, such as assigning non-administrative accounts as application owners and granting unconstrained permissions like Mail.ReadWrite or Mail.Send. 

Participants will explore real-world examples, including the Midnight Blizzard attack, which exploited a compromised OAuth application to infiltrate Microsoft’s tenant. 

Attendees will learn actionable strategies to mitigate these threats, including:

  • Implementing stringent access controls for app ownership.
  • Applying the principle of least privilege to app permissions.
  • Utilizing tools such as PowerShell cmdlets and security scanners to enforce application access policies and monitor elevated permissions.
Protecting Against Workload Identity Risks in Entra ID Webinar 2025 - Register

Protecting Against Workload Identity Risks in Entra ID

Workload identities, such as service principals and managed identities, are essential for enabling seamless application-to-application communication in Microsoft Entra ID. However, these identities are increasingly targeted by attackers due to their elevated privileges and lack of robust security controls.

This session will focus on the unique risks associated with workload identities, including their susceptibility to credential misuse and excessive permissions. We will also explore the parallels between securing workload identities and interactive user accounts, emphasizing the importance of applying consistent security measures across both.

Through practical demonstrations and actionable guidance, participants will discover how to:

  • Implement Conditional Access policies tailored for workload identities.
  • Enforce least privilege principles to limit the scope of access for service principals.
  • Monitor and audit workload identity usage to detect suspicious activity.

On-Demand Webinars

App Governance Biomarkers in Entra ID – Your 100-Day Health Check - Recording

App Governance Biomarkers in Entra ID – Your 100-Day Health Check

Watch for a practical session where Microsoft MVPs Nicolas Blank and Alistair Pugin lay out a 100-day roadmap to clean up and secure your Entra ID application environment. They break down key focus areas—Enterprise Apps, App Registrations, Hunting, and Tenant Settings—and give you clear measures of success.
 
In this webinar, you'll learn:

✅How to assess your current Application Governance risk posture
✅Key milestones for your first 100 days of App Gov cleanup
✅Steps to remediate risky app permissions and configurations
✅ Measures of success along the way
The Biggest Problem with Application Governance in Entra ID - View Recording

The Biggest Problem with Application Governance in Entra ID

Alistair and Nicolas explore:

  •  The top 5 challenges of provisioning applications—and how to overcome them
  • 🐶 Why application security is a “Dog Eat Dog” world (and how to protect your org)
  • ⚠️ Critical governance measures you must implement today
  • 🚨 The #1 problem with Application Governance in Entra ID—and how to fix it
Identity Security Predictions for 2025 - Application Governance for Everyone - recording

Identity Security Predictions for 2025: Application Governance for Everyone

Come along to Episode 1 of ENow’s Season 3 of its Preventive Maintenance show to find out what the hosts, Nic and Al, believe companies should focus on in 2025 in the world of Application Governance. They’ll be covering:

  • Where Microsoft sees the world going
  • Does AI really matter in Identity Security
  • Recapping the most significant breaches of 2024
  • And why Application Governance is for everyone

This session will provide you with insight into the future of application governance trends, what tools you should focus on so that you can improve your posture, and, ultimately, what you should be thinking about in 2025.

How to Risk Profile Your Entra ID Enterprise Applications - View Recording

How to Risk Profile Your Entra ID Enterprise Applications

As applications proliferate in Entra ID, organizations' attack surface and risk profile increases. Understanding how to prioritize risks, address vulnerabilities, and create an ongoing governance plan becomes essential for protecting your organization. In this webinar, industry experts Nicolas Blank and Alistair Pugin will walk you through the key steps to create a robust risk profile for your Entra ID applications. 

During this session, you’ll learn how to: 

  • Identify and categorize applications based on their criticality and risk level. 
  • Prioritize actions based on real-world threat scenarios and business impact. 
  • Develop a clear action plan to tackle the most important security risks. 
  • Implement best practices for ongoing risk monitoring using AppGov Score

With the adoption of cloud-based applications and hybrid work environments, the security perimeter is redefined from firewall-based security to Identity based security. Zero Trust offers a more proactive and granular approach to security, assuming that no entity within or outside the network should be trusted without continuous verification. In this session, we explored how Microsoft Entra ID can be leveraged to implement Zero Trust principles for application security. 

We discussed the key benefits of Zero Trust, including: 

  • A unified strategy: Building a security strategy that includes what you already own. 
  • Enhanced security: Protecting your applications from unauthorized access and data breaches. 
  • Reduced risk: Minimizing the impact of security incidents. 
  • Increased productivity: Enabling secure and seamless access to applications. 

Entra ID, the Identity Management platform for all of Microsoft’s Cloud infrastructure and software services, does not only cater to traditional directory services but also application registrations and, more importantly, security. Identity administrators across the globe have been facing the enormous task of understanding application security patterns and practices. While security standards and frameworks like NIST, ISO 27001, and FISMA exist, many organizations are still figuring out how to apply these standards to Entra ID applications specifically. 

This session will give you the confidence to appropriately secure and govern your Entra ID Applications and Identities for an improved security posture and compliance with real-world standards. 

With application deployment in the Microsoft cloud as easy as adding a Teams app, Identity, and Security administrators have been inundated with applications popping up in their tenants, with very little knowledge about what they are and what they do. Yes, you should be worried.

Don't let application security vulnerabilities catch you off guard. Equip yourself with the knowledge and tools to protect your applications and the identities they're tied to in Entra ID.

 

SaaS-Security-Exposed-Entra-ID-App-Discoveries-webinar-recording

SaaS Security Exposed: 265 Days of Alarming Entra ID Application Discoveries

Take advantage of insights that could transform your approach to SaaS application security! With SaaS applications integrated heavily into our Microsoft 365 and Entra ID tenants and user identities, ensuring their security is more critical than ever. 

Understand the 'red flags,' most significant risks, and challenges companies face and unlock the secrets of SaaS Security Posture Management.

Entra ID Governance - Best Practices for Real World Success - Watch On-Demand

Entra ID Governance - Best Practices for Real World Success

Drawing from a decade of practical, hands-on experience with Entra ID (A.K.A. - Azure Active Directory), Nicolas Blank and Alistair Pugin share key strategies and methodologies to streamline Entra ID deployment while ensuring adherence to compliance, bolstered security, and operational efficiency. In this session, we cover: 

  • Defining Clear Policies and Roles 
  • Implementing Robust Access Controls 
  • Designing and enforcing access control mechanisms 
  • Harnessing Entra ID features 
  • Monitoring and Auditing Mechanisms 
  • Addressing User and App Lifecycle Management Challenges 
  • Role Mapping and Privileged Access Management 

Join us for a webinar on Wed, March 20th at 10 am PST, where Alistair Pugin and Nicolas Blank will walk you through how to identify risky apps in your Entra ID tenant and, more importantly – the steps you need to take next to fix and securely configure applications. They’ll focus on things like:

  • How applications are deployed 
  • What security really means in Entra ID 
  • How to make sure that your applications are secured 
  • How to continuously evaluate your Application Security Posture
Identify and Fix Application Security Vulnerabilities in MS Entra ID - ODW

Identify and Fix Application Security Vulnerabilities in Microsoft Entra ID

In this session, Microsoft MVPs Alistair Pugin and Nicolas Blank will explore the top 5 risks associated with application security and more, including: 

  • A break down of the recent "Midnight Blizzard" attack on Microsoft
  • Injection attacks 
  • Broken authentication and session management 
  • Sensitive data exposure 
  • Security misconfiguration 
  • Insufficient logging and monitoring