Je hebt een klacht over de onderstaande posting:
de slides pdf is een aanrader! "Conclusions • Entra ID connect on-prem was way more powerful than you thought. • Most attack paths from Entra ID connect are now mitigated. • Exchange hybrid on-prem = Exchange online. • Exchange online has/had unrestricted access in your tenant through S2S actor tokens with impersonation rights. • S2S actor tokens design is messed up, should never have existed and the impersonation should be removed ASAP. • Lack of transparency about internal auth protocols hurts security. • Customers running Exchange hybrid should apply mitigations to reduce the impact."
Beschrijf je klacht (Optioneel):