Alex Weinert

88 Followers
17 Following
14 Posts
Microsoft VP Director of Identity Security
Blue sky@alexweinert.bsky.social
Coming out of hibernation to say how excited I am for this - PLEASE END PAT USE: https://devblogs.microsoft.com/devops/introducing-service-principal-and-managed-identity-support-on-azure-devops/
Introducing Service Principal and Managed Identity support on Azure DevOps - Azure DevOps Blog

We are proud to announce that Service Principals and Managed Identities can now be used to authenticate with Azure DevOps. For those who have not heard of them before, these Azure Active Directory identities enable teams to gain access to your Azure DevOps organizations acting as their own application,

Azure DevOps Blog
Many thanks to Praetorian for great research and responsible disclosure Azure B2C Crypto Misuse and Account Compromise - Praetorian https://www.praetorian.com/blog/azure-b2c-crypto-misuse-and-account-compromise/
Azure B2C Crypto Misuse and Account Compromise -

Microsoft’s Azure B2C service misused cryptography, which allowed an attacker to craft an OAuth refresh token to access a victim account.

Praetorian
At long last, posting this Identiverse talk from last year I did with the amazing Nicole Hart regarding the mandate for and challenges in diversity in cyber-defense: https://youtu.be/ozY3PdJeJYM
As Diverse as Our Adversaries: The Mandate, Challenges and Opportunities of Diversifying Leadership

YouTube
Improve identity strategy with Microsoft - Microsoft Security Blog

Learn about the latest identity-based cyberattacks and how your organization can create an integrated, layered defense with Microsoft.

Microsoft Security Blog
https://www.microsoft.com/en-us/diversity/programs/hola-scholarship.aspx this is super cool - if we want to change course, we have to apply rudder.
HOLA at Microsoft Scholarship

HOLA is dedicated to supporting the continued growth and development of Hispanic and Latinx employees and encouraging students to pursue a career in technology.

https://youtu.be/3wtwUh6iyxY super video on phishing resistant credentials from Inbar and Tarek
From Strong To Stronger: Phishing Resistant Authentication Methods (The Blueprint | BRK244

YouTube
Improve identity strategy with Microsoft - Microsoft Security Blog

Learn about the latest identity-based cyberattacks and how your organization can create an integrated, layered defense with Microsoft.

Microsoft Security Blog
I finally got Mastodon on my mobile - feels like coming out of hibernation. Howdy everyone! So much catching up to do!!
HELLO WORLD!