Eric Woodruff [MS MVP] 

234 Followers
111 Following
102 Posts
#Entra nerd, Microsoft Security MVP, CIDPro certified, ex-MSFT, identity and security enthusiast, part time hiker, full time dad. All opinions expressed are from my cat.
Bloghttps://ericonidentity.com
Twitterhttps://twitter.com/msft_hiker
LinkedInhttps://www.linkedin.com/in/msfthiker
Linktreehttps://linktr.ee/ericonidentity

Anthropic - AI can do cyber without much human.

Me - AI can you help me with this research:

I’ve been finding the #Entra Usage & Insights report useless lately when it comes to #passkey reporting.

Why? It’s broken.

It’s concerning that this seems to be an ongoing issue that isn’t tenant specific and Microsoft hasn’t caught it.

#EntraID

https://ericonidentity.com/2025/09/02/entra-useless-insights-report/

Entra Useless Insights Report - Eric on Identity

Exploring the Entra Usage & Insights report on MFA usage, and the issues with the reports lack of accuracy, as well as a workaround.

Eric on Identity

Going right from @WEareTROOPERS in Heidelberg to @fwdcloudsec in Denver ✈️ - from one excellent conference to another!

I’m looking forward to speaking Monday @ 2:00pm in track 1 on the dangers of #nOAuth, with some new and tweaked slides and talking points!

#Entra #EntraID #infosec #cybersecurity #mvpbuzz

At @WEareTROOPERS I dropped new research on #nOAuth, an abuse of #EntraID that allows you to spoof users in vulnerable SaaS applications.

The attack is still alive and well.

You can read all about it here:

#Entra #M365 #infosec

https://www.semperis.com/blog/noauth-abuse-alert-full-account-takeover

New nOAuth Abuse Alert: Entra Cross-Tenant Saas Apps at Risk

Think nOAuth abuse is old news? We wish. Our recent testing shows that nearly 10% of apps in the Microsoft Entra Gallery remain vulnerable.

Semperis
Really good analysis by @ericonidentity on a fascinating new scam approach that leverages legitimate emails from service providers in a novel (to me at least) way. Read it to learn how it works.
#TheWorkNeverEnds #NewThreatModels #Fraud
https://ericonidentity.com/2025/02/20/an-interesting-m365-billing-scam/
An interesting M365 billing scam - Eric on Identity

A look at a recent spam scam email that I received, trying to understand what mechanism the attacker is using to deliver the scam email.

Eric on Identity

Haven’t been highly active on the socials lately… trying to change that a bit.

En route to #HIPConf24, where I’ll be presenting on #UnOauthorized tomorrow, as well as joining a panel with Thomas Naunheim on workload identities, and having some good hallway conversations. Looking forward to seeing folks!

#Entra #EntraID #infosec

I've been quiet on here for a while, but wanted to share the blog that details much of UnOAuthorized from my #bhusa talk yesterday.

#blackhat #blackhat2024 #EntraID #azure #microsoft365 #microsoft #infosec

https://www.semperis.com/blog/unoauthorized-privilege-elevation-through-microsoft-applications/

Privilege Elevation in Entra ID: UnOAuthorized | Semperis Research

Recent Semperis security research findings reveal a past potential for privilege elevation in Entra ID. Learn more in this article.

Semperis

📣 Blue Team Con 2024 Speaker Highlight 📣

Eric Woodruff
Talk Title: Death By A Thousand Control Planes: The Reality Of Modern Privileged Access

View abstract: https://blueteamcon.com/directory/the-reality-of-modern-privileged-access/

Death by a Thousand Control Planes: The Reality of Modern Privileged Access - Blue Team Con

Learn more about our BTC 2024 talk: Death by a Thousand Control Planes: The Reality of Modern Privileged Access - presented by Eric Woodruff.

Blue Team Con

The obligatory starting my journey to the MVP Summit picture 😜😎

#mvpbuzz #mvpsummit

Thought of the day - when you spend a lot of personal time and effort to speak at a conference in a vendor-neutral spot that you had to really put the work in to earn, the conference management team should in turn exclude you from the list of attendees that they give to sponsors.

I get that most conferences need money, and that most sponsors, if they pay enough, get a list of attendee contact information, but I didn't spend several hours working on a presentation for the community to get a bunch of spam from vendors.

#infosec #conference #cybersecurity #complaining