Nathan McNulty

1.2K Followers
192 Following
354 Posts
Protecting Auth Tokens

Authenticating to websites in browsers is complicated. There are numerous different approaches: the popular “Web Forms” approach, where username and password (“credentials”)…

text/plain

As promised, here is my deep dive into the Microsoft Enterprise Single Sign On (SSO) plug-in for Apple devices

This works on all Apple devices including iOS, iPadOS & macOS!

Windows users have long enjoyed SSO, now you can bring that experience to your Apple users 😍

Read on ⬇️

Pretty excited to share a new post on a lesser known Intune feature! :)

Microsoft Tunnel can do full device or per-app tunneling on iOS and Android, providing access to on-prem resources, restricted cloud resources, or ensuring access to SaaS apps come from a known, trusted set of IPs 🔥

https://blog.nathanmcnulty.com/intune-microsoft-tunnel-vpn-gateway/

#NathansBlog

Intune - Microsoft Tunnel VPN Gateway

A really neat but lesser known feature of Intune is Microsoft's Tunnel VPN solution which can do full device or per-app VPN tunneling on iOS and Android. This allows us to provide access to on-prem resources, restricted cloud resources, or ensure access to SaaS apps are coming from a known,

Nathan McNulty

In case it's helpful for anyone else, I quickly documented how to create a CA for your lab

OpenSSL offline root CA, ADCS as Intermediate CA, and for fun, GitHub + Azure Static Website to host the CRLs :p

Microsoft Tunnel and EAP-TLS posts in the works :)

https://blog.nathanmcnulty.com/lab-certificate-authority-setup/

Lab - Certificate Authority Setup

I know there are hundreds of posts out there on how to do this, but I really documented this for my future self as something that is really fast, easy, and repeatable when I need to stand up a lab for testing with Azure AD and Intune :) 💡I am not

Nathan McNulty

Hey #AzureAD admins - We can now automate clean up of stale devices!

Microsoft updated the Delete device API endpoint to support Application permissions, so I've rewritten my Azure Automation blog post

Also new: Managed Identities and Graph V2 modules :)
https://blog.nathanmcnulty.com/azure-automation-device-cleanup-v2/

Just published my follow up post for setting up Azure AD SSO to AWS for Single-Account access, also using PIM for Groups :)

This one is really cool because of this regex used to create the SAML claim:
AWS-(?'accountid'[\d]{12})-(?'role'[\w])

Even if you don't use AWS, this technique can be applied to other apps that use Roles in SAML claims, like Splunk

https://blog.nathanmcnulty.com/aws-pim-single-account-access/

#NathansBlog

AWS - Integrating PIM with Azure AD SSO for AWS Single-Account Access

Previously I showed how we can configure SAML SSO with AWS IAM Identity Center which can make many things easier, especially for larger companies, but it may not be an ideal fit for smaller companies who have one or two accounts and want to manage groups, permissions, and governance in

Nathan McNulty

It works! 🥳

Last two pieces that did the trick: a HAADJ session host needs the *on-prem* user added to the Remote Desktop Users group, not the AAD user (which can be added as a SID converted from AAD Object ID but it doesn't work for this use case).

Duo's Windows application had to be removed. Otherwise the RDP session would start but not sign you in - you just connected to the session host's local console output.

Did you know the Recon SOC sends out a monthly newsletter about trending threats and mitigations?

No sales or marketing--just immediately useful information for IT teams✌️💙🤓

Interested? Sign up here: https://reconis.co/3GNvXaE

Form

Just published a new blog post on setting up AWS SSO with Azure AD leveraging Privileged Access Groups to provide just-in-time access and approval workflows

This concept can be used for any Azure app, so it's still an interesting read even without AWS :)

https://blog.nathanmcnulty.com/aws-pim-iam-identity-center/

#NathansBlog

AWS - Integrating PIM with Azure AD SSO for AWS IAM Identity Center

I've been working in AWS a fair bit lately (Defender for Cloud posts coming soon) and thought it would be fun to set up SSO from Azure AD. But I also wanted to see if there was a way I could integrate Privileged Identity Management into it for just in

Nathan McNulty
I cannot sum this up more perfectly than @nathanmcnulty ”Microsoft can't even block email from attacker infrastructure, but sure, let's block known legitimate businesses” re: https://www.bleepingcomputer.com/news/security/exchange-online-to-block-emails-from-vulnerable-on-prem-servers/
Exchange Online to block emails from vulnerable on-prem servers

Microsoft is introducing a new Exchange Online security feature that will automatically start throttling and eventually block all emails sent from "persistently vulnerable Exchange servers" 90 days after the admins are pinged to secure them. 

BleepingComputer