

Understanding Identity & Token Compromise in Entra ID
Who Should Attend
SOC Analysts
Threat Hunters
Detection Engineers
Incident Responders
Security Engineers
Identity & Access Management Teams
Security Operations Leaders
Why Should You Attend
Real-world lessons from major identity compromise incidents including Storm-0558, Midnight Blizzard, Scattered Spider, and Storm-2372.
Understand why attackers are targeting identity trust decisions instead of traditional vulnerabilities.
Learn how tokens, OAuth applications, service principals, and device-code authentication are abused.
Discover the Entra ID logs and telemetry critical for detecting identity compromise.
Learn practical detection rules using Sign-in Logs, Audit Logs, and Identity Protection telemetry.
Understand why password resets and MFA revocation may not be enough to stop an active token compromise.
Identify forgotten OAuth applications and excessive permissions before attackers exploit them.
Agenda
Session 1: The Token Is the New Password – Understanding Modern Identity Attacks
Session 2: Six Real-World Identity Breaches – How Attackers Exploited Trust
Session 3: The Token Layer – Why Password Resets Aren’t Enough
Session 4: Building Identity Detection Rules in Entra ID
Session 5: The Forgotten Blind Spots – OAuth Apps, Service Principals & Consent
Session 6: What Your Detections Still Can’t Catch
Q&A and Closing Remarks