Video summary
Episode 54 - Unlock the Power of EntraOps: Smarter Identity Security & Privileged Access Management
Main summary
Key takeaways
Summary
The episode explores EntraOps, a community project for understanding privileged access in Microsoft cloud environments and applying the Microsoft Enterprise Access Model—the modern counterpart to Active Directory tiering. The model separates highly privileged control-plane administration from platform and workload access, helping reduce the risk of exposing privileged account credentials or tokens through ordinary user devices.
How EntraOps classifies access
EntraOps does not rely only on role names. It examines:
- Role actions: What a role actually permits, such as disabling a user, changing authentication methods, or managing credentials.
- Assignment scope: Where those permissions apply, such as across a tenant or only within an administrative unit.
- Sensitive resources and context: Signals that help determine whether a role or resource is part of a critical scope.
This approach can reveal unexpected privilege. For example, the speakers discuss how an Authentication Administrator may have broader capabilities than its name suggests, and how the impact of a Group Administrator depends partly on which groups it can change. EntraOps also classifies custom roles by their actions rather than relying on predefined role names.
Features and integrations
- Classification files and Explorer: Public JSON classification data is available in the project repository. The Classification Explorer lets users inspect and compare role classifications, review sensitive actions, and see community-documented attack paths associated with roles. A public web version is available, and organizations can also deploy the code in their own environments.
- KQL and Microsoft Defender XDR: The demonstrated Unified Identity Info KQL function combines identity information from advanced hunting and exposure-management tables with EntraOps classifications. It can enrich information about users, service principals, roles, and permissions.
- Maester: EntraOps classification data is used in Maester checks, including checks for privileged identities and potentially risky assignments. Users can run Maester with the EntraOps tag. The integration uses the relevant query and requires Microsoft Defender XDR and the necessary permissions.
- Reporting and investigation: EntraOps can produce reports explaining why an assignment is considered sensitive, help identify possible tier breaches, and let analysts flag items for later review.
- Operational and security integrations: Results can be stored in a repository to track changes over time, sent to Log Analytics or Sentinel for querying and workbooks, and used with BloodHound. The guest also describes a Copilot agent that helps interpret EntraOps results.
- Automation: EntraOps can run locally or in workflow pipelines. The speakers mention work toward Azure DevOps support and collaboration on a landing-zone automation framework.
Guidance and getting started
The guest’s main recommendation is to learn what roles actually permit, rather than judging them by name. Evaluate both a role’s actions and its scope before assigning it. This supports least-privilege decisions and helps identify high-privilege access on accounts or devices that should not be used for everyday work.
For newcomers, the guest points to entraops.com, which provides an overview, a repository template, and a getting-started guide. Users can test a collection and view reports locally using a static web app; the demo does not depend on a multi-tenant app or the guest’s environment. For Maester, the guest recommends starting with its documentation and interactive setup. The KQL classification query can be run in an environment with the required XDR access.
The guest also recommends manually reviewing changes to cloud role definitions regularly rather than relying on an LLM to determine what changed. The episode’s demo illustrates how EntraOps reports can provide context for investigating sensitive assignments.
Speakers and sources
- Don: Host and cloud security architect at IT impressiv(e); surname unclear in the subtitles.
- Thomas Naunheim: Cybersecurity architect at glueckkanja AG, Microsoft Security MVP, and EntraOps creator and guest.
- Tools and community projects discussed include EntraOps, Microsoft Defender XDR, KQL, Maester, Microsoft Sentinel/Log Analytics, BloodHound, and community research on role-related attack paths.
Rate this summary
Your feedback will help improve summaries.
Improve this summary
Reprocess with a stronger model when the summary feels incomplete or inaccurate.
Translate summary in another language
Ask questions to this video
Chat for follow-up questions, clarifications, and source-backed answers.