TRAINING COURSES
Adversary Perspectives: Azure
WHAT TO EXPECT
See Azure and Entra ID the way attackers do
Cloud adoption has fundamentally shifted the attack surface, but many security teams still lack the offensive perspective needed to protect Azure environments effectively.
This course teaches participants to understand how adversaries identify and exploit vulnerabilities in Azure and Entra ID infrastructure. Whether you’re a red teamer planning your first cloud engagement or a defender responsible for securing Azure deployments, this foundational knowledge is essential in modern cloud environments where traditional on-premises security strategies no longer apply. Built by practitioners conducting real-world Azure and Entra ID assessments, participants gain practical skills to execute or defend against cloud-based attacks.
key takeaways
Course summary
Before you can emulate or defend against the tactics of an adversary operating in Azure and Entra ID, first you must understand their perspective.
How do premier security operators view Azure’s infrastructure components, common architecture designs, and security controls? Through hands-on labs, this course teaches participants how to identify misconfigurations in Azure and Entra ID that are commonly leveraged by attackers. Participants should expect to walk away from the Adversary Perspectives: Azure course with a strong foundation of Azure and Entra ID security knowledge and having taken their first step in attacking or defending corporate Azure and Entra ID environments.
Participants will learn
How to identify misconfigurations in common Azure components, such as virtual machines and function apps
How Entra ID relates to Azure and its role in cloud authentication
How to approach an Azure environment in an offensive security engagement
A CLOSER LOOK AT THE COURSE
Adversary Perspectives: Azure
Organizations have their heads in the clouds, or at least their infrastructure. Gone are the days of on-premises domain controllers and Exchange servers. Microsoft’s Azure provides organizations with the ability to deploy cloud hosts and services to augment, or in some cases, replace existing functionality completely. All of these new cloud assets need protection, both through traditional defensive security measures, and offensive security assessments. For new and veteran security professionals alike, understanding how these new technologies work and the nuances of securing them can quickly become complicated.
Dig into Azure
Adversary Perspectives: Azure provides participants without previous Azure experience with a solid understanding of how attackers look at Microsoft Azure and Entra ID, its authentication mechanisms, and how they commonly attack Azure-based environments.
Here’s what we’ll cover:
- Class Introduction
- Entra ID
- Application Registration
- Entra Roles
- Azure Resource Manager
- Azure Roles
Here’s what we’ll cover:
- Microsoft 365
- App Services
- Virtual Machines
- Microsoft Graph
- Microsoft Intune
- OAuth
Here’s what we’ll cover:
- Hybrid Identities
- Authentication
- Device Authentication
- Passwordless Authentication
- OIDC
- Multi-Factor Authentication
Here’s what we’ll cover:
- Conditional Access Policies
- External Information Gathering
- Credentials
- PIM
- Tooling
Before you attend
Who should attend
Adversary Perspectives: Azure is intended for security professionals of any experience level looking to learn more about the foundations of Azure security and common attacks against it.
Prerequisites
The course assumes no prior Azure knowledge, though participants should have a basic familiarity with cloud concepts and would benefit from previous exposure to an enterprise Azure environment.
What to bring
Participants must provide their own computer with a modern web browser installed to access training materials and complete the course’s labs. The SpecterOps training platform URL (specterops.training) must be accessible from the participant’s computer throughout the duration of the course.
There are no local virtual machines or special software required to fully participate in the course or labs.
What you receive
During the course, participants receive access to a hands-on training range where they complete labs and work through course objectives.
Upon completion of the course, participants receive:
- A copy of the course slides
- A certificate of completion
- A course challenge coin
- A digital badge
Accepting your digital badge confirms your SpecterOps Training alumni status, which conveys exclusive discounts to future SpecterOps hosted training.
MORE WAYS TO TRAIN
Private and custom training
SpecterOps courses, delivered exclusively for your team. Need something beyond our current offerings? We develop custom curriculum, labs, and CTFs designed around your team’s specific goals and threat landscape. Our training is taught by the same front-line practitioners who conduct our engagements, bringing real-world experience into every course.
DEEPEN YOUR TRADECRAFT
Explore additional training courses
Adversary Perspectives: Active Directory
Learn Active Directory’s architecture and security implications, and identify misconfigurations before an attacker does.
Adversary Tactics: Red Team Operations
Go beyond Domain Admin and sharpen your offense-in-depth skills.
Adversary Tactics: Identity-Driven Offensive Tradecraft
What turns a path into an attack path? Learn how to find and abuse them.
Adversary Tactics: Detection
Stop chasing indicators. Build detections that focus on how attackers operate.
Adversary Tactics: Tradecraft Analysis
Deconstruct how attack techniques really work, then build detections or learn how to evade them.
SpecterOps Tradecraft Academy
Hands-on offensive and defensive security training built by SpecterOps practitioners, available on demand and designed to be completed at your own pace.