TRAINING COURSES

Adversary Perspectives: Azure

iAPM-HeroImage@2x-4_d5476b
APM-MainImage-Azure-@2x

WHAT TO EXPECT

See Azure and Entra ID the way attackers do

Cloud adoption has fundamentally shifted the attack surface, but many security teams still lack the offensive perspective needed to protect Azure environments effectively.

This course teaches participants to understand how adversaries identify and exploit vulnerabilities in Azure and Entra ID infrastructure. Whether you’re a red teamer planning your first cloud engagement or a defender responsible for securing Azure deployments, this foundational knowledge is essential in modern cloud environments where traditional on-premises security strategies no longer apply. Built by practitioners conducting real-world Azure and Entra ID assessments, participants gain practical skills to execute or defend against cloud-based attacks.

key takeaways

Course summary

Before you can emulate or defend against the tactics of an adversary operating in Azure and Entra ID, first you must understand their perspective.

How do premier security operators view Azure’s infrastructure components, common architecture designs, and security controls? Through hands-on labs, this course teaches participants how to identify misconfigurations in Azure and Entra ID that are commonly leveraged by attackers. Participants should expect to walk away from the Adversary Perspectives: Azure course with a strong foundation of Azure and Entra ID security knowledge and having taken their first step in attacking or defending corporate Azure and Entra ID environments.

Participants will learn

Icons-Alert

How to identify misconfigurations in common Azure components, such as virtual machines and function apps

Icons-Cloud

How Entra ID relates to Azure and its role in cloud authentication

Cards-Learn1@2x

How to approach an Azure environment in an offensive security engagement

A CLOSER LOOK AT THE COURSE

Adversary Perspectives: Azure

Organizations have their heads in the clouds, or at least their infrastructure. Gone are the days of on-premises domain controllers and Exchange servers. Microsoft’s Azure provides organizations with the ability to deploy cloud hosts and services to augment, or in some cases, replace existing functionality completely. All of these new cloud assets need protection, both through traditional defensive security measures, and offensive security assessments. For new and veteran security professionals alike, understanding how these new technologies work and the nuances of securing them can quickly become complicated.

Dig into Azure

Adversary Perspectives: Azure provides participants without previous Azure experience with a solid understanding of how attackers look at Microsoft Azure and Entra ID, its authentication mechanisms, and how they commonly attack Azure-based environments.

Carousel1-Azure@2x_4a37ca

Here’s what we’ll cover:

  • Class Introduction
  • Entra ID
  • Application Registration
  • Entra Roles
  • Azure Resource Manager
  • Azure Roles
Azure-Day1@2x_118c4d

Here’s what we’ll cover:

  • Microsoft 365
  • App Services
  • Virtual Machines
  • Microsoft Graph
  • Microsoft Intune
  • OAuth
Azure-Day2@2x_bc0cbe

Here’s what we’ll cover:

  • Hybrid Identities
  • Authentication
  • Device Authentication
  • Passwordless Authentication
  • OIDC
  • Multi-Factor Authentication
Azure-Day3@2x_fce75e

Here’s what we’ll cover:

  • Conditional Access Policies
  • External Information Gathering
  • Credentials
  • PIM
  • Tooling
Azure-Day4@2x_d3ebdf

Overview

Dig into Azure

Adversary Perspectives: Azure provides participants without previous Azure experience with a solid understanding of how attackers look at Microsoft Azure and Entra ID, its authentication mechanisms, and how they commonly attack Azure-based environments.

Carousel1-Azure@2x_4a37ca

Day 1

Here’s what we’ll cover:

  • Class Introduction
  • Entra ID
  • Application Registration
  • Entra Roles
  • Azure Resource Manager
  • Azure Roles
Azure-Day1@2x_118c4d

Day 2

Here’s what we’ll cover:

  • Microsoft 365
  • App Services
  • Virtual Machines
  • Microsoft Graph
  • Microsoft Intune
  • OAuth
Azure-Day2@2x_bc0cbe

Day 3

Here’s what we’ll cover:

  • Hybrid Identities
  • Authentication
  • Device Authentication
  • Passwordless Authentication
  • OIDC
  • Multi-Factor Authentication
Azure-Day3@2x_fce75e

Day 4

Here’s what we’ll cover:

  • Conditional Access Policies
  • External Information Gathering
  • Credentials
  • PIM
  • Tooling
Azure-Day4@2x_d3ebdf

Before you attend

Who should attend

Adversary Perspectives: Azure is intended for security professionals of any experience level looking to learn more about the foundations of Azure security and common attacks against it.

Prerequisites

The course assumes no prior Azure knowledge, though participants should have a basic familiarity with cloud concepts and would benefit from previous exposure to an enterprise Azure environment.

What to bring

Participants must provide their own computer with a modern web browser installed to access training materials and complete the course’s labs. The SpecterOps training platform URL (specterops.training) must be accessible from the participant’s computer throughout the duration of the course.

There are no local virtual machines or special software required to fully participate in the course or labs.

What you receive

During the course, participants receive access to a hands-on training range where they complete labs and work through course objectives.

Upon completion of the course, participants receive:

  • A copy of the course slides
  • A certificate of completion
  • A course challenge coin
  • A digital badge

Accepting your digital badge confirms your SpecterOps Training alumni status, which conveys exclusive discounts to future SpecterOps hosted training.

MORE WAYS TO TRAIN

Private and custom training

SpecterOps courses, delivered exclusively for your team. Need something beyond our current offerings? We develop custom curriculum, labs, and CTFs designed around your team’s specific goals and threat landscape. Our training is taught by the same front-line practitioners who conduct our engagements, bringing real-world experience into every course.

5050-1-AttackPaths_b167b9

 DEEPEN YOUR TRADECRAFT

Explore additional training courses

TrainingPage-ActiveDirectory_9494c3

Adversary Perspectives: Active Directory

Learn Active Directory’s architecture and security implications, and identify misconfigurations before an attacker does.

Learn More
TrainingPage-RedTeam

Adversary Tactics: Red Team Operations

Go beyond Domain Admin and sharpen your offense-in-depth skills.

Learn More
TrainingPage-OffensiveTradecraft

Adversary Tactics: Identity-Driven Offensive Tradecraft

What turns a path into an attack path? Learn how to find and abuse them.

Learn More
TrainingPage-Detection

Adversary Tactics: Detection

Stop chasing indicators. Build detections that focus on how attackers operate.

Learn More
TrainingPage-TradecraftAnalysis

Adversary Tactics: Tradecraft Analysis

Deconstruct how attack techniques really work, then build detections or learn how to evade them.

Learn More

SpecterOps Tradecraft Academy

Hands-on offensive and defensive security training built by SpecterOps practitioners, available on demand and designed to be completed at your own pace.

TradeCraftAcademyLogo@2x_3266ac
Morty Proxy This is a proxified and sanitized view of the page, visit original site.