Cloud Security with Microsoft 365 Developer Tenants
Key Takeaways
The video demonstrates how to set up and use Microsoft 365 developer tenants for cloud security purposes, utilizing tools such as Microsoft 365 Dev Center, Azure portal, and Microsoft Graph API. It covers topics including two-factor authentication, Azure Active Directory, and access tokens.
Full Transcript
the cloud it's super vague right when you say the word cloud you could mean so many different things and I'll be the first to admit I don't know a whole lot about it all I'm still learning but I do know that a whole lot of folks use Microsoft 365 or Azure active directory now called Microsoft entra ID I think and we could at least get into an environment where we can play with it practice develop maybe test some things and learn all about the cloud and Cloud security so in this video I want to show you how you can easily set up your own Microsoft 365 tenant and start to play with this Cloud security stuff so I am inside of just a flat vanilla Windows 11 virtual machine that we can use as our environment our endpoint to play with but honestly hey we want to be setting up a cloud environment so let me spin up my web browser I'll just use Microsoft Edge cuz hey whatever that's how we got started with this virtual machine and I'm going to go to developer. microsoft.com now I know all this stuff might not be everyone's cup of tea but seriously microsof roft does do a relatively decent job at at least getting information and documentation and safe playgrounds and sandboxes for us to play with in fact we could just go dive into Microsoft 365 and here we are in the Microsoft 365 Dev Center we could go ahead and try to sign in and then create our own Microsoft 365 tenant this way you can administrate your own development environment you can create automations you can learn hey all the things necessary to make this M365 or entra ID class environment work and work with security so if we go actually into the more segment of the navigation on top in the developer program we can simply join now and get started with the Microsoft 365 developer program let me go ahead and click join now we will need to log in with our own Microsoft user account but hey since we're kind of setting up this environment for ourselves for learning in the playground inside of this own virtual machine we can just go and create one super duper simple so it doesn't mess with anything else I'm going to start with a blank slate so let's get a new email address I'll just call this like jh YouTube hopefully that's okay nah how about jh- YouTube how about that I'll create a little bit of a password Here and Now we can sign up and create our account now that we have our own Microsoft account we can join the Microsoft 365 developer program just a couple questions that should be super easy to cruise through we can fill that out accept the terms and conditions and then click on next to say look we are going to be using this for our own personal projects just for our learning and what are we interested in developing uh all the above like hey I want to learn everything give me as much as I can now this will just give you an E5 subscription and license and we can easily spin up just an instant stand boox that gives us everything we need to play with M365 it's preconfigured with fictitious users uh sample data within Microsoft teams and Microsoft graph SharePoint office add-ins everything that we might like so honestly instant sandbox is probably fine for me we can customize the domain name but we should be a okay let's just click on next let's define an admin username let's just call this m 365 admin and whatever password we might want I will note though that this has some pretty bad like password policy stuff it looks like it's limited between 15 and 20 characters so we can just set some stupid thing and then maybe change it later and for the 16 fictitious users we could set a specific password for them rather than reusing the same admin one that I just created this does need to do some phone verification but that's just fine at least it gets to set up with like multiactor indication and all the things for good two-step verification finally after we set up the phone verification we're all done it set up the Microsoft 365 developer program and environment we have our E5 subscription with our own domain name about nine user licenses and 16 fictitious users and we can go add whatever sample data packs we might like now note I know some people might question hey how come you only have 90 days left or however much time available displayed on that little page here look it will automatically Renew at least if you use it like if you play with this if if you go tinker and mess around in the developer environment then it should just automatically hey send you an email that say look everything's good and we've renewed the subscription for you to keep playing in your test bad our tenant is set up and we can go play with this within like the Azure portal or Microsoft entra ID and we can go mess with it on the command line even like hey let's do some of those little hacker stuff you know hey pulling in some Powershell modules and starting to play with the different apis that could use a whole lot of these Microsoft 365 Services let's s into that just after this I do want to give some special love if you're interested in a whole lot more Cloud security let me tell you about whiz it makes Cloud security absolute magic whiz provides a cloud native application protection platform that scans each and every layer of your Cloud environments and gives you complete visibility across all of your technology stack so that you have the big picture and you can focus on what matters most whether or not you're working with AWS or Azure Google Cloud platform vmw V sphere or kubernetes across every single virtual machine container serverless function or data store whz finds the blind spots and gives you more context with less noise because when a threat faces your environment it's not just one isolated issue it's multiple different vulnerabilities or misconfigurations and whiz ties these all together across each Cloud component and uncovers all types of risks whiz streamlines your alerts and routes them to the right people on the right platform and you and your organization can proactively protect your environment you can keep your Cloud secure with whz get started with whiz with my link below in the video description jh. life/ whz huge thanks to whiz for sponsoring this video back in our web browser if we actually try to Now navigate to portal. azure.com we should be able to see as we sign in here with our developer tenant we know we created the account M365 live admin at that domain we can go ahead and log in and let's enter our password hit sign in and oh hey with the conversation of cloud security this is a good thing to do we should set up two fact authentication so I'll get this cruising on my phone here let me just enter the number 15 and that gives us our two factor and security defaults we can stay signed in Here and Now Azure will be loading up for us and if we wanted to hey we could start the tour but I think we're good there it is azure active directory is becoming my Microsoft entra ID not confusing at all now if we click on our little hamburger icon we could probably go dig into that Microsoft entra ID section and here it is we can see our primary domain and the license is set up at the P2 here now we could dig into all of the users and groups here in the graphical user interface over on the web playing in the Azure portal but look we can go also play with this on the command line using some Powershell stuff that might allow us to work with the Microsoft graph API or the stuff under the hood here with that I want to go to aad internal.com and this is one awesome resource where we might be able to go play with hey some M365 hacking and admin toolkits all things in the sake of security here and this is in all honesty just a Powershell module that's put together by some of the super smart incredible folks credit where credit is due this is Dr noori cinea I don't know if I'm getting your name Dr Azure ad but take a look at the documentation for aad internals it's something that we can install super duper easy from just Powershell we can install module aad internals and let's get to it let me fire up on the command line just a simple terminal here we'll get Powershell started and let me install module aad internals M don't forget hey we should run this as an administrator so let's restart Powershell with control shift enter here we go yep we're good to allow this install module aad internals enter on that we can go ahead and hit yes I'm fine with installing that and a I'm cool with the untrusted repository all right that should be cooking and now once I get my prompt back let's clear the screen and let's import module aad internals ah loading scripts is disabled so let's set our execution policy to remote signed and let's try that again looking good there it is here's a super cool Banner for aad internals now back on the documentation let's see how we can play with this and it should be super duper easy just getting into some access tokens if we jump to that playing with access token section we probably can understand a little bit more about this most of the functions are using the rest apis that do require oop access tokens that's how hey Azure or entra ID does a lot of its authentication the aad internal modules is using the following types of access tokens and since version 0.4.0 all tokens are cached if tax save to Cache switch is used looks like there are different kinds of functions or commandlets for any specific apis that we want to hit like Azure active directory graph so we can just use get A8 int access token for aad graph and that is the underlying sort of brain and smarts behind a lot of this so we could try to use that let's use get aad int access tokens for aad graph save to cache and let's try it out I'll copy and paste enter this here there we go okay so now we can just simply log in basically from the command line right let's try to use our M365 admin at our domain and I guess I'm going to have to memorize 2 NT by4 onmicrosoft.com slap that in here and we'll enter our password and now we'll need our two Factor authentication we can just use the phone app notification as we've been doing before so I'll get that on my cell phone here we'll approve the sign in with the given number yep and now we should see that authentication complete and take a look our access token is saved to the cache for the same tenant ID that we saw inside of the portal we can validate that just to see the cash credentials with get aad in cash slap that one in and take a look this is what we working with here now just as a sort of hello world demonstration let's try to Simply list all of the users inside of this tenant we can go back to the documentation here for aad internals and let's just see do we have like a get users command L yeah here it is user manipulation get aad in users this function returns users of the tenant and then we could select kind of whatever we want here let's just grab the users and select their user principal name which at least in the example output is just the email address that we're associating them with get A8 into users and let's select user principal name let's pull all of this down and there it is these are all of our fictitious users that the Microsoft developer program has set up for us here's Alex here's Isaiah here's Diego and here is our M365 admin that we can use to continue to explore poke and play with this environment all in the cloud hey before we wrap things up though let me say credit where credit is due uh this whole walkth through this setup of the M3 365 environment in the developer program uh Kudos all credit Big Ups to Nathan mcnolty who had shared this on Twitter a good little thread here and I believe is also on his blog so look uh we're standing on the shoulders of giants here we always are in this industry but uh again all the credit goes to Nathan for showcasing the startup with that we have opened the door for some more Cloud security content right hey for some opportunity to poke and play with Microsoft Azure or the Microsoft entra ID it's going to take me a while to get used to that but look all those users hey do they have two fact authentication on what are their logins up to are they maybe logging in from some Rogue locations or they shouldn't at odd times or are there any API weaknesses or Securities or misconfigurations that we should be tracking and with that hey we can dig into it but if you don't mind I'd love to hey really recommend you guys go check out whiz sponsor this video they've doing some incredible stuff like what is it the fastest growing cyber security company ever so seriously whiz is phenomenal and I'm super dupy to have them here with us I hope you go create your own Microsoft 365 tenant and I hope we get to play with some more Cloud Security in our own playground test bed and sandbox environment thanks so much for watching I'll see you in the next video
Original Description
https://jh.live/wiz || Get the big picture of your security posture across your entire cloud environment with Wiz and their Cloud Native Application Protection Platform: https://jh.live/wiz
Free Cybersecurity Education and Ethical Hacking
🔥YOUTUBE ALGORITHM ➡ Like, Comment, & Subscribe!
🙏SUPPORT THE CHANNEL ➡ https://jh.live/patreon
🤝 SPONSOR THE CHANNEL ➡ https://jh.live/sponsor
🌎FOLLOW ME EVERYWHERE ➡ https://jh.live/discord ↔ https://jh.live/twitter ↔ https://jh.live/linkedin ↔ https://jh.live/instagram ↔ https://jh.live/tiktok
💥 SEND ME MALWARE ➡ https://jh.live/malware
Watch on YouTube ↗
(saves to browser)
Sign in to unlock AI tutor explanation · ⚡30
Playlist
Uploads from John Hammond · John Hammond · 0 of 60
← Previous
Next →
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
Code Commentaries? PHP to JavaScript in Bash and PHP!
John Hammond
Tutorials? MySQL connection with PHP and Bash!
John Hammond
Variable Naming in Python! Happy Birthday, Linux! Nokia N900!
John Hammond
JavaScript Splits The URL!
John Hammond
HTML Tables in Python!
John Hammond
HTML, Net Shares, GML!
John Hammond
Python 08 Programming Style and Comments
John Hammond
Python 26 Object Oriented Programming
John Hammond
75 Python Tutorials, Out Now!
John Hammond
Batch 14 Mathematical Expressions
John Hammond
Batch 85 Array Append
John Hammond
Batch 86 Array Count
John Hammond
Batch 87 Array Index
John Hammond
Batch 88 Array Insert
John Hammond
Batch 89 Array Remove
John Hammond
Batch 90 Array Reverse
John Hammond
Python [colorama] 00 Installing on Linux
John Hammond
Python [colorama] 09 Cursor Position
John Hammond
Python [hashlib] 02 Algorithms
John Hammond
Python 00 Installing IDLE on Linux
John Hammond
Python [pygame] 11 Rectangular Collision Detection
John Hammond
Python [pygame] 12 Platforming Rectangular Collision Resolution
John Hammond
Python [XML-RPC] 01 Research
John Hammond
Python [pyenchant] 03 Personal Word Lists
John Hammond
FancyURLopener Authentication and User-Agent [urllib] 03
John Hammond
Python 04: PEP8 Coding
John Hammond
Python Challenge! 17 COOKIES
John Hammond
Google CTF 2016: Ernst Echidna
John Hammond
Google CTF 2016: Spotted Quoll
John Hammond
Google CTF 2016: Can you Repo It?
John Hammond
Google CTF 2016: No Big Deal
John Hammond
Google CTF 2016: In Recorded Conversation
John Hammond
Homemade CTF Challenge: 01 "Orchestra"
John Hammond
Homemade CTF Challenge: 02 "Bae's Base"
John Hammond
Homemade CTF Challenge: 03 "Web Hunt"
John Hammond
Homemade CTF Challenge: 04 "UPX"
John Hammond
Homemade CTF Challenge: 05 "The Assumption Song"
John Hammond
Homemade CTF Challenge: 06 "A Brisk Stroll"
John Hammond
Homemade CTF Challenge: 06 "I lost my password!"
John Hammond
web25 :: Mr. Robot : EKOPARTY CTF 2016
John Hammond
web50 : RFC 7230 :: EKOPARTY CTF 2016
John Hammond
misc50 : Hidden inside EKO :: EKOPARTY CTF 2016
John Hammond
Hack The Vote 2016 CTF: Sander's Fan Club [web100]
John Hammond
Hack The Vote 2016 CTF Warpspeed [forensics150]
John Hammond
Juniors CTF 2016 :: Black Suprematic Square
John Hammond
Juniors CTF 2016 :: Six Strange Tales
John Hammond
Juniors CTF 2016 :: Lost Code
John Hammond
Juniors CTF 2016 :: Here Goes!
John Hammond
Juniors CTF 2016 :: Southern Cross
John Hammond
Juniors CTF 2016 :: Clone Attack
John Hammond
Juniors CTF 2016 :: Dirty Repo
John Hammond
Juniors CTF 2016 :: Hackers Blog
John Hammond
Juniors CTF 2016 :: Voting!!!
John Hammond
Juniors CTF 2016 :: The Good, The Bad and The Junkman
John Hammond
Juniors CTF 2016 :: Stop Thief!
John Hammond
Juniors CTF 2016 :: ROFL
John Hammond
Juniors CTF 2016 :: Restriced Area
John Hammond
Juniors CTF 2016 :: Oh SSH!
John Hammond
HackCon CTF 2017 TRIVIA and BONUS Challenges
John Hammond
HackCon CTF 2017 "Bacche" Challenges
John Hammond
More on: AI Security
View skill →Related Reads
📰
📰
📰
📰
Secured MCP Complete Guide: OWASP Top 10, Best Practices, Security Guardrails, and Compliance
Medium · AI
Whose ASN Goes on Your Leased IPv4 Prefix?
Dev.to · Artem Kohanevich
Blank Identifier: Idiomatic Go or Vulnerability Trap?
Medium · Cybersecurity
Kinetix Browser Review: The Ultimate Solution for Fast, Secure, and Private Web Surfing
Medium · Machine Learning
🎓
Tutor Explanation
DeepCamp AI