Six Degrees of Global Admin at Nullcon
In Windows and Active Directory, there is one system responsible for making access decisions in nearly *all* cases: the Security Reference Monitor. This system makes access decisions by analyzing security descriptors on securable objects and User Rights Assignments:
In "Azure", the story is very, very different. There are multiple forms of access control, and multiple services responsible for making access decisions.
"Azure" means the 600+ distinct services that comprise Microsoft's cloud computing platform.
Understanding who has control of any given object in any given Azure service requires a complete understanding of *all* of these systems and how they cooperate with one another.?
Whether you're an attacker or defender, I will explain and demonstrate in my?@nullcon?talk how graphs bring accurate and clear understanding of effective permissions in Azure.
You can register for?@nullcon?here:?