BSides Canberra 2026

Malicious Entra ID Apps - what they are, how to find them and how to stop them
2026-09-26 , Off-Main Track

We've all heard of password guessing and MFA bypass techniques that are used to attack M365 - but those are old news now! The newer and more interesting vector - to both attackers and defender alike - are malicious Entra ID (formerly Azure AD) apps. In this presentation I'll explain what Entra ID apps are (and what makes some malicious), how attackers trick users/victims into registering them, how you can find any that may already be in your environment, and what you can do to stop more in the future.

This presentation is designed for technical audiences (or those wanting to become technical) to understand an emerging vector and what can be done to defend against them. The content is based on both our firsthand experience (as both attackers and defenders) as well as that from our partners.

Sam is a Microsoft MVP for M365 and Copilot - and therefore has spent more time in the consoles than anyone should... When he isn't, he leads the Technical Consulting team at Fujitsu Cyber which includes both the technical testing team (that attempts to break in) and the professional services team (that attempt to stop the break-ins).

Sam was one of the original authors of the Digital Transformation Agency (DTA) Protected Utility Blueprint for Microsoft 365 (M365), Sam has more experience than most with how to balance usability and collaboration with the evolving nature of cyber security threats.