For years, Azure AD Connect was the only way to synchronize identities between on-premises Active Directory and the cloud. Today, Microsoft is redefining that model. I recently finished implementing Entra Cloud Kerberos Trust and want to share what I learned along the way: 🔑 What is Cloud Kerberos Trust? It's a mechanism that allows users to authenticate using Kerberos tickets issued directly by Entra ID — without requiring line-of-sight to a Domain Controller. This unlocks hybrid scenarios like Windows Hello for Business and SSPR in a much more efficient and cloud-native way. 🔄 Does it replace AD Connect? Not entirely — and this distinction matters: • Cloud Kerberos Trust → Syncs Kerberos keys between on-prem AD and Entra ID • Entra Cloud Sync → Syncs users, groups, and devices (the lightweight successor to AD Connect) They complement each other. Microsoft's new architecture is moving away from the classic AD Connect agent toward Entra Cloud Sync — lighter, more resilient, and far easier to maintain. ⚙️ What this architecture enables: ✅ Cloud Kerberos Trust active and fully synchronized ✅ On-prem AD users replicated to Entra ID via Cloud Sync ✅ Hybrid Azure AD Join ready for Windows 11 devices ✅ Foundation for automatic Intune enrollment If you're modernizing your hybrid identity infrastructure or planning a migration, this combination is the direction Microsoft is actively pushing today. Have you already deployed Entra Cloud Sync in your organization? 👇 #MicrosoftEntra #HybridIdentity #CloudKerberosTrust #EntraID #ActiveDirectory #WindowsHello #Azure #CloudSync #Intune #Microsoft365
Cloud Security
Explore top LinkedIn content from expert professionals.
-
-
As technology becomes the backbone of modern business, understanding cybersecurity fundamentals has shifted from a specialized skill to a critical competency for all IT professionals. Here’s an overview of the critical areas IT professionals need to master: Phishing Attacks - What it is: Deceptive emails designed to trick users into sharing sensitive information or downloading malicious files. - Why it matters: Phishing accounts for over 90% of cyberattacks globally. - How to prevent it: Implement email filtering, educate users, and enforce multi-factor authentication (MFA). Ransomware - What it is: Malware that encrypts data and demands payment for its release. - Why it matters: The average ransomware attack costs organizations millions in downtime and recovery. - How to prevent it: Regular backups, endpoint protection, and a robust incident response plan. Denial-of-Service (DoS) Attacks - What it is: Overwhelming systems with traffic to disrupt service availability. - Why it matters: DoS attacks can cripple mission-critical systems. - How to prevent it: Use load balancers, rate limiting, and cloud-based mitigation solutions. Man-in-the-Middle (MitM) Attacks - What it is: Interception and manipulation of data between two parties. - Why it matters: These attacks compromise data confidentiality and integrity. - How to prevent it: Use end-to-end encryption and secure protocols like HTTPS. SQL Injection - What it is: Exploitation of database vulnerabilities to gain unauthorized access or manipulate data. - Why it matters: It’s one of the most common web application vulnerabilities. - How to prevent it: Validate input and use parameterized queries. Cross-Site Scripting (XSS) - What it is: Injection of malicious scripts into web applications to execute on users’ browsers. - Why it matters: XSS compromises user sessions and data. - How to prevent it: Sanitize user inputs and use content security policies (CSP). Zero-Day Exploits - What it is: Attacks that exploit unknown or unpatched vulnerabilities. - Why it matters: These attacks are highly targeted and difficult to detect. - How to prevent it: Regular patching and leveraging threat intelligence tools. DNS Spoofing - What it is: Manipulating DNS records to redirect users to malicious sites. - Why it matters: It compromises user trust and security. - How to prevent it: Use DNSSEC (Domain Name System Security Extensions) and monitor DNS traffic. Why Mastering Cybersecurity Matters - Risk Mitigation: Proactive knowledge minimizes exposure to threats. - Organizational Resilience: Strong security measures ensure business continuity. - Stakeholder Trust: Protecting digital assets fosters confidence among customers and partners. The cybersecurity landscape evolves rapidly. Staying ahead requires regular training, and keeping pace with the latest trends and technologies.
-
👉 Why Your Organization Needs to "Containerize" AI Agents Right Now If your employees are installing OpenClaw (or similar agents) directly onto their local machines, you aren’t just adopting AI—you’re creating a massive, unmonitored risk. I recently sat down with Stephen Schmidt, Chief Security Officer at Amazon, and his advice was blunt: "Never let an AI agent run free on an individual machine." Here is why the "Isolation Chamber" approach is the new security standard: ✔️ The Problem with "Unfettered Access": Standard agents often have access to literally everything on a machine. If that one agent is compromised, your entire local exposure risk skyrockets. ✔️The "Piercing" Principle: By running agents in a container (like a VM or microVM), the agent is physically fenced in. ✔️Auditability as a Control: To do anything useful, an agent must "pierce" that container boundary to get credentials or access data. That act of piercing is a measurable event that you can audit, log, and control. ✔️The "Judge" Model: Once an agent makes a request for a credential from inside its container, you can use a second "Judge" model to examine if that request is reasonable based on the user's job and context before granting it. ✔️ The Bottom Line: Security isn't about stopping the deployment of agents—it’s about ensuring they operate in an environment where their actions are scoped, measured, and tied to a unique identity. For those exploring the enterprise side of agentic AI, AWS has a useful overview here: https://lnkd.in/eubr-VpH Stop the "OpenClaw oopsies" before they happen. Pick an isolation method—container, VM, or otherwise—and start measuring what your agents are actually doing. Are you currently allowing AI agents to run natively on employee hardware, or have you already started moving toward a "sandboxed" environment? Let’s discuss the trade-offs in the comments. #AWSAmbassador #AI #CyberSecurity #AgenticAI #Amazon #HumanX #TechLeadership
-
We’re moving from operating software to operating alongside systems that can reason and act. Today we’re making that real with the general availability of AWS DevOps Agent and AWS Security Agent — part of a new class of systems we call frontier agents. Unlike traditional tools, frontier agents don’t just respond to prompts — they work autonomously across multiple steps to achieve outcomes, operating continuously until the job is done. One helps you run cloud operations — investigating incidents, reducing time to resolution, and preventing issues before they happen. Customers like United Airlines, Western Governors University, and T-Mobile are already using DevOps Agent to accelerate incident response and simplify operations at scale. At WGU, resolution time dropped from hours to minutes, and in preview customers report up to 75% lower MTTR and 3–5x faster resolution. The other helps you secure them — bringing continuous, context-aware penetration testing into the development lifecycle. Customers including LG CNS, HENNGE, and Wayspring are seeing strong results. At LG CNS, teams estimate over 50% faster testing and ~30% lower costs, along with significantly fewer false positives. Both are designed to work across Amazon Web Services (AWS), multicloud, and on-prem environments. The goal is simple: give teams an always-available teammate that can handle the heavy lifting, so builders can focus on what matters most. We’re still early, but this is a big step toward more autonomous, resilient systems. Learn more: https://lnkd.in/em-eeJwc
-
AI security/securing the use of AI is going to kill me. I use Claude Code almost daily. It's a problem.... Here's what I have to change AGAIN this week. Security researcher Ari Marzuk disclosed 30+ vulnerabilities across AI coding tools. Cursor. GitHub Copilot. Windsurf. Claude Code. All of them. He called it IDEsaster. The attack chain includes prompt injection, hijacking LLM context, and auto-approved tool calls executing without permission. Then, legitimate IDE features are weaponized for data exfiltration and RCE. Your .env files. Your API keys. Your source code. Accessible through features you thought were safe. Most studies I read claim that around 85% of developers now use AI coding tools daily. Most have no idea their IDE treats its own features as inherently trusted. 𝗦𝗼... 𝗮𝗳𝘁𝗲𝗿 𝗿𝗲𝘃𝗶𝗲𝘄𝗶𝗻𝗴 𝗔𝗿𝗶'𝘀 𝗿𝗲𝘀𝗲𝗮𝗿𝗰𝗵, 𝗵𝗲𝗿𝗲'𝘀 𝗜 𝘄𝗶𝗹𝗹 𝗯𝗲 𝗱𝗼𝗶𝗻𝗴... Be warned: All this is SO much easier said than done! Audit every MCP server connection. Checked for tool poisoning vectors where legitimate tools might parse attacker-controlled input from GitHub PRs or web content. Removed servers I couldn't verify. Disabled auto-approve for file writes. The attack chains weaponize configuration files and project instructions like .claude/settings.json and CLAUDE.md. One malicious write to these files can alter agent behavior or achieve code execution without additional user interaction. Move all credentials to a secrets manager. No .gitignored .env files in agent-accessible directories. API keys live in 1Password CLI. Environment variables inject at runtime through a wrapper script the LLM never sees. Start running Claude Code in isolated containers. Mounted volumes limited to specific project directories. No access to ~/.ssh, ~/.aws, or ~/.config. If the agent gets compromised, blast radius stays contained. Enable all security warnings. Claude Code added explicit warnings for JSON schema exfiltration and settings file modifications. These exist because Anthropic knows the attack surface. Add pre-commit hooks for hidden characters. Prompt injections hide in pasted URLs, READMEs, and file names using invisible Unicode. Flag non-ASCII characters in any file the agent might ingest. The fix isn't to stop using AI coding tools. The fix is to stop trusting them implicitly. What controls do you have for AI tools with write access to your codebase? 👉 Follow for more AI and cybersecurity insights with the occasional rant #AISecurity #DevSecOps
-
Following strong interest from public administrations and IT providers, we have published further clarification on our Cloud Sovereignty Framework – a key tool used by the European Commission in its recent sovereign cloud procurement. ☁️ By embedding sovereignty directly into cloud acquisition, the Commission set a benchmark for secure and values-based digital infrastructure in Europe. What makes the Framework particularly significant is its structured approach to evaluating sovereignty through two complementary mechanisms: 🔹 The Sovereignty Effectiveness Assurance Level (SEAL) that measure levels of sovereignty and resilience. 🔹 An overall sovereignty score based on 48 criteria including strategic, legal and jurisdictional ones, data and AI, operational, supply chain, technological, security and compliance, as well as environmental sustainability. This Framework sends a strong signal to the market: sovereignty is no longer an abstract policy discussion, but an operational requirement in public procurement. Find the implementation guidance here 👉 https://lnkd.in/eWQRn74x
-
Folks, I'm starting a new series of Entra Hardening tips from today. Here's how it will work. One new tip every weekday (I take a break on weekends). ---- Tip #1: Privileged accounts in Entra ID should be cloud native identities If your privileged accounts in Entra ID are synced from on-prem AD then you have a problem. Attackers that compromise your on-prem infrastructure can pivot to the cloud, into Entra ID and gain access to the cloud servers, data, Microsoft 365 and other SaaS apps. Why? We've seen this happen multiple times. The biggest ones have been Solorigate (compromise ADFS and pivot to cloud), other examples include Storm-0501 (compromise AAD Connect server) and more. The Fix? Reduce the blast surface. Don't allow accounts synced from on-prem to be granted privileged roles. Instead create admin accounts natively in Entra ID and grant privileged roles to these cloud only accounts. How do you go about it? For each role with high privileges (assigned permanently or eligible through Microsoft Entra Privileged Identity Management), you should do the following actions: ✅ Review the users that have onPremisesImmutableId and onPremisesSyncEnabled set. See Microsoft Graph API user resource type. ✅ Create cloud-only user accounts for those individuals and remove their hybrid identity from privileged roles. To learn more see: https://lnkd.in/gYb8Hgts References: https://lnkd.in/gX_KnMfc Golden SAML: Newly Discovered Attack Technique Forges Authentication to Cloud Apps https://lnkd.in/gX_KnMfc Storm-0501: Ransomware attacks expanding to hybrid cloud environments https://lnkd.in/gKyevQFB
-
What a surprise for the EU 😱 😉 A recently published expert opinion commissioned by the German Federal Ministry of the Interior has sparked a pivotal discussion on data governance and sovereignty. According to the report, US authorities can exert far-reaching access rights to cloud data managed by US-based companies, even when that data is stored in European data centers and administered through local subsidiaries. This is because legal instruments such as the Stored Communications Act extended by the Cloud Act and Section 702 of FISA focus on the provider’s control, not the physical location of the servers. This finding is a firm reminder that simply hosting data on European soil does not guarantee protection from extraterritorial legal claims. It reveals structural risks in relying on dominant foreign cloud providers for sensitive data and critical digital infrastructure. For Europe to truly uphold its data protection principles and strategic autonomy, the conversation must go beyond compliance checklists and contractual assurances. We need stronger investment in #opensource digital infrastructure and indigenous technologies that reduce dependency on non-European platforms. Open source fosters transparency and auditability while enabling communities and businesses to build on systems that are not bound by foreign legal systems. If #digitalsovereignty is to mean more than a buzzword, we must accelerate our efforts towards resilient, interoperable, and locally governed alternatives. Only then Europe can ensure that its data is governed by the laws and values that its citizens and organisations expect. Source: https://lnkd.in/dtpXiwYN
-
This EY incident underscores a truth we often overlook: the most common cloud vulnerability isn't a zero-day exploit; it's a configuration oversight. A single misstep in cloud storage permissions turned a database backup into a public-facing risk. These files often hold the "keys to the kingdom" ie. credentials, API keys, and tokens that can lead to a much wider breach. How do we protect ourselves against these costly mistakes? Suggestions 1. Continuous Monitoring: Implement a CSPM for 24/7 configuration scanning. CSPM is Cloud Security Posture Management -> a type of automated security tool that continuously monitors cloud environments for misconfigurations, vulnerabilities, and compliance violations. It provides visibility, threat detection, and remediation workflows across multi-cloud and hybrid cloud setups, including SaaS, PaaS, and IaaS services 2. Least Privilege Access: Default to private. Grant access sparingly. 3. Data Encryption: For data at rest and in transit. 4. Automated Alerts: The moment something becomes public, you should know. 5. Regular Audits: Regularly review access controls and rotate secrets.
-
📛 CVE 2025 32711 is a turning point Last week, we saw the first confirmed zero click prompt injection breach against a production AI assistant. No malware. No links to click. No user interaction. Just a cleverly crafted email quietly triggering Microsoft 365 Copilot to leak sensitive org data as part of its intended behavior. Here’s how it worked: • The attacker sent a benign-looking email or calendar invite • Copilot ingested it automatically as background context • Hidden inside was markdown-crafted prompt injection • Copilot responded by appending internal data into an external URL owned by the attacker • All of this happened without the user ever opening the email This is CVE 2025 32711 (EchoLeak). Severity 9.3 Let that sink in. The AI assistant did exactly what it was designed to do. It read context, summarized, assisted. But with no guardrails on trust boundaries, it blended attacker inputs with internal memory. This wasn’t a user mistake. It wasn’t a phishing scam. It was a design flaw in the AI data pipeline itself. 🧠 The Novelty What makes this different from prior prompt injection? 1. Zero click. No action by the user. Sitting in the inbox was enough 2. Silent execution. No visible output or alerts. Invisible to the user and the SOC 3. Trusted context abuse. The assistant couldn’t distinguish between hostile inputs and safe memory 4. No sandboxing. Context ingestion, generation, and network response occurred in the same flow This wasn’t just bad prompt filtering. It was the AI behaving correctly in a poorly defined system. 🔐 Implications For CISOs, architects, and Copilot owners - read this twice. → You must assume all inputs are hostile, including passive ones → Enforce strict context segmentation. Copilot shouldn’t ingest emails, chats, docs in the same pass → Treat prompt handling as a security boundary, not just UX → Monitor agent output channels like you would outbound APIs → Require your vendors to disclose what their AI sees and what triggers it 🧭 Final Thought The next wave of breaches won’t look like malware or phishing. They will look like AI tools doing exactly what they were trained to do but in systems that never imagined a threat could come from within a calendar invite. Patch if you must. But fix your AI architecture before the next CVE hits.