Identity Security Architect @ TrustedSec. Microsoft Certified Master #ActiveDirectory & former Microsoft MVP. Co-Host @ Enterprise Security Weekly. He/Him. #BLM

4°08'15.0N 162°03'42.0E
To my black family, friends, and people seeing this: I love you You matter I'm here for you #BlackLivesMatter
5
5
138
Sean Metcalf retweeted
Microsoft just moved Endpoint Privilege Management into base Microsoft 365 E5. No more separate add-on cost for a feature that lets standard users elevate one task without ever getting admin rights.
5
8
88
9,292
Sean Metcalf retweeted
Saddle up, Deadwood, you won't want to miss this! Identity Security Architect @PyroTek3 is presenting "Entra the Dragon: Entra ID Red vs Blue" at @WWHackinFest on October 8 at 10:00AM. Plus, find the rest of the team at our booth—see you there 🤠 hubs.la/Q04ymDmw0
2
5
17
1,736
Sean Metcalf retweeted
Monitoring privileged groups (tier 0) for changes is super important but if you can get to a point where you’re also detecting abnormal changes, that’s better. Eg, if somehow joe the sql guy has added an account to Domain Admins even though he shouldn’t be able to, that’s a big red flag.
1
4
21
1,256
Sean Metcalf retweeted

ALT boom smile GIF

Periodic reminder: Good security architecture minimizes the number of bugs and CVEs you have to care about.
2
6
39
2,777
Sean Metcalf retweeted
Agentic AI is part of the team now and our CTO @HackingLZ has thoughts 👀 Tune in next week to #SecurityNoise as we dig into the risks, practical uses, and how red team pentesters are keeping humans in the loop. Search "Security Noise" in your podcast app and subscribe today!
3
7
20
1,512
Sean Metcalf retweeted
Microsoft Defender for Office 365 will enable Teams user reporting by default starting late October 2026 for licensed organizations. Users can report suspicious Teams content to improve threat detection. SOC can implement custom detection to monitor Teams user Reporting incident for prompt follow up. #MicrosoftDefender #Teamsuserreporting
8
36
2,361
Our call for papers is over, now we start a call for volunteers! If you want to help with the BSides NOVA conference on Oct 30-31st, read this forms.gle/nZCDR6MPRgs8DQV28, fill out what you'd like to do and submit! We need volunteers to run the conference, thanks if you can help!
1
3
9
577
Sean Metcalf retweeted
14
233
1,471
31,995
Sean Metcalf retweeted
Probably a good time to point you all to a tool I released not to long ago called SecretsStalker. If you have found an exposed client ID and secret to s service principal, SecretsStalker will authenticate you into the environment and recon the exact rights that it has. github.com/rootsecdev/Secret…
Microsoft Security Research has identified extensive cloud resource destruction activity linked to JADEPUFFER, which Microsoft tracks as Storm-3168. The activity used compromised service principals and performed cloud credential collection that could be used to facilitate future exfiltration. msft.it/6015a9lob Two compromised service principals divided discovery, destruction, and credential collection, with timing and overlapping token streams strongly indicating automated or scripted execution that included more than 100 storage account deletion attempts in about seven minutes. Discovered by Sysdig in July 2026, JADEPUFFER is reported to be the first documented agentic ransomware operation. These new findings expand publicly documented activity associated with Storm-3168 and indicate an evolution in the threat actor's cloud operations. Read the blog for analysis, Microsoft Defender detections, and mitigation guidance on protecting workload identities, revoking or rotating exposed credentials, and safeguarding backup and recovery resources.
2
11
81
7,271
The people have spoken and Active Directory just nudges out Entra ID, but both is the runaway winner! Thank you all for voting!
I'm planning my conference talks for 2027. What do you want to hear about?
1
1
13
1,475
Sean Metcalf retweeted
ISOC in Microsoft Defender is a benefit for M365 E5 and E7 customers, it is not a new product. Those lucky customers will save 44% off 3P security log ingestion. I spent all day reading and broke it down here to bring it to you straight: patriotconsulting.com/blogs/…
XDR and SIEM now in one platform. Meet the new ISOC in Microsoft Defender—a SOC built for agentic security. Here to help you investigate and respond more efficiently. msft.it/6019ag5T1
7
39
277
370,842
Sean Metcalf retweeted
At #GrrCon? Swing by the @TrustedSec and @Binary_Defense booths #TrustedSec - booth #97 #BinaryDefense - booth #121 Great folks over there, see NightBeacon live in action, chat with our folks at TS to talk about what we're doing on offense and defense.
1
3
14
5,014
Sean Metcalf retweeted
I just wanted to do a special shoutout to @P1nkN1ghtmare @EggDropX and all of the amazing folks that put on @GrrCON and its volunteers, staff, and sponsors. One of my favorite cons of all times, superb every year - so many great friends there and super well run. Appreciate all the time, effort, and work that goes into making that place magical. Know the level of effort and attention to detail it takes. Had a blast speaking again this year, so many great talks, good people - and many memories forged. Thank you all!
3
6
53
5,841
Sean Metcalf retweeted
Wait, did we just get native app control for macOS 27 in Intune?
7
13
97
11,890
Sean Metcalf retweeted
🔁 Microsoft Entra Connect (Azure AD Connect) version 2.6.92.0 is now available 🔒 This is a hotfix release with security fixes. Microsoft recommends upgrading as soon as possible. 🛠️ It fixes an issue in 2.6.91.0 where enabling Pass-through Authentication through the wizard could fail while registering the local Authentication Agent. If you planned to deploy 2.6.91.0, go straight to 2.6.92.0. The .msi must be downloaded from the Microsoft Entra admin center: entra[.]microsoft[.]com > Identity > Hybrid Management > Microsoft Entra Connect > Connect Sync > Get started > Manage tab 🚨 Reminder: on September 30, 2026, every server below 2.5.79.0 stops synchronizing until it is upgraded. Less than a week left. 🔗 Official release notes: learn.microsoft.com/en-us/en… 🔗 Previous versions list, you can download older versions there: l.itpro.tips/entraconnectsyn…
8
15
1,933
Sean Metcalf retweeted
I've begun publishing a set of more detailed Active Directory Certificate Services modules. Here is the first on determining topology and role deployment. learn.microsoft.com/en-us/tr…
5
47
1,958
Sean Metcalf retweeted
If you have ADCS and you’re not monitoring for certificate abuse, you should be!
Defender for Identity sensor v3 on ADFS, ADCS, and Entra Connect sync is now in preview! 🥳 Make sure you have at least one, reachable DC running the v3 sensor as well ;)
4
11
1,635
Sean Metcalf retweeted
I'm planning my conference talks for 2027. What do you want to hear about?
26% Active Directory
23% Entra ID
51% Both!
0% Other (comment)
105 votes • Final results
3
3
9
3,995
We...worked on this story for a year...and...they just...they tweeted it out.
Keeping your fridge and freezer closed is the best way to keep food fresh for as long as possible. - @nbcselected nbcnews.com/select/shopping/…
142
965
27,890
1,341,444