i Olivia Hodges / Unsplash

Defending the Digital Gate: Combating Adversary in The Middle Phishing Attacks with Passkeys and Conditional Access

This presentation will cover some statistics on increased phishing and account takeover activity. Then, we will discuss why traditional multi-factor authentication methods are becoming less effective at preventing these attacks. In doing so, we will cover how token-based OIDC Authentication works and why it’s vulnerable to AITM Attacks. During this, I’ll demo an attack I conducted against my lab environment to compromise a Microsoft User Account. Afterwards, we will discuss FIDO2 Authentication protocols, the use of Passkeys, and how they prevent these attacks. Lastly, we will discuss Microsoft Entra conditional access policy controls and how to use them to prevent these attacks using both passkey-focused and non-passkey-focused controls.

Speaker Bio

Jeremy Rogers is a Senior Security Operations Engineer with Acrisure LLC. After leaving the United States Marine Corps in 2017, he obtained a bachelor’s in information security/cyber assurance and joined Acrisure in 2020. He has almost five years of experience in security architecture, engineering, and incident response, having implemented and managed a wide range of tools, including SIEM, EDR, Email Security, SOAR, and Cloud Security Solutions. Jeremy’s current focus is on implementing phishing-resistant security solutions for Entra ID for an organization of almost 20k employees; as well as the design and implementation of Security Automation solutions.