BEGIN:VCALENDAR
VERSION:2.0
PRODID:-//pretalx//cfp.bsidesfrankfurt.org//call-for-paper-presentations-20
 26//speaker//WLCTVY
BEGIN:VTIMEZONE
TZID:CET
BEGIN:STANDARD
DTSTART:20001029T040000
RRULE:FREQ=YEARLY;BYDAY=-1SU;BYMONTH=10
TZNAME:CET
TZOFFSETFROM:+0200
TZOFFSETTO:+0100
END:STANDARD
BEGIN:DAYLIGHT
DTSTART:20000326T030000
RRULE:FREQ=YEARLY;BYDAY=-1SU;BYMONTH=3
TZNAME:CEST
TZOFFSETFROM:+0100
TZOFFSETTO:+0200
END:DAYLIGHT
END:VTIMEZONE
BEGIN:VEVENT
UID:pretalx-call-for-paper-presentations-2026-KVLR3V@cfp.bsidesfrankfurt.or
 g
DTSTART;TZID=CET:20260910T101000
DTEND;TZID=CET:20260910T110500
DESCRIPTION:Enterprise identity has fundamentally changed.\n\nLarge organis
 ations no longer rely on a single identity system. Instead\, Active Direct
 ory\, Microsoft Entra ID\, Azure\, Microsoft 365\, SaaS applications\, ide
 ntity synchronisation\, third-party identity providers and cross-tenant tr
 ust relationships have evolved into a single interconnected identity archi
 tecture.\n\nUnfortunately\, attackers don’t think in terms of “on-prem
 ises” or “cloud.” They follow trust relationships.\n\nWhile organisa
 tions often assess Active Directory and cloud environments separately\, th
 e most valuable attack paths increasingly exist between them. Hybrid ident
 ity\, multi-forests\, multiple Entra ID tenants\, synchronisation services
 \, service principals\, managed identities and delegated administration al
 l contribute to an enterprise identity attack surface that is significantl
 y larger\, and far less understood\, than many organisations realise.\n\nT
 his session explores enterprise identity architecture from an attacker’s
  perspective. Rather than focusing on individual attack techniques\, it ex
 amines how identity systems interact\, where trust boundaries actually exi
 st\, and how seemingly isolated weaknesses can be chained together across 
 on-premises and cloud environments.\n\nAttendees will leave with a practic
 al approach to identifying enterprise identity attack paths\, defining rea
 listic assessment scopes\, and understanding why the biggest identity risk
 s often exist in the connections between systems\,not the systems themselv
 es.
DTSTAMP:20260923T103626Z
LOCATION:Großer Saal
SUMMARY:Welcome to Hybrid Hell - Breaking Entrpise Identity beyond Active D
 irectory - georg
URL:https://cfp.bsidesfrankfurt.org/call-for-paper-presentations-2026/talk/
 KVLR3V/
END:VEVENT
END:VCALENDAR
