← All talks

Conditional Access Policies: Active Directory's GPOs #shorts

BSides Frankfurt0:40231 viewsPublished 2026-01Watch on YouTube ↗
About this talk
Conditional access policies are like GPOs, but in Active Directory. 58% of organizations have at least one attack path. 7% have over 1,000 attack paths. #bsidesfrankfurt #bsides #bsidesfra #TomerNahum #JonathanElkabas #Semperis
Show transcript [en]

For those of you who don't know, citial access policies are like GPOS in Active Directory. It's a very big thing in our opinion. But you don't just need to believe us when you say there's a lot of attack paths in ENT ID. You can look at Microsoft and what they published that 58% of organizations have at least one attack path in their environment. 7% have over a thousand attack puffs in their environment. That's probably thousands or maybe hundreds of thousands of organizations. Um and on average, yeah, there's 351 attack paths in any organization.