Log inSign up
Dirk-jan
2,547 posts
Dirk-jan profile banner
@_dirkjan

Dirk-jan

@_dirkjan
Hacker at @OutsiderSec. Researches AD and Azure (AD) security. Likes to play around with Python and write tools that make work easier.
dirkjanm.io
Joined December 2017
208
Following
30.1K
Followers
RepliesRepliesRepostsRepostsMediaMedia

Log in or sign up for X

See what’s happening and join the conversation

Continue with phone
or
Log in with username or email
Terms·Privacy·Cookies·Accessibility·Ads Info·© 2026 X Corp.
  • Pinned
    @_dirkjan
    Dirk-jan
    @_dirkjan
    Sep 17, 2025
    I've been researching the Microsoft cloud for almost 7 years now. A few months ago that research resulted in the most impactful vulnerability I will probably ever find: a token validation flaw allowing me to get Global Admin in any Entra ID tenant. Blog:
    dirkjanm.io
    One Token to rule them all - obtaining Global Admin in every Entra ID tenant via Actor tokens
    While preparing for my Black Hat and DEF CON talks in July of this year, I found the most impactful Entra ID vulnerability that I will probably ever find. One that could have allowed me to compromise...
    138
  • @_dirkjan
    Dirk-jan
    @_dirkjan
    Sep 1
    Spent way too much time figuring out why RDP with a FIDO2 key didn't work. Turns out unlike the WHFB path, using web sign-in for RDP uses a TPM bound (temp, I think) key for TLS. TPM 2.0 up to certain spec versions don't properly implement the required algos for TLS 1.3 signing,
    3
  • @_dirkjan
    Dirk-jan
    @_dirkjan
    Aug 20
    📢 The next edition of my offensive Entra ID security class just opened up for registration! November 16-19 in The Hague, Netherlands. In this 4 day class we deep dive into Entra ID security, tokens, oauth2 and Conditional Access. More info and reg:
    Image
    events.outsidersecurity.nl
    Training: Offensive Entra ID (Azure AD) and Hybrid AD security
    Nov. 16 – 19, 2026
    2
  • @_dirkjan
    Dirk-jan
    @_dirkjan
    Aug 6
    If you're at Black Hat, check out this booth. Probably the only one where they deliver what they say too 😅.
    @SkelSec
    SkelSec
    @SkelSec
    Aug 5
    First time having a booth at @BlackHatEvents and the experience so far is eyeopening. Anyhow, if you are interested in internal network pentest tooling check us out at booth 6312, ppl who understand hacking really loved the demo :)
  • @_dirkjan
    Dirk-jan
    @_dirkjan
    Aug 5
    ✈️ blog to kick off BH/DC week: Borrowing Windows Hello keys for authentication and persistence.
    dirkjanm.io
    Borrowing Windows Hello keys for authentication and persistence
    Most research into Windows Hello focuses on the mechanics in use when authenticating to the local device. As an Entra ID researcher, I’ve always been more interested in how these keys are used to...
    5
Advertisement
Advertisement