top of page
attacking and defending

From Initial Access to Persistence :
Abusing synced passkeys in Azure

17 July 2026  |  12:00 PM ET  |  2+ Hours Duration

hacker summer  webinar page  banner final 1.png

Overview

Passkeys are rapidly being adopted across Azure environments as a phishing-resistant authentication method. While they offer strong security benefits when properly configured, they also introduce new attack surfaces that allow attackers to convert initial access into long-term persistence.

Join us as we examine how attackers can move from compromised credentials or session tokens to registering persistent passkeys that survive password resets and traditional session revocation. We break down the registration and authentication flows, the differences between attested device-bound passkeys and synced passkeys, and the configuration options available in Entra ID that directly impact attack feasibility.

Attendees will see practical techniques for converting captured authentication material into usable passkeys, using those passkeys to obtain tokens across Azure services, and operating automated agents with the resulting access. We also explore methods for storing and managing these credentials in ways that enable long-term, low-detection persistence within Azure environments.

The session concludes with a focused discussion on detection opportunities, response considerations, and effective remediation steps that security teams can implement to reduce risk. Real-world examples and recommended client guidance are included throughout.

webinar 17 july.png

Register

Get the latest updates on exclusive offers, webinars, giveaways, and key activities delivered directly to your inbox.

Watch the Recorded Webinar

Attend Live Webinar

17 July 2026 | 12:00 PM ET | 2+ Hours Duration

Get Webinar Participation Certificate

HS-C-02-Initial Access.jpg

MEET THE INSTRUCTOR

Nathan McNulty

Nathan.jpg

Nathan McNulty is a Microsoft MVP in Security and a Principal Security Solutions Architect for Patriot Consulting. With over 20 years of experience, his career started on Helpdesk and moved through SysAdmin, Client Architect, Cloud Architect, and Security Architect roles, spending nearly a decade administering and securing an environment with more than 50,000 users and 90,000 devices, building a security program primarily around Microsoft's E5 Security suite.

bottom of page