
Identity Architect
DirTeam

IT Infrastructure Specialist – MVP
Nextpert
This presentation by Sander Berkauer and Raymond Convalius focuses on application security in Microsoft Entra ID and the modern workplace.
The speakers explain how Entra ID applications work, distinguishing between app registrations and enterprise applications, and emphasizing that everything is becoming an app-based identity. They cover the differences between delegated permissions and app-only permissions, highlighting security risks from misconfigurations.
The session includes real-world examples of breaches, including a municipality losing €600,000 due to improper application permissions. Key topics include: credential hygiene, user consent settings, admin consent workflows, and the importance of reviewing application permissions regularly.
The speakers provide practical recommendations for securing applications without requiring expensive E5 licenses, emphasizing proper governance, monitoring of privileged roles like cloud app administrators, and the need to treat applications as part of identity and access management processes.