**Varonis Researchers Create Challenging Entra ID Training Experience to Help Defenders Stay Ahead of Modern Threats**
Imagine being on a tranquil beach vacation when suddenly you receive word of a breach in the identity management system used by your organization. Sounds like a scenario from a cybersecurity thriller, right? But for Doron Kapah and Mark Vaitsman, researchers at Varonis Threat Labs, this is all too familiar. Their days are spent researching how threats exfiltrate sensitive data in cloud-native environments, including those managed by Entra ID.
The duo’s experience has led them to create a unique training experience called Breach at the Beach, an Entra ID Capture The Flag (CTF) challenge designed to give security practitioners hands-on knowledge of modern attacks on identity management systems. By playing through this interactive experience, participants can gain valuable insights into how threats exploit legitimate features and evade detection.
Entra ID is more than just an identity provider; it’s the control plane for the entire enterprise, connecting users, applications, permissions, automation, and increasingly AI-powered workflows. The rise of non-human identities – such as AI agents, service principals, and automated workflows – has transformed what a compromise in Entra ID can look like. According to Mark Vaitsman, Security Research Team Leader at Varonis, “In today’s AI era, a lot of identities are non-human identities. If there is a compromise in Entra, a threat actor can pivot themselves into a non-human identity, and it can quickly turn into a stealthy and scalable data exfiltration attempt.”
The techniques used throughout Breach at the Beach aren’t hypothetical; they reflect real-world cases encountered by Doron and Mark in customer environments. Each challenge is grounded in what defenders are up against today, making this training experience a valuable resource for those looking to stay ahead of modern threats.
One key aspect of Breach at the Beach is its focus on hands-on learning. Mark emphasizes that “reading is not enough” when it comes to understanding complex cybersecurity concepts. By engaging with the CTF challenge, participants can develop real-world skills and gain a deeper appreciation for the impact of these threats on their organization. As Mark notes, “You kind of feel that this is actually really your company with a breach happening.”
Breach at the Beach offers several key takeaways for defenders, including:
* How threats abuse features, not misconfigurations: Players learn to recognize when legitimate functionality is being weaponized.
* How to detect threats without AI: The CTF challenge is designed to avoid relying on Large Language Models (LLMs) to solve challenges, allowing participants to absorb the lessons embedded in the experience.
* How to eliminate noise: By working through raw Entra logs, players are tested to create their own clarity and understand how to navigate complex data.
To participate in Breach at the Beach, simply visit the website and start playing. This free online CTF challenge is available now, offering a unique opportunity for security practitioners to gain hands-on experience with modern threats on identity management systems.
**Takeaway**: With the rise of non-human identities and AI-powered workflows, defenders need to stay ahead of modern threats. Breach at the Beach offers a valuable training experience that can help you develop real-world skills and understand the impact of these threats on your organization. So why not take a break from the beach and dive into this challenging CTF challenge?
Source: Bleeping Computer — 2026-07-13