Introduction
A lot of companies implement Duo 2-Factor Authentication for O365. If this is not configured properly, it can allow mobile clients to authenticate without triggering the Duo prompt.
This video has been presented by Cassandra Young. She is a security professional focussing on cloud security architecture and engineering. She is also one of the organisers of Blue Team Village.
This video is part of the tech talks presented at Cloud Village. Cloud Village is an open space dedicated for people interested in cloud security and conducts various activities like talks, workshops, CTFs, and discussions around cloud.
Video
https://www.youtube.com/watch?v=D77aJug_-aQ
What to expect from this video
Following topics have been covered in this video:
- Overview of O365 Authentication Types and Email Protocols
- Understanding the Misconfiguration
- Conditional Access Policies in Azure Active Directory
- Understanding Conditions
- Apple’s iOS Mail App Use Case
- A look at Conditional Access Policies before and after August 2020
- Detecting the Misconfiguration
- Remediating the Misconfiguration
Key Takeaways
This video introduces you to O365 authentication types and various email protocols. The presenter gives an overview of conditional access policies in Azure Active Directory and explains what leads to the misconfiguration. An interesting use case of Apple’s iOS Mail App has been presented to demonstrate the misconfiguration. Cassandra Young also shares ways to detect this misconfiguration and what one can do to remediate it.

Riyaz Walikar
Founder & Chief of R&D
Riyaz is the founder and Chief of R&D at Kloudle, where he hunts for cloud misconfigurations so developers don’t have to. With over 15 years of experience breaking into systems, he’s led offensive security at PwC and product security across APAC for Citrix. Riyaz created the Kubernetes security testing methodology at Appsecco, blending frameworks like MITRE ATT&CK, OWASP, and PTES. He’s passionate about teaching people how to hack—and how to stay secure.

Riyaz Walikar
Founder & Chief of R&D
Riyaz is the founder and Chief of R&D at Kloudle, where he hunts for cloud misconfigurations so developers don’t have to. With over 15 years of experience breaking into systems, he’s led offensive security at PwC and product security across APAC for Citrix. Riyaz created the Kubernetes security testing methodology at Appsecco, blending frameworks like MITRE ATT&CK, OWASP, and PTES. He’s passionate about teaching people how to hack—and how to stay secure.