The Best Cybersecurity Training in the World - No Travel Required! Learn More


To attend this webcast, login to your SANS Account or create your Account.

Legacy Authentication and Password Spray, Understanding and Stopping Attackers Favorite TTPs in Azure AD

  • Monday, August 19th, 2019 at 1:00 PM EDT (17:00:00 UTC)
  • Mark Morowczynski and Ramiro Calderon
This webcast has been archived. You can view the webcast presentation and download the slides by logging into your SANS Portal Account or creating an Account. Click the Register Now button after you have logged in to view the Webcast.

You can now attend the webcast using your mobile device!


One of attackers' favorite techniques today is password spraying. And it should be: in August 2018, 200,000 accounts were compromised using this. Nearly all password spray attacks are targeting legacy authentication protocols. The good news there are several steps you can take to prevent this type of attack. In this session we will focus on what legacy authentication is, how to look for it in your environment and what you need to do to prevent it from compromising your accounts.

Speaker Bios

Mark Morowczynski

Mark is a Principal Program Manager on the customer success team in the Microsoft Identity division . He spends most of his time working with customers on their deployments of Azure Active Directory . Previously he was Premier Field Engineer supporting Active Directory, Active Directory Federation Services and Windows Client performance . He was also one of the founders of the AskPFEPlat blog . Hes spoken at various industry events such as Microsoft Ignite, Microsoft Inspire, Microsoft Ready, Microsoft MVP Summits, The Cloud Identity Summit, SANs Security Summits and TechMentor . He can be frequently found on Twitter as @markmorow arguing about baseball and making sometimes-funny gifs .

Ramiro Calderon

Ramiro Calderon is a Principal Program Manager in the Azure AD product group . He is part of the customer success team and his role as an architect is to accelerate the adoption of cloud services across enterprise customers . This involves establishing a long-term advisory relationship with customers; working with the engineering team throughout the whole engineering cycle; training customers and partners with identity products and services; and producing reusable intellectual property . Ramiro has more than 10 years of experience in the identity space in Microsoft, shipping multiple releases of Active Directory Federation Services, active directory, and Azure AD Connect Health .

Need Help? Visit our FAQ page or email

Not able to attend a SANS webcast? All Webcasts are archived so you may view and listen at a time convenient to your schedule. View our webcast archive and access webcast recordings/PDF slides.