SEC536: Adversarial AI - Penetration Testing AI Systems


Experience SANS training through course previews.
Learn MoreLet us help.
Contact usBecome a member for instant access to our free resources.
Sign UpWe're here to help.
Contact UsOrganizations with complex, multi-system environments face significant challenges in managing identity lifecycle, access provisioning, and governance at scale, and typically rely on dedicated platforms or homegrown codebases to address these needs. However, the evolution of Microsoft Entra ID and its Governance capabilities raises the question of whether a standalone IGA solution is necessary for organizations already invested in the Microsoft ecosystem.
This research evaluates the viability of using Entra ID Governance as a primary IAM/IGA solution through a proof-of-concept implementation modeled on a moderately complex organization with multiple systems of record. Using criteria aligned with industry-standard IGA capabilities, the study maps governance requirements to native Entra features. It tests their effectiveness across identity lifecycle management, access provisioning, reconciliation, and audit processes.
Findings indicate that Entra ID Governance can fulfill core IGA functions without middleware by leveraging lifecycle workflows, access packages, and API-driven integrations. However, limitations in real-time processing, service thresholds, and attribute flexibility must be considered. The results suggest that organizations can reduce architectural complexity and accelerate adoption by consolidating identity governance within Entra ID, provided their operational requirements align with the platform’s current capabilities.
It uses the SANS PICERL lifecycle - Preparation, Identification, Containment, Eradication, Recovery, and Lessons Learned - adapted to the safety and operational constraints of industrial control system environments.
In IT, endpoint tools can isolate individual hosts remotely. In OT, containment typically means physical or logical isolation of the whole network at a firewall, router, or switch, and the decision is usually made by facility or safety managers rather than cybersecurity staff alone.
No - ransomware attacks rarely compromise lower-level process systems like PLCs directly. They more commonly disrupt higher-level systems such as HMIs, engineering workstations, and SCADA platforms used for visibility and control.
No - paying the ransom does not remove the initial access broker or ransomware affiliate from the environment. A full forensic investigation and containment effort is still required after payment to fully restore security.
At least annually, according to the framework, though more frequent exercises are preferable, along with regular drills of critical technical procedures in lab or digital twin environments to avoid disrupting live operations.


















