Hybrid Cloud & Active Directory Security Training

Hands-on training to attack and defend hybrid cloud and Active Directory, from on-prem to Entra ID

Our hybrid cloud and Active Directory security training gives your team the practical skills to attack and defend the seam between on-prem and the cloud, where most real breaches actually move. Through hands-on labs in live Active Directory, Entra ID and Azure environments, your engineers chain an on-prem foothold into full cloud compromise and build the detections that stop it.

enumerate_gcp_permissions
Active Directory Attacks

Exploit and defend Active Directory: Kerberoasting, delegation, DCSync and ADCS abuse

Active Directory is still the backbone of most enterprises and the first domino in most hybrid breaches. Our hands-on labs walk your team through the full offensive playbook: Kerberoasting and AS-REP roasting, unconstrained and constrained delegation abuse, DCSync and credential extraction, and Active Directory Certificate Services (ADCS) escalation paths from ESC1 to ESC8. Learners practice both the attack and the fix, from tiered administration and delegation cleanup to certificate template hardening.

ssrf_vulnerability
Entra ID & Hybrid Identity

Attack and secure Entra ID, Entra Connect and hybrid identity

Hybrid identity is where on-prem and cloud trust each other, and exactly where attackers pivot. Our labs cover Entra Connect (Azure AD Connect) compromise, Password Hash Sync and Pass-through Authentication abuse, Seamless SSO silver-ticket attacks into the cloud, primary refresh token and device-based token theft, and Conditional Access enumeration and bypass. Your team learns to harden the sync account, enforce phishing-resistant MFA, and close the hybrid trust paths that lead to Global Admin.

dangerous_gcp_permissions
On-Prem to Cloud Movement

Chain on-prem footholds into full cloud compromise

Real intrusions rarely stay in one place. Our hands-on labs walk your team through complete hybrid attack chains: from a phished workstation or a compromised on-prem service account, through Active Directory, across the Entra Connect trust, and into Azure and Microsoft 365. Learners map these paths with BloodHound and AzureHound, then apply the segmentation and identity controls that break them, so a single on-prem foothold no longer means the whole tenant.

scc_attack_paths-1
Detection & Hardening

Detect hybrid attacks with Microsoft Sentinel and Defender for Identity

Detection is only as good as the tradecraft it was tested against. Our labs teach your team to deploy Microsoft Sentinel and Defender for Identity, write and tune analytics rules for Kerberoasting, DCSync, ADCS abuse and risky sign-ins, and correlate on-prem and cloud signals into a single hybrid attack timeline. Learners leave able to spot the exact techniques they just executed and to harden identity posture across Active Directory and Entra ID.

exposed_terraform
Certification & Practitioners

Prove expert hybrid skills with the MCRTE certification

This training maps to the Microsoft Cloud Red Team Expert (MCRTE), our expert-level certification for operators who attack and defend hybrid Microsoft environments end to end. It is built and taught by practitioners who run these engagements across Fortune 500 environments every day, holding certifications including AZ-500, SC-200, MCRTP and CRT. Every technique is practiced in a live hybrid lab, so the skills, and the verifiable Credly badge, transfer straight to production.