All talks

BlueHat USA 2024 · 2024/10

Scaling AppSec With an SDL for Citizen Development (ft Don Willits)

Loading presentation…

Read the abstract and transcript

Abstract

Application security programs are difficult. Filled to the brim with vulnerabilities. Overloaded staff and inadequate budget. Challenging communication with developers. The common “solution” is to narrow scope and focus on crown jewel applications and their developers, playing on relative easy mode. What if instead we increase the scope to cover 100x developers and 1000x applications? Surprisingly, it works. In the first 3 months of 2024, our program remediated >50K security vulnerabilities. 18K of them were remediated in a single night. In this talk, we will share insights from two years in the making of a security program for applications built by business users using GenAI and low-code/no-code tools, a.k.a. Citizen Development. We will share lessons learned and pitfalls not-avoided, and unique challenges for this kind of program. Applying SDLC to hundreds of thousands of citizen developers, with no security savvy. Working at 1,000x the AppSec scale relying on automation and guidance. Next, we will share the kind of vulnerabilities we see common in citizen development environments. Breaking access controls, allowing one user to impersonate another, leaking data to uncontrolled locations. We will demo exploits showing how they look like from the attacker’s perspective. We will finish off sharing our adoption of the SDL for citizen development, and showcase the OWASP Low-Code No-Code Top 10 as a framework to help you focus your program.

Official conference abstract

Transcript

AI generated from recording.

Opening and Context; Speaker Introductions

00:00 Presenter: Welcome. So, let’s just go ahead and get started. 55,000 developers. 90,000 co-pilots. Half a million apps. And more than a million automations. 10 million credentials. These are the numbers that the team at Microsoft has to deal with. These are crazy numbers. Like when you think about an application security program, you’ll typically

00:30 Presenter: be thinking about maybe a thousand apps? Maybe. They are dealing with like a hundred

00:36 Presenter: X, a thousand X that. How is this? How do you even begin? Where do you even begin? I’ll

00:43 Presenter: tell you more than that, how they’re actually successful. So how can you be successful with

00:49 Presenter: such high numbers? This is what we’re going to talk about today in this talk. So here’s

00:56 Presenter: what we’re going to do today. We’re going to start with figuring out why the numbers are so high.

01:00 Presenter: Like, how is it even possible? Then we’ll understand

01:04 Presenter: what are the applications behind these numbers. Why is this important?

01:08 Presenter: Why is this important for you to target today? Next,

01:12 Presenter: we’re going to tell you all of the things that went wrong when we tried to fix it.

01:16 Presenter: And then we’ll finish off with actually how did the team

01:20 Presenter: at Microsoft was actually able to fix this problem and what can you do with it

01:27 Presenter: So first, we’re going to start with a thank you to our team.

01:30 Presenter: Without the great cross-group collaboration of Jake, Andrew, CJ, PJ, and Lee, we would not be standing here today.

01:36 Presenter: Next slide.

01:37 Presenter: My name is Don Willits.

01:38 Presenter: I’m a 30-year veteran of Microsoft.

01:40 Presenter: I’ve been working on security in one form or another since 2002.

01:44 Presenter: The last five years, I’ve been working on driving security features into the Power Platform.

01:49 Presenter: In the last two years, I’ve been increasingly focused on the unintended consequences of citizen development,

01:54 Presenter: which is to say creating risk of oversharing data just by using the platform but using it incorrectly.

The Scale of Citizen Development; Low‑Code Misconfigurations – External Exposure

02:03 Presenter: My name is Michael. I’m the CTO and co-founder at Xenity.

02:06 Presenter: We’re an appsec company focused on helping large customers secure their low-code, no-code apps,

02:13 Presenter: recently AI agents and co-pilots.

02:16 Presenter: I also lead the OSP low-code, no-code top 10.

02:19 Presenter: And actually, most of my days are spent hacking these things.

02:23 Presenter: And so that’s where I feel most comfortable, but really excited to be taking the blue team perspective here today.

02:31 Presenter: So we’ve been collaborating for over two years now, in part focusing on risk from those unintended consequences of the citizen developer, not product gaps.

02:42 Presenter: I also started helping Michael with the top 10 back when it was the top five or six.

02:49 Presenter: to tell the same story, but one from, I’m sorry,

02:59 Presenter: we tell the same story and show how we did what we did

03:03 Presenter: so that you can do it yourself.

03:04 Presenter: So I think it’s really cool for Microsoft

03:07 Presenter: to be willing to share this story externally

03:09 Presenter: because I’m seeing lots of large organizations

03:13 Presenter: targeting the same kind of concerns,

03:16 Presenter: and Microsoft has really done an incredible job at it.

03:20 Presenter: So I just want to say thank you for the team

03:22 Presenter: for their willingness to share their story.

03:25 Presenter: All right, so let’s figure out where those numbers come from.

03:30 Presenter: And so one of the things that’s happening today

03:33 Presenter: is that building applications has become just very, very easy.

03:36 Presenter: And what you’re seeing on screen is,

03:39 Presenter: like just by talking to basically an AI chat bot,

03:41 Presenter: an application gets created.

03:43 Presenter: By the time you’re done with the conversation,

03:46 Presenter: now lives. It has identity.

03:48 Presenter: It can talk to data. It can be shared.

03:52 Presenter: It’s just

03:52 Presenter: so easy. While I’m talking,

03:54 Presenter: you see this application getting created.

03:56 Presenter: This is

03:58 Presenter: lowering the bar to create applications

04:00 Presenter: to be productive in an enterprise.

04:02 Presenter: It also means that the people that are building

04:04 Presenter: an application, they are everyone.

04:06 Presenter: This is no longer just a game for developers.

04:09 Presenter: These technologies are

04:10 Presenter: empowering everyone to just

04:12 Presenter: create things.

04:14 Presenter: But creating things in an enterprise is iffy, right?

04:18 Presenter: It’s important to get a whole bunch of things right,

04:21 Presenter: not just getting the app to work.

04:23 Presenter: And so let me give you just one example

04:25 Presenter: so we have something in mind.

04:27 Presenter: When I first visited Microsoft Campus

04:30 Presenter: while working with Dan like two years ago,

04:32 Presenter: this was just after COVID,

04:34 Presenter: and we had to upload vaccination proofs

04:39 Presenter: of vaccination to this app.

04:41 Presenter: So it was called the COVID Healthcare Check App.

Data Leakage and Bot Misuse

04:45 Presenter: And later I learned that this is actually a low-code app.

04:48 Presenter: Yeah, this was the first major app we built inside of Teams itself.

04:52 Presenter: When Power Platform and Power Automate Flow was integrated into Teams,

04:58 Presenter: this came out the door like the next day or so after that feature got enabled.

05:03 Presenter: So this is a pretty sophisticated piece of application,

05:06 Presenter: but more importantly, it’s storing healthcare data, personal data for people.

05:12 Presenter: So it’s really important to get it right.

05:14 Presenter: And even if somebody in the business is able to build it, which is awesome,

05:17 Presenter: of course, we need to handle security for that as well, right?

05:20 Presenter: So part of the reason why this world is getting unnoticed

05:25 Presenter: but also expanding widely within the enterprise

05:28 Presenter: is that you don’t really get to make a choice

05:31 Presenter: whether you’re adopting these technologies or not.

05:33 Presenter: So there’s no show me an enterprise in the world that doesn’t use at least one of the vendors that you’re seeing on screen right now.

05:39 Presenter: This is not just a Microsoft thing.

05:41 Presenter: Everybody’s using those technologies.

05:43 Presenter: And so this so low code, no code, like four years or five years ago.

05:47 Presenter: And Gen.ai and the next in the last two years have been just been added into those platforms that you already use, giving business users the ability to create themselves.

05:57 Presenter: This is not a choice.

05:58 Presenter: Everybody has this in the organization.

06:00 Presenter: It’s whether they take control of it or not.

06:03 Presenter: Microsoft has had a pretty early start on figuring out that this is important.

06:07 Presenter: This is a quote from Satya back in 2019.

06:11 Presenter: And he’s saying, hey, by like five years from now,

06:14 Presenter: we’re going to have 500 million apps built with these low-code, no-code tools,

06:20 Presenter: and it’s going to be more than what we’ve built together in the last 40 years.

06:25 Presenter: So this is what Satya said in 2019.

06:29 Presenter: We’re going to have 500 million apps by 2023.

06:33 Presenter: then Gen.ai hits. So this is before Gen.ai. This is before things become even easier to

06:39 Presenter: create. And so this is the growth just inside of the Microsoft tenant in the last year.

06:44 Presenter: You can see that the number of applications created with these technologies have been

06:49 Presenter: tripled in the last year. This is after the 500 million apps. So these numbers are really

06:54 Presenter: going crazy. We’re talking about almost 2 million assets in the Microsoft environment

06:59 Presenter: today. Again, crazy, crazy, crazy numbers. And so hopefully this gives you a bit of perspective

07:07 Presenter: into what we’re talking about and why it’s important for you to kind of stay with us

07:11 Presenter: for the rest of the time we have here today. And so up until now, we talked about these

07:17 Presenter: numbers, but I think this is a security conference. It’s important for us to show some implications.

07:23 Presenter: So let’s do that.

07:24 Presenter: Let me start with the first story.

07:27 Presenter: So Salesforce has this feature called community websites,

07:30 Presenter: and it’s like very easily you create a website that’s external facing

07:35 Presenter: for people outside of your organization.

07:37 Presenter: It could be for vendors.

07:38 Presenter: It could be for your partners.

07:40 Presenter: This is a very popular feature.

07:41 Presenter: So here’s a website that we created.

07:44 Presenter: This is a website for, like, showing customer use cases.

07:48 Presenter: So this is how a customer use case looks like.

07:51 Presenter: It’s a bunch of information about the customer.

07:53 Presenter: It’s connected back to the CRM.

Security Failures and Lessons Learned

07:56 Presenter: So the CRM holds the actual information.

07:59 Presenter: Now, of course, we don’t want to reveal the entire CRM.

08:01 Presenter: We just want to reveal information about specific customers.

08:04 Presenter: So this is how you set up whether a website like that is external facing or not.

08:11 Presenter: So, again, a single click.

08:13 Presenter: A single click is the distinction between whether this thing is going to be available for people anonymously on the Internet

08:21 Presenter: or just logged in folks.

08:23 Presenter: could lead to mistakes.

08:25 Presenter: So this is the first part we have here.

08:28 Presenter: We have an app that app is now publicly accessible

08:30 Presenter: because somebody clicked on that configuration.

08:33 Presenter: And then you need this app to be able to actually

08:36 Presenter: pull information from the CRM.

08:38 Presenter: This is done with a low-code tool called Salesforce Flow.

08:41 Presenter: It’s just like an automation tool.

08:43 Presenter: And you can see the automation here.

08:45 Presenter: It’s pretty simple, right?

08:47 Presenter: It just brings the information about specific customers.

08:51 Presenter: So now we have the app.

08:53 Presenter: The app is external facing, and it is using that flow behind the scenes.

08:58 Presenter: Now, this flow has a bunch of configuration.

09:01 Presenter: One of the things that you need to configure is how does this flow run?

09:05 Presenter: Does it run in user context or in system context?

09:09 Presenter: Guess what system context does?

09:11 Presenter: It completely ignores the role-based access control.

09:16 Presenter: So it means that even if you’re not logged in, even if you’re an anonymous user,

09:22 Presenter: you can still get information about everything in the table behind it.

09:25 Presenter: So, of course, what this means is that now you have external-facing folks,

09:30 Presenter: like people on the Internet, that then can get data about every customer,

09:35 Presenter: not just the customers that have their use cases out there.

09:38 Presenter: And so this is what this looks like.

09:40 Presenter: You can actually get to the table with all of the different customers that are available there.

09:44 Presenter: And so this is just like a series of small choices that together, the combined effect is data leaking outside of the Internet.

09:54 Presenter: Let me show you another example.

09:56 Presenter: So say you want to create an Ask HR copilot.

09:59 Presenter: So you have an Ask HR SharePoint site with a bunch of useful information.

10:03 Presenter: Now you want to create a copilot to be able to converse over that website.

10:08 Presenter: So you go through a quick wizard.

10:12 Presenter: This is a copilot studio.

10:15 Presenter: explain what you want this copilot to actually do.

10:18 Presenter: So first, we have now this copilot.

10:20 Presenter: It’s living out there in the Internet.

10:22 Presenter: One of the things that you can configure about this copilot is who has access to it.

10:27 Presenter: Okay?

10:28 Presenter: So is this going to be available just in Teams?

10:31 Presenter: Is this going to be available to external users?

10:34 Presenter: And one of the configuration options that you have here is no authentication.

10:39 Presenter: No authentication means anybody on the Internet can go out and talk to this bot

10:44 Presenter: Without logging in.

10:46 Presenter: This was actually the default for a while.

Remediation Strategy and Automation

10:48 Presenter: And so, of course, this means that we still have these bots out there.

10:51 Presenter: And so right now, somebody has made this mistake.

10:53 Presenter: This is no longer the default.

10:55 Presenter: But now somebody can make this mistake.

10:57 Presenter: They click on that button.

10:58 Presenter: And now you have a bot that’s out there in the Internet.

11:01 Presenter: This is still fine if we haven’t connected this bot to something important.

11:05 Presenter: So let’s do that.

11:07 Presenter: So you can add a bunch of knowledge to this bot.

11:10 Presenter: It can connect everywhere you’d like.

11:11 Presenter: Really, the knowledge sources here are very wide.

11:15 Presenter: One of the things that you can do is actually connect it to fabric.

11:18 Presenter: So on the other side, within the fabric ecosystem, you can take, let’s say, a CSV file with sensitive information.

11:25 Presenter: It could have a sensitive label, whatever you’d like.

11:27 Presenter: And you can create an AI skill out of it.

11:30 Presenter: Now, the data has a sensitivity label, but the AI skill doesn’t.

11:35 Presenter: And so now you can go back to Copilot.

11:37 Presenter: You can grab that skill.

11:39 Presenter: You can connect it to your bot.

11:41 Presenter: What have you done?

11:42 Presenter: Well, you have a copilot on one side.

11:45 Presenter: It’s connected to this AI skill inside of Fabric.

11:48 Presenter: And now you have public access on one side, business data on the other side.

11:52 Presenter: And you can see how this becomes very difficult to solve when it goes out between different ecosystems.

11:58 Presenter: It doesn’t stay just in one place.

12:00 Presenter: And so this is actually something that we’ve seen happen a lot.

12:04 Presenter: As I mentioned, this was a default for a while.

12:06 Presenter: And so one of the things that we did in order to check this out is to try and search those bots.

12:12 Presenter: So, for example, we know that AWS has been struggling for a while with S3 buckets, right?

12:19 Presenter: S3 buckets are open to the public.

12:21 Presenter: This is the same thing for Azure as well.

12:22 Presenter: And even though the defaults are now secure, we are still seeing those buckets misconfigured out there in the world, right?

12:29 Presenter: So we wanted to do the same thing here.

12:31 Presenter: So this is PowerPoint.

12:32 Presenter: This is a tool that we wrote.

12:33 Presenter: It’s a red teaming tool that allows people to basically check their own organizations.

12:39 Presenter: And what PowerPoint does is just it guesses a bunch of information.

12:42 Presenter: Maybe this is happening way too fast.

12:45 Presenter: So PowerPoint allows you to add either you can either point it at your tenant or scan the entire Internet widely.

12:54 Presenter: and so what it does is it guesses the specific random parts of the URL

13:00 Presenter: where these bots, these Copilot Studio bots are available on the Internet

13:04 Presenter: and so I’m scanning my own environment here of course

13:07 Presenter: and it’s finding out the tenant ID

13:10 Presenter: using the same technique that we learned from AID internals

13:13 Presenter: so thank you Nestori

13:16 Presenter: then we try to guess a bunch of information

13:20 Presenter: for example the environment ID

13:24 Presenter: the default environment ID.

13:25 Presenter: And on top of that, we need to guess a couple of things.

13:28 Presenter: So let’s see what are we actually guessing.

13:31 Presenter: So what we need to find is first the,

13:35 Presenter: you can see this like five-letter combination there.

13:39 Presenter: That’s basically something called the solution prefix,

13:42 Presenter: but this is something, this is not,

13:45 Presenter: so this is just five characters.

13:46 Presenter: It’s pretty easy to find.

13:48 Presenter: And then we just look for popular bot names.

13:51 Presenter: So you can see that we found copilot test, copilot flow, copilot 1, 2, 3, 4, up until 9.

14:00 Presenter: You’ll see in a moment copilot SharePoint, copilot POC.

14:04 Presenter: Every time I find one of these names, I get an actual website out there on the Internet.

14:10 Presenter: And after we found all of these bots, the next thing we’re going to do is just we’re going to go to every one of them and try to talk to them.

14:16 Presenter: And so some of them, you can see that they won’t talk to us, but some will.

14:21 Presenter: So every red line here is actually a copilot we find out there on the Internet ready to talk to us.

14:26 Presenter: So this tool is out there today, and again, it’s meant to help you secure your own organization.

14:32 Presenter: We have actually used it to scan the entire Internet or a vast majority of the Internet.

14:36 Presenter: We found more than 1,000 of these bots out there belonging to Fortune 500 companies that are exposing sensitive data.

14:45 Presenter: So you talk to them.

14:46 Presenter: You extract information behind them.

14:48 Presenter: They’ll tell you all of the secrets they know.

14:51 Presenter: All right. Let me give you another example. So one of the challenging things about working in an enterprise is that you need to work without look. No, I’m kidding. Is that when there are all of these security controls, right? And they are annoying sometimes. So what do people do? Well, they take their corporate email and they find a way to send the email to off to their personal Gmail accounts.

Program Outcomes and Future Directions — Part 1

15:18 Presenter: Now, if they do this without the forwarding rules,

15:20 Presenter: then we will probably find them.

15:24 Presenter: You have controls on the email server.

15:26 Presenter: You have controls on the network.

15:28 Presenter: This is all great.

15:29 Presenter: Here’s the latest innovation in getting your information to your Gmail.

15:33 Presenter: You simply use something like Power Automate

15:35 Presenter: to trigger on every new email that you get,

15:38 Presenter: and then you copy the content of the email to your personal Gmail address.

15:42 Presenter: So you will not find this on the email server.

15:45 Presenter: You will not see any email forward.

15:48 Presenter: copied inside of Power Automate.

15:50 Presenter: So no way for you to know.

15:52 Presenter: And so that’s something that we are seeing, by the way, a lot,

15:55 Presenter: like pretty much every organization we work with.

15:57 Presenter: And so for this example, we’re going to look at a few different things that went wrong.

16:04 Presenter: So the first thing here is, well, pretty obvious.

16:07 Presenter: Business data is linking to a personal account.

16:09 Presenter: But wait, there’s more.

16:11 Presenter: So what about the existing emails that I already have?

16:14 Presenter: So if I want to sync every email that I already have in my inbox to my Gmail account, how can I do that?

16:21 Presenter: Because this is not possible with the automation I just showed you.

16:25 Presenter: So this is a nice little app.

16:27 Presenter: It’s called Sync Outlook History to Gmail.

16:30 Presenter: I give it the email address to store the information in, and then how many emails I want to sync.

16:37 Presenter: This is how it looks like.

16:39 Presenter: And what you can see here is just like what I just showed.

16:44 Presenter: work? Well, there’s a Power Automate flow behind it. It goes out to my email address.

16:49 Presenter: It goes through each and every one of the emails, the last emails that I asked for.

16:55 Presenter: And then using my Gmail account, it sends those emails. But again, with my Gmail account,

17:01 Presenter: you have no controls there. And so you can see the icon on the right bottom of the screen.

17:07 Presenter: That’s basically the hacker icon or the malicious user icon. So what I’m going to do now is I’m

17:14 Presenter: app that I built for myself, and I’m going to share it with everyone.

17:19 Presenter: And by the way, when I say share with everyone, I really mean everyone.

17:23 Presenter: So you can see that this share also means I’m sharing, I would need access, this application

17:29 Presenter: would need access to Outlook, and when I share this application, this is going to be accessible

17:35 Presenter: to everyone that has access to your AAD tenant.

17:38 Presenter: This includes guests, and this is actually something that I was able to have a lot of

17:44 Presenter: Black Hat last year. So if you’re interested in what could go wrong when you can share something

17:48 Presenter: with everyone, credentials. The problem is credentials. So check out the talk I gave at

17:56 Presenter: Black Hat last year. So here’s the thing. Now I sent this to everyone, and now you have the

18:01 Presenter: little icon there of just the user, just the user in the organization, the guy on the right

18:07 Presenter: bottom of the screen. So they click on this app, and the app immediately says, hey, I need to be

18:14 Presenter: Okay, so you give it the access for Outlook, and you use the application, which is fine.

18:19 Presenter: But here’s the problem.

18:20 Presenter: Every piece of information that goes through Power Automate gets logged.

18:24 Presenter: So now as the malicious user that created this app, I can actually go to the flow execution logs and see all of your emails.

18:31 Presenter: So every user of this app ends up giving access to their emails to the person that created this app.

18:39 Presenter: So this is the second problem here, or we’re seeing two other problems, the sharing with everyone.

18:44 Presenter: and personal data that leads to logs.

18:46 Presenter: But wait, there’s more.

18:48 Presenter: Because this application is not just fetching this information.

18:52 Presenter: This application actually gets the ability to operate on behalf of that users

18:57 Presenter: with their Outlook account.

18:58 Presenter: This is not scoped to a specific permission.

19:01 Presenter: This is full user impersonation with this app.

19:05 Presenter: What this means is that I can use this to harvest credentials.

19:08 Presenter: So here’s another module in PowerPoint.

19:10 Presenter: I basically install

19:13 Presenter: so I need an app

19:15 Presenter: I need an account within an enterprise

19:17 Presenter: I install a malicious application

19:19 Presenter: in the enterprise

19:22 Presenter: and now

19:23 Presenter: this application is just a shout out application

19:25 Presenter: that’s on the templates there for Power Platform

19:28 Presenter: so it’s a nice little app

19:29 Presenter: again I’m logged in as the malicious user

19:31 Presenter: and I’m going to create a

19:33 Presenter: I’m going to do like a shout out

19:35 Presenter: for my victim, specifically the

19:37 Presenter: CFO of that company

19:38 Presenter: I’m going to say, hey, good job.

19:40 Presenter: Thank you very much.

19:42 Presenter: Send, like, a nice message.

19:44 Presenter: Your hard work is much appreciated.

19:47 Presenter: So now this is my victim.

19:49 Presenter: They’re going to get this nice little email.

19:52 Presenter: And wouldn’t you click it?

19:53 Presenter: Like, it’s a nice-looking email, right?

19:57 Presenter: Okay.

19:58 Presenter: So they get this email.

19:59 Presenter: They click on this link.

20:00 Presenter: They go to the shout-out app.

20:02 Presenter: But, of course, and, of course, they’ll give a shout-out to somebody else.

20:05 Presenter: Of course, once they use the app, I just stole all of their emails.

20:09 Presenter: Because why not?

20:10 Presenter: I have access to their account while they’re using the app.

20:14 Presenter: And the thing behind these applications, of course, every application can do that.

20:19 Presenter: But the thing here is that this application is hosted on a Microsoft domain, is very highly trusted,

20:25 Presenter: is not scoped in terms of OAuth permissions, and so it’s just a recipe for disaster.

20:33 Presenter: So again, you can use this to try and test your defenses.

20:37 Presenter: So this is the fourth thing here, privilege escalation path and account impersonation.

20:43 Presenter: This is a big deal within those applications.

20:45 Presenter: And so I think, so this is just like a thing that tries to wrap everything around here.

20:51 Presenter: So we have a privilege escalation path with a bunch of sensitive data that could leak.

20:55 Presenter: Let me leave you off with one last example, and I’ll be quick about it.

20:59 Presenter: Go ahead.

21:00 Presenter: So we have John, the persistent vendor.

21:02 Presenter: Next slide.

21:03 Presenter: John is an employee of the fictional Contoso LLC Corporation, and for 18 months, we hired him to create Salesforce assets like DataFlows.

21:13 Presenter: So during that 18-month period, his Active Directory account, excuse me, EntraID account is enabled.

21:22 Presenter: But as soon as that contract expired, he can no longer call the flow, modify the flow.

21:28 Presenter: But before he left, he added his place of business as an identity, giving it full ownership and editable privileges.

21:35 Presenter: Now, this is something I see with vendors a lot.

21:38 Presenter: And I sometimes wonder if the vendor companies actually insist upon this for some reason.

21:43 Presenter: But if you see this once with a vendor, you’re going to see it practically in everything they create.

21:48 Presenter: But also before John left, he added Johnny5 at Hotmail.com, which is his personal ID.

21:55 Presenter: there is no legitimate business user reason for him to do that.

22:01 Presenter: So this is a pattern we see with full-time employees as well, not just vendors.

22:08 Presenter: But it does seem to be a pattern that we see more than once with vendors themselves.

Program Outcomes and Future Directions — Part 2

22:14 Presenter: So all of these examples, this is just to show that if we are leaving these –

22:20 Presenter: so business users are now creating pretty sophisticated applications.

22:25 Presenter: and most of them are doing this alone.

22:28 Presenter: And as security teams, we are just not involved.

22:31 Presenter: Now, of course, what’s going to happen

22:33 Presenter: is that they’re going to make a bunch of mistakes.

22:35 Presenter: Of course they will because we’re not helping them.

22:38 Presenter: So if we’re going to continue to let them do that,

22:42 Presenter: then this is not going to work.

22:45 Presenter: So let’s go through a few examples

22:48 Presenter: of what we tried to do to actually fix this

22:50 Presenter: and how did we fail.

22:52 Presenter: So, of course, the first thing,

22:53 Presenter: so you have all of these apps.

22:55 Presenter: You understand why they are important.

22:57 Presenter: And now, what would be the best thing that you,

22:59 Presenter: the first thing that you try to do to build a program

23:02 Presenter: that can actually solve this?

23:03 Presenter: You’d go after best practice.

23:05 Presenter: And, of course, spoiler alert, none of them will work.

23:08 Presenter: And so let’s take a free, three different best practice here,

23:12 Presenter: focusing on crown jewels, right?

23:14 Presenter: We have so many apps.

23:15 Presenter: Let’s focus on the ones that matter.

23:17 Presenter: Getting developer buy-in, so getting the developers

23:19 Presenter: to actually not make so many mistakes.

23:22 Presenter: And the SDL.

23:23 Presenter: So let’s start with focusing on crown jewels.

23:25 Presenter: Let’s look at the Microsoft environment.

23:28 Presenter: We want to find which of these applications are actually important.

23:31 Presenter: Well, guess what?

23:33 Presenter: This is the number.

23:34 Presenter: So you can see the numbers of active credentials to each one of the different services.

23:39 Presenter: These are all crown jewels.

23:41 Presenter: By definition, these are all built within your business application where you hold all of your important information.

23:47 Presenter: So good luck with trying to figure out which ones are not important, not for you to focus on.

23:53 Presenter: Just if you want to focus on every app that connects to Office 365, you’re over a million different connections here.

24:03 Presenter: So the next thing you’re thinking about is, okay, let’s get developer buying.

24:07 Presenter: Let’s get these business users not to make so many mistakes, right?

24:11 Presenter: So try and have a conversation with somebody in finance or in sales about storing sensitive data, storing social security numbers in a safe way.

24:21 Presenter: This is actually an example we see a lot.

24:23 Presenter: So people store sensitive data behind those applications,

24:27 Presenter: available to everyone in plain text.

24:28 Presenter: Of course, you can’t really expect them to have that conversation.

24:31 Presenter: It’s not a fair conversation to have.

24:33 Presenter: And then you have the SDL.

24:36 Presenter: So I’ve been working with the SDL for the last 20 years,

24:39 Presenter: and even further back before we even decided to call it the SDL,

24:42 Presenter: it was there back with the original Bill G

24:44 Presenter: trustworthy computing memo in 2002.

24:47 Presenter: We more recently added Zero Trust,

24:51 Presenter: of scope for this talk.

24:53 Presenter: Next.

24:55 Presenter: Okay, so how well does SDL guidance apply to low code, no code, all up?

25:02 Presenter: Not just Power Platform, but all low code, no code platforms.

25:05 Presenter: I did a gap analysis on our internal technical requirements in SDL that would apply to things

25:12 Presenter: that you create with low code, no code, and 71% of it is just can’t get there from here.

25:18 Presenter: It’s either specific to technology you only find in Visual Code or Visual Studio or platforms like that.

25:24 Presenter: Low-code, no-code hides things from you that you might not be able to get to.

25:30 Presenter: And usually it’s not a bad thing to hide that, but sometimes there are consequences.

25:36 Presenter: One of the prominent requirements in any SDL should be use HTTPS.

25:41 Presenter: Ensure that the data between you and whatever you’re talking to is encrypted in transit.

25:47 Presenter: The thing about HTTPS is that PowerApps.com, or actually Preview.Make.PowerApps.com, I think I got it right, the HTTPS is implemented for you.

25:57 Presenter: So the communications channel between you and PowerApps.com itself is encrypted.

26:01 Presenter: But what about your connections?

26:04 Presenter: So many connections take URLs as the connection parameter.

26:09 Presenter: So did the citizen developer even remember to include HTTPS?

26:14 Presenter: If they did, is the back-end server configured and patched so that HTTPS isn’t dropping down to plain text by accident?

26:23 Presenter: Is there even an HTTPS implementation on that back-end data server where the data is being hosted?

26:29 Presenter: This level of nuance is something that’s not going to be in the citizen developer’s awareness.

26:35 Presenter: A lot of our SDL tools, we have a lot of SDL tools internally and externally that they’re built for a source code file.

26:45 Presenter: They’re built for a compiled binary, neither of which exists in low-code, no-code.

26:52 Presenter: For the typical low-code, no-code developer, the business user, this is just technobabble.

26:57 Presenter: It’s a well-written piece of SDL content, but for them, it’s just over their heads.

27:04 Presenter: If we look at the traditional high slices of the secure development lifecycle, the never-ending circle, we have seven slices.

27:13 Presenter: They’re split across responsibilities with four different teams.

27:17 Presenter: The business, engineering, quality assurance, and operations.

27:22 Presenter: But with low code, no code, we’re bouncing constantly from envision, create, envision, create.

27:27 Presenter: Actually, we envision, create, publish.

27:28 Presenter: Envision, create, publish.

27:29 Presenter: It’s like agile on steroids in this respect.

27:34 Presenter: awareness of the other pie slices.

27:36 Presenter: And a lot of things are handled for you,

27:39 Presenter: but there’s still some gotchas here and there,

27:41 Presenter: like the HTTPS connector example.

27:46 Presenter: We have features in Power Platform.

27:48 Presenter: I can’t speak to other platforms for continuous integration,

27:50 Presenter: continuous development, but it’s not widely adopted.

27:55 Presenter: And so there’s places in the SDL might hook into your CI, CD.

28:00 Presenter: There’s no place, well, there is a place to hook into it,

28:04 Presenter: consistently?

28:05 Presenter: So at this point, we’re kind of stuck, right?

28:08 Presenter: We are trying, we’ve tried the best practice.

28:10 Presenter: We have all of these applications that are created,

28:12 Presenter: all of these different credentials.

28:14 Presenter: We are in a place where we can’t move forward.

28:18 Presenter: And so now one of the,

28:21 Presenter: so we needed an insight to get us out of this dent.

28:25 Presenter: And here it is.

28:26 Presenter: Remember these applications.

28:27 Presenter: These applications are very easy to create, right?

28:31 Presenter: If something is so easy to create,

28:34 Presenter: be also easy to fix it? Shouldn’t we be able to understand everything about the app, about

28:40 Presenter: its environment, about its connections and credentials, and find out and actually create

28:46 Presenter: a patch for you, or tell you what are the exact things that you need to do to actually

28:52 Presenter: fix it? So this is how we actually got started. We got started with this idea of autofix or

28:58 Presenter: silent remediation. This was basically saying, okay, for some of these problems,

29:04 Presenter: for some of these volumes, we can actually fix them automatically.

29:08 Presenter: We don’t need to talk to anyone.

29:09 Presenter: We don’t need to ask people to do stuff.

29:11 Presenter: We can just change configuration.

Program Outcomes and Future Directions — Part 3

29:13 Presenter: We can change the, so you can see a few examples here.

29:16 Presenter: These are clear examples where we can fix things,

29:19 Presenter: and we know we’re not going to prevent business.

29:21 Presenter: We’re not going to make any bad impact.

29:25 Presenter: And so, of course, this is not possible for any vulnerability,

29:27 Presenter: but it’s possible for many of them,

29:29 Presenter: and you’ll see how many the team was able to actually pull off.

29:34 Presenter: gave us a start because once we have autofix, we can show early success.

29:40 Presenter: And once we have early success, then we can go to higher management and say,

29:44 Presenter: hey, please give us more resources to actually fix this problem.

29:47 Presenter: And so once we have buying, of course, we can take over the world.

29:51 Presenter: Well, we can’t, but we can scale this program.

29:54 Presenter: We can get the resources.

29:55 Presenter: We can get the backup required to actually scale this program.

29:58 Presenter: So now you know what this stock is actually going to give you.

30:04 Presenter: plate, an idea on how you can, or actually kind of practical advice on how you can build

30:09 Presenter: this program to work in your organization.

30:14 Presenter: So how did we make it work?

30:16 Presenter: Good, I get to trade places with you.

30:18 Presenter: Good.

30:22 Presenter: Well, we started by envisioning the project, of course.

30:25 Presenter: We want to remediate all the vulnerabilities.

30:26 Presenter: We have a limited team of two to three headcount, depending on how you count.

30:31 Presenter: After the automation had been written, which was based on some previous burndown automation,

30:36 Presenter: we had six months, and we finished in just a little over four.

30:41 Presenter: If we wanted to have a minimum viable product, it had to be self-serve.

30:46 Presenter: So we were constantly thinking about the citizen developer, making sure that we had step-by-step instructions,

30:52 Presenter: and we had a screenshot for each instruction that had visual cues in the screenshot itself

30:58 Presenter: is make sure that the developer could tie the text directly to the screenshot

31:01 Presenter: and there’d be no ambiguity.

31:04 Presenter: Here’s an example here.

31:10 Presenter: So Michael’s just talking about automatic remediation.

31:15 Presenter: Do we have enough context?

31:17 Presenter: Is there enough functionality in the cmdlets and the APIs and the admin connectors

31:22 Presenter: that will let us actually fix the misconfiguration live?

31:28 Presenter: We usually ran this in the dark of night, at least if you’re in the Americas.

31:31 Presenter: The rest of the world, your mileage will vary.

31:35 Presenter: So anything we couldn’t auto-fix, we wanted to give a reasonable time frame before we would shift-delete their risky assets.

31:42 Presenter: So we settled on 30 days to fix.

31:45 Presenter: So when you receive an email from us, either burning down pre-existing risk or net new risk, the 30-day clock is ticking when that email is sent.

31:55 Presenter: So this was our get to green, and we decided anything created before January 1st, we would call brownfield or pre-existing.

32:02 Presenter: Anything created after January 1st would be greenfield or net new.

32:07 Presenter: But that also meant, because we were focusing on the pre-existing, we weren’t necessarily auto-fixing net new as it came in.

32:16 Presenter: So this is sort of the process, a simplified version of the process of the application we had.

32:23 Presenter: from Xenity, or we decide we’re going to burn something down that’s pre-existing risk. First

32:28 Presenter: thing we do is send out that email. I’m just going to stay in the top swim lane for the moment.

32:32 Presenter: If 14 days go by and no response, it’s still not fixed, we send out another email.

32:37 Presenter: Nine days goes by and no response. We send out a final email. We wait seven days. Is it fixed?

32:43 Presenter: Great. Close the violation. If it’s not fixed, shift, delete, close the violation.

32:48 Presenter: Sometimes though, there are going to be false positives. Generally, guests are things that

32:53 Presenter: are legitimate cases where guests need to have access to your asset, to your application,

32:59 Presenter: to your co-pilot. So there’s going to be times when, yes, there’s a legitimate business case,

33:06 Presenter: great, tell us what it is, close the violation. Sometimes the dev needs support, we would answer

33:12 Presenter: questions and fine-tune our step-by-step instructions, and then they’d fix it and

33:18 Presenter: close the violation. Now, something, this is going to be one of those, your mileage may vary,

33:24 Presenter: that based on your environment strategy or equivalent in other platforms,

33:28 Presenter: you may want to migrate this user’s assets into, say, like a developer environment

33:33 Presenter: just to provide better isolation and atomic controls

33:37 Presenter: that will make it less likely someone could see this and take advantage of it.

33:43 Presenter: Our governance team for Microsoft, they’re actually taking care of that,

33:47 Presenter: so we stayed in our swim lane and didn’t do anything with that,

33:51 Presenter: but that’s something you might want to think about based on your needs.

33:56 Presenter: And there’s a great, great discussion on environment strategy up in the documentation.

34:01 Presenter: Our governor’s team helped them write it, at least a little tiny bit if they survived in there.

34:05 Presenter: You may also want to file an exception or track an exemption.

34:09 Presenter: If someone does say this is a false positive, that’s up to you.

34:14 Presenter: We are going minimum viable product and skipping that part entirely.

34:21 Presenter: here’s a view of the SharePoint list where we keep the instructions. Here’s a view where we

34:25 Presenter: edit the SharePoint list. Here’s an example of the first email that goes out. And we worked very

34:35 Presenter: hard with a professional editor to make sure this text was very crisp, very clean, and had no

34:39 Presenter: ambiguity. Sometimes when I get these messages, sometimes they’re well written. Sometimes you got

34:44 Presenter: to kind of read between the lines to figure out what you have to do. Final notice, we have that

34:51 Presenter: to get your attention, hopefully.

34:54 Presenter: And here’s the actual violations dashboard.

34:56 Presenter: This is what both mails are sending you to.

34:58 Presenter: So I blacked some things out

35:00 Presenter: so we don’t advertise the names of our connections

35:02 Presenter: and our users across the internet.

35:04 Presenter: But there’s three violations here.

35:07 Presenter: The top violation is one of those

35:09 Presenter: that could be a false positive.

35:11 Presenter: It’s not necessarily a bad thing

35:13 Presenter: that you’re connecting to an on-premise connector

35:15 Presenter: or on-premise data source instead of the cloud.

35:19 Presenter: but generally we want things in the cloud.

35:22 Presenter: So if you have a choice between the two, you should choose the cloud generally,

35:28 Presenter: but your mileage may vary.

35:30 Presenter: And so we leave room for that.

35:32 Presenter: The bottom two violations are loosely coupled.

35:35 Presenter: I’m going to focus on the bottom one.

35:37 Presenter: The connection is using shareable authentication method.

35:40 Presenter: The middle one says, okay, it should be readable,

35:42 Presenter: it says connection is accessible by the entire tenant.

35:45 Presenter: Sometimes these two can be coupled.

35:48 Presenter: not. It just depends on how the asset was built. Connection is using a shareable authentication

35:54 Presenter: method means you’re not using Enter ID. So I think we have like 1,300, 1,400 total connectors.

36:00 Presenter: About 120 of those are to Microsoft first-party products and services. And about slightly less

36:07 Presenter: than 50 of those have multiple forms of authentication. And you really want to use

Program Outcomes and Future Directions — Part 4

36:12 Presenter: Enter ID at all possible. Because if you use like a user ID password or just a simple key,

36:18 Presenter: you can get these weird side effects that are endemic to the actual data source.

36:24 Presenter: So here we’ve clicked on the bottom violation.

36:27 Presenter: You get three tabs.

36:29 Presenter: We’re going to talk about two.

36:30 Presenter: The violations description tab, you know, what is this?

36:35 Presenter: What caused it?

36:36 Presenter: Give you an explanation.

36:38 Presenter: The steps to fix is our SharePoint list again.

36:43 Presenter: and one of the keys to being able to have our automation work for both

36:47 Presenter: greenfield and brownfield were playbooks. When condition X, Y,

36:51 Presenter: and Z is discovered, then take actions A, B, and C to remediate it.

36:56 Presenter: And so this would get triggered whether it was a net new violation, stay green,

37:00 Presenter: or we were doing a campaign, get to green.

37:04 Presenter: So the results were, we proved we can scale up.

37:08 Presenter: We proved we can get to green in two of our environments, two of our

37:11 Presenter: environments. And we proved that we can use stay green and get to green with the same automation,

37:17 Presenter: same process, the same tooling. Here you can see our progress over the first six months of this

37:23 Presenter: year. If we look at the May 1st column, that top green slice of open violations, that’s a mix of

37:32 Presenter: 30 data fix and probably the last of the net new violations that have come in after January 1st.

37:37 Presenter: So somewhere in April, we burned through the last of that risk from before January 1st, and then we started playing catch-up with everything that had come in since.

37:45 Presenter: By the time we got to June 1st, that low green slice is nothing but 30 days to fix.

37:50 Presenter: Management or senior leadership teams always say, why isn’t it 100%?

37:54 Presenter: And the answer is because we got these 30-day clocks ticking.

37:56 Presenter: We’ll never get to 100%.

38:00 Presenter: But 95% with 5% open isn’t bad.

38:04 Presenter: and as we scan more and more things over time,

38:06 Presenter: that 5% will drop down to 4% to 3%.

38:09 Presenter: But there can be minor monthly variations.

38:14 Presenter: I think Don is being super modest,

38:16 Presenter: so let me go out on a limb and just say it out as it is.

38:20 Presenter: I think when you look at these such high numbers of applications,

38:24 Presenter: you can imagine how many issues you can find.

38:27 Presenter: Like, show me an AppSec program that can scale 100x or 1,000x

38:34 Presenter: and fix 95% of all issues in four months.

38:37 Presenter: This is just incredible work,

38:39 Presenter: so I think it really deserves the recognition.

38:42 Presenter: Thank you.

38:44 Presenter: So part of the success we had

38:46 Presenter: is because I’ve set up three different SDL programs

38:48 Presenter: over the years.

38:49 Presenter: Within the org, it was once known as MSIT.

38:52 Presenter: It also meant I was full of clever ideas

38:54 Presenter: and creeping elegance that would politely get shot down

38:56 Presenter: and then shake my head and say,

38:57 Presenter: yep, no, that was beyond what we have time for.

39:01 Presenter: So what are some of our takeaways?

39:05 Presenter: So, implicit underneath this was the OWASP top 10 for low code, no code.

39:10 Presenter: This was something I was probably more concerned than other team members on this project,

39:14 Presenter: but this was very impactful on me in terms of thinking about what do we want to fix, how do we want to fix it.

39:20 Presenter: The top 10 for large language models is increasingly in scope.

39:25 Presenter: So, I think right now we have rules for about four to five of these categories.

39:30 Presenter: They look somewhat like what we already have for low-code, no-code, but as time goes on, I imagine things will get more and more sophisticated as the AI features in Copilot and elsewhere get more and more sophisticated.

39:46 Presenter: We prioritized what we wanted to fix.

39:49 Presenter: We looked at all the violations and looked at the top ten and basically came up with six campaigns, guest and or access control, AI and or Copilot issues.

40:00 Presenter: and so on. I was assuming we’d move stately from one category to the next, to the next,

40:05 Presenter: and our burndowns. The reality is anytime we sent out an email campaign, we were probably

40:09 Presenter: covering two to three of those based on, there’s always little questions from SLT as things were

40:15 Presenter: coming in and say, well, why don’t you do this instead? So we would balance our prioritization

40:20 Presenter: accordingly. I think that’s a really cool point that people usually say, okay, let’s do campaigns

40:26 Presenter: that are focused on one specific thing

40:28 Presenter: and go one after the other.

40:30 Presenter: And you can see the different campaigns

40:32 Presenter: that were important for Microsoft to cover here.

40:34 Presenter: But then I think what we found

40:37 Presenter: was that we can actually do more than once.

40:39 Presenter: So because you get the confidence

40:40 Presenter: that this is not creating a lot of noise,

40:43 Presenter: problems are getting fixed,

40:44 Presenter: people are happy,

40:45 Presenter: then you can push forward fast.

40:48 Presenter: So here’s part of our dashboard.

40:50 Presenter: So that’s a piece you don’t want to forget

40:52 Presenter: is make sure you can report out to SLT

40:53 Presenter: to show what you’re accomplishing.

40:57 Presenter: We blacked out a couple of sensitive things, but the column over on the far right, bottom far right, shows you basically how many violations that we were mediated in each category.

41:07 Presenter: And, of course, the heat map there kind of gives you a sense overall as well.

41:14 Presenter: So now we want to finish up on something that kind of came up by accident.

41:19 Presenter: Michael had been talking about the shared responsibility model at a high level in his talks for a good year or so.

41:27 Presenter: But by the end of that six-month campaign, it was clear to us that we needed to go to a deeper level.

41:33 Presenter: So, Michael, I’ll have you represent your own slides.

41:36 Presenter: So one of the things that, like, if we want to take a step back and figure out what’s happening here,

41:42 Presenter: we are just not thinking about the shared responsibility model.

41:47 Presenter: So most people, when they think about, like, citizen development, business users building stuff,

41:53 Presenter: They are thinking about, yeah, this is all going to be secure and nothing could go wrong.

41:59 Presenter: But of course, every piece of technology, if it’s impactful, if it’s powerful, it can do bad stuff, right?

42:06 Presenter: There’s no free lunch.

42:09 Presenter: And so we need to think about the shared responsibility model.

42:13 Presenter: And we know that works in the cloud.

42:15 Presenter: So here’s the shared responsibility model from the cloud, specifically for serverless.

42:19 Presenter: So the platform itself, Azure, AWS, GCP, whatever, they own, making sure that the platform itself is safe, and it gives you the right building blocks, and each building block has safe configuration.

42:31 Presenter: But of course, you are in charge of what you build.

42:34 Presenter: Nobody else can own this for you.

42:37 Presenter: Local, no code is exactly the same.

42:39 Presenter: You just don’t own the code, but you do own the business logic.

42:43 Presenter: You do own access.

42:44 Presenter: You do own the data.

42:46 Presenter: So it’s pretty much the same thing as serverless, but somehow we forgot about it.

42:52 Presenter: Somehow we’re not sure, it’s not clear to us that within low-code, no-code,

42:58 Presenter: there’s also a shared responsibility model.

43:00 Presenter: So for people that are using low-code, no-code, not the platform,

43:04 Presenter: like here are a bunch of questions to ask yourself.

43:07 Presenter: So can you answer how many of your apps are moving data outside of your corporate boundary?

Program Outcomes and Future Directions — Part 5

43:12 Presenter: How many users are oversharing data?

43:14 Presenter: Or how many of them are allowing external access?

43:17 Presenter: How many are outcoding secrets?

43:19 Presenter: These are questions that only the organization using these platforms can answer, not the platform itself.

43:26 Presenter: So this all goes to one thing.

43:30 Presenter: Do we apply application security to what these business users are building or not?

43:35 Presenter: And if we’re not, well, of course, we’re going to get the wrong thing.

43:39 Presenter: So we give a lot of power to business users, developer-level power, and with AI especially.

43:46 Presenter: Of course, if we’re not there to help them, things would go wrong.

43:51 Presenter: So we don’t have time to go into this in great depth, but I started with his domains, access control, business logic, data management, added governance, added responsibility of the low-code, no-code platform itself,

44:04 Presenter: and then other platforms that you can use, say, block people, bulk exfiltrating their email.

44:09 Presenter: to Gmail. Expanded on his roles and then came up with what we hope was a lean and mean list of

44:18 Presenter: actual responsibilities. Before the month of November is over, we’ll have a detailed white

44:23 Presenter: paper walking through this. Okay, next slide. Let’s do real quick because we got 30 seconds.

44:31 Presenter: So we, at the end of the day, next slide, we got de facto SDL enforcement. We didn’t get things

44:39 Presenter: and other process like the SDL bug bar,

44:42 Presenter: but in terms of the technical requirements

44:43 Presenter: and in terms of things that there’s tooling for the SDL to validate

44:46 Presenter: and ensure compliance,

44:49 Presenter: we got the equivalent with the process that we were using.

44:52 Presenter: Next slide.

44:55 Presenter: Next slide.

44:56 Presenter: We’ve got to get to the last two slides.

45:01 Presenter: So things that we recommend,

45:05 Presenter: you know, if you don’t know the SDL,

45:07 Presenter: please check out the SDL.

45:09 Presenter: We’re due for a refresh of the OWASP top 10 for low-code, no-code in 2025.

45:14 Presenter: So we both invite all of you to come join us.

45:17 Presenter: It’s going to be fun.

45:20 Presenter: Again, the low-code, no-code shared responsibility white paper is coming shortly.

45:24 Presenter: And then we’ll have a full write-up of this talk available there.

45:27 Presenter: And all of the links will be available in this link.

45:29 Presenter: So if you want to grab a picture, this is the one.

45:32 Presenter: So let’s just, like, to wrap things up, this, like, low-code, no-code and Gen.AI,

45:39 Presenter: business today, in your organization today.

45:42 Presenter: So it’s really important for us to figure out that this thing is really powerful, but

45:50 Presenter: there’s a shared responsibility model, and we need to own our part.

45:54 Presenter: The second thing is that I think this has been an incredible example of how you can

45:59 Presenter: actually build a program that can scale to this level and get to really unprecedented

46:04 Presenter: results.

46:05 Presenter: So I think that’s really powerful.

46:06 Presenter: And so the end result here is that you can have both.

46:09 Presenter: empower your business and also stay secure.

46:12 Presenter: And so with that, thank you.

46:15 Presenter: Thank you very much.