Keytos Security
Keytos Security
  • 181
  • 136 241
The Most Powerful Cloud RADIUS Got Better What is New in EZRADIUS in 2025
EZRADIUS just got a major update, making it an even better cloud RADIUS for Microsoft 365 and Entra ID. Learn about the latest features
Learn More www.keytos.io/cloud-radius-as-a-service-for-azure-and-entra-id
Переглядів: 25

Відео

How to Setup Self-Service FIDO2 onboarding and Entra CBA with EZCMS From Start to Finish
Переглядів 4314 днів тому
Are you trying to setup Entra CBA and FIDO2 in Microsoft 365 / Entra ID? In this video we teach you how to setup self service FIDO2 and Entra CBA Onboarding in less than 30 minutes. Docs: www.keytos.io/docs/passwordless-onboarding/ Learn More about EZCMS Yubikey Onboarding Solution: www.keytos.io/passwordless-onboarding Learn More about EZCA Cloud PKI: www.keytos.io/azure-pki 0:00 Intro 0:35 Cr...
FIDO2 and Entra CBA Onboarding Just Got Easier: Whats New in EZCMS
Переглядів 5321 день тому
If you are looking to onboard your #fido2 key and Entra CBA, The already powerful EZCMS onboarding tool for phishing resistant onboarding just got better and easier to use, so get your YubiKey or FEITIAN key ready and go password less today! Learn more about EZCMS www.keytos.io/passwordless-onboarding
How To Use Entra ID For SSH - Sir Tifficate explains to Tux about EZSSH
Переглядів 18628 днів тому
Tux learns that Linux has not been forgotten on the Entra ID and Microsoft world. Sir Tifficate explains how EZSSH helps you authenticate to linux using entra ID. You can learn more about EZSSH and Linux Authentication: www.keytos.io/passwordless-ssh-authentication
How To Issue SCEP Certificates to Domain Joined Windows Devices
Переглядів 76Місяць тому
You are using Intune to Issue SCEP Certificates, however, you still have some domain joined windows machines and are looking at how to issue SCEP certificates for them? Learn how EZCA can help you Issue certificates for both Intune and Domain Joined Machines. github.com/markeytos/Certificate-Renewal-Client www.keytos.io/azure-pki
How To Enable WebEnroll for ADCS in Azure
Переглядів 34Місяць тому
Enable Web Based Certificate Issuance for your Active Directory Certificate Services (ADCS) CA, or for a cloud-based Azure PKI using EZCA. This will enable you to allow access to your users using their Entra ID identity. Learn About Azure PKI www.keytos.io/azure-pki
How To Automatically Rotate Azure Key Vault Private Certificates
Переглядів 83Місяць тому
Are you looking for a way to Automate your Private Certificates in Azure Key Vault? EZCA can connect to your existing PKI or create a cloud-based certificate authority in Azure and connect to Azure Key Vault for Automatic Certificate Rotation. Learn more about Azure PKI www.keytos.io/azure-pki
How to Issue Linux SCEP Certificates in Intune
Переглядів 93Місяць тому
Are you trying to distribute wifi certificates on Linux with Intune? In this video we go over how to Issue SCEP certificates to Linux Devices in Intune Docs for Linux SCEP certificates in Intune: www.keytos.io/docs/azure-pki/create-ssl-certificates-with-mdm/intune-certificate-authority/create-intune-certificate-profiles/how-to-create-linux-scep-certificates-in-intune/
How To Go Passworldess in Hybrid Environments - FEITIAN Webinar
Переглядів 1792 місяці тому
How To Go Passworldess in Hybrid Environments - FEITIAN Webinar
How To Find Similar Domains that Might Be Phishing Your Customers
Переглядів 782 місяці тому
How To Find Similar Domains that Might Be Phishing Your Customers
What is MFA Fatigue Attack
Переглядів 2452 місяці тому
What is MFA Fatigue Attack
How Phishing Resistant Authentication Works
Переглядів 1702 місяці тому
How Phishing Resistant Authentication Works
How EAP-TLS Wi-Fi Certificate Authentication Works
Переглядів 1,3 тис.3 місяці тому
How EAP-TLS Wi-Fi Certificate Authentication Works
How To Connect to Wi-Fi Using Entra ID Using Cloud RADIUS
Переглядів 5503 місяці тому
How To Connect to Wi-Fi Using Entra ID Using Cloud RADIUS
Can I Go Passwordless with Windows Hello For Business
Переглядів 16 тис.3 місяці тому
Can I Go Passwordless with Windows Hello For Business
How To Enable MAC Address Authentication in Cloud RADIUS
Переглядів 2193 місяці тому
How To Enable MAC Address Authentication in Cloud RADIUS
How To Prevent Phishing Attacks with Unphishable credentials - Sir Tifficate Journey to Zero Trust
Переглядів 763 місяці тому
How To Prevent Phishing Attacks with Unphishable credentials - Sir Tifficate Journey to Zero Trust
How To Install EAP-TLS Wifi Proflies for Apple Devices Using EZRADIUS
Переглядів 6134 місяці тому
How To Install EAP-TLS Wifi Proflies for Apple Devices Using EZRADIUS
How To Create Wi-Fi Certificates Without Intune
Переглядів 3154 місяці тому
How To Create Wi-Fi Certificates Without Intune
How smartcards work
Переглядів 5024 місяці тому
How smartcards work
FIDO2 + SmartCard (PIV) functionality is the best hardware token for Entra ID and Active Directory
Переглядів 6274 місяці тому
FIDO2 SmartCard (PIV) functionality is the best hardware token for Entra ID and Active Directory
What is FIDO2 Authentication
Переглядів 1,4 тис.4 місяці тому
What is FIDO2 Authentication
What are Unphishable Credentials
Переглядів 805 місяців тому
What are Unphishable Credentials
Why Should You Modernized Your PKI and Move your Certificate Authorities to the Cloud
Переглядів 1075 місяців тому
Why Should You Modernized Your PKI and Move your Certificate Authorities to the Cloud
How To Troubleshoot RADIUS with EZRADIUS Cloud RADIUS
Переглядів 1635 місяців тому
How To Troubleshoot RADIUS with EZRADIUS Cloud RADIUS
The problem with SSH keys. Are SSH Keys Secure?
Переглядів 3925 місяців тому
The problem with SSH keys. Are SSH Keys Secure?
What Certificate Authority To Use for Azure IoT
Переглядів 996 місяців тому
What Certificate Authority To Use for Azure IoT
What is an HSM?
Переглядів 2536 місяців тому
What is an HSM?
Setup Meraki VPN to User RADIUS with Entra ID
Переглядів 5276 місяців тому
Setup Meraki VPN to User RADIUS with Entra ID
How to Enable Certificate Based Authentication in Meraki Networks with EZRADIUS Cloud RADIUS
Переглядів 1,7 тис.6 місяців тому
How to Enable Certificate Based Authentication in Meraki Networks with EZRADIUS Cloud RADIUS

КОМЕНТАРІ

  • @JakeDigweed-c5y
    @JakeDigweed-c5y 5 днів тому

    Great video! The right tools are a must for MSPs. Robust cybersecurity, reliable backups, and Thirdlane Multi Tenant PBX help maintain secure and efficient communication.

  • @vagrantrandomstuff2312
    @vagrantrandomstuff2312 7 днів тому

    Just wondering, what is that device model? Does it have a mac-based radius authentication and does it have an option for bandwidth accounting?

    • @keytos
      @keytos 6 днів тому

      I don't remember which model we used for the video but it works with any TP link that supports RADIUS. Yes we also support Mac-Based auth www.keytos.io/docs/cloud-radius/manage-cloud-radius-pap-user-passwords/how-to-enable-mac-address-bypass/ and accounting

  • @sonakshikhangar9156
    @sonakshikhangar9156 10 днів тому

    Thanks for this wonderful knowledge base. Just to know one thing ... can we have fido2keys stored on smartcard..... just for curious about it...

    • @keytos
      @keytos 6 днів тому

      There are new smartcards that now also support FIDO2 keys. If you purchase one of those then yes the same smartcard can have both the FIDO2 and the SmartCard Certificate

  • @q3ngar789
    @q3ngar789 23 дні тому

    Hey buddy I see you’ve done a lot of videos and are quite dedicated and knowledgeable about what you do. I just want to show my sincere appreciation for your hard work.m and cheer you one. Good luck in life.

    • @keytos
      @keytos 19 днів тому

      Thank you for the kind words, I really appreciate it!

  • @spitbacca
    @spitbacca Місяць тому

    A better analogy which can be more easily understood world wide is your passport issuance office. DMV means nothing to me in the UK it would be DVLA instead 😢.

  • @mrwhitebp
    @mrwhitebp Місяць тому

    Where did you get the certificate ? I missed that part

    • @keytos
      @keytos Місяць тому

      We used EZCA, here is a video that guides you through the whole process ua-cam.com/video/LV6gN15QWLI/v-deo.htmlsi=Hdhsh9DicdUlpIz3

  • @annytran2048
    @annytran2048 Місяць тому

    great information

  • @MuhamadParel-hw2il
    @MuhamadParel-hw2il Місяць тому

    Jepang

  • @angiedale3647
    @angiedale3647 2 місяці тому

    awafull music in the background , which is also too loud

  • @nelsontovars
    @nelsontovars 2 місяці тому

    For curiosity, which unifi device did you use for this example?

    • @keytos
      @keytos 6 днів тому

      I don't remember which model we used for the video but it works with any UniFi that supports RADIUS

  • @yourusernameistoolong
    @yourusernameistoolong 2 місяці тому

    How do you prevent token loss? It’s all good until they steal a valid cookie.

    • @keytos
      @keytos 2 місяці тому

      While using phishing resistant credentials dramatically reduce the attack surface, you are correct it is not a silver bullet for that you have to have a defense in layers. Depending on your organization needs it might even mean having dedicated workstations and identities just for production (Microsoft PAW), these are some of the steps we take here at Keytos: www.keytos.io/blog/cloud-security/azure-ad-identity-security-best-practices

  • @RedRyz3n
    @RedRyz3n 2 місяці тому

    Please clarify this for me. You are adding a public IP address to Meraki for the Radius server but not selecting "RadSec," so how is the connection secured? My understanding is that radius auth via the WAN is not an encrypted connection unless you are using a VPN or RadSec.

    • @keytos
      @keytos 2 місяці тому

      EAP-TLS creates a TLS tunnel by default using the server and client certificate. If you are using EAP-TTLS then it is encrypted using the server certificate. We have a video explaining that here: ua-cam.com/video/A-rNeYL9BUI/v-deo.html

  • @AK-xu1fx
    @AK-xu1fx 2 місяці тому

    How about OpenVPN?

    • @keytos
      @keytos 6 днів тому

      Unfortunately OpenVPN uses a RADIUS protocol that is not supported by Entra ID

  • @StijnHommes
    @StijnHommes 3 місяці тому

    You bet I keep using passwords. Using the same way to unlock your device to unlock all your accounts is stupid. It reduces security as a hacker only needs to steal one thing to get into ALL your accounts at once.

  • @AleksandrZhuravlev-tu3to
    @AleksandrZhuravlev-tu3to 3 місяці тому

    BUT USEFUL 🤣🤣🤣🤣

  • @davw07
    @davw07 3 місяці тому

    which way is he looking

  • @owencahill6551
    @owencahill6551 3 місяці тому

    That is an excellent explanation! Just reviewing for a Job Interview.

    • @keytos
      @keytos 3 місяці тому

      Best of luck in the interview :)

    • @owencahill6551
      @owencahill6551 3 місяці тому

      Thank you!

  • @mahmoudragab8529
    @mahmoudragab8529 3 місяці тому

    Simple Explanation

  • @TheGreatestShowman69
    @TheGreatestShowman69 3 місяці тому

    Everyone and no one 🦎

  • @austinmurphy6359
    @austinmurphy6359 3 місяці тому

    Who is this guy looking at?

  • @jonesm501
    @jonesm501 4 місяці тому

    Hi there, Will this work for Entra ID accounts that have MFA?

    • @keytos
      @keytos 4 місяці тому

      Unfortunately not, this is for username and password authentication. For a more secure authentication we recommend using certificates issued by your MDM ua-cam.com/video/LV6gN15QWLI/v-deo.html

  • @LaithCpE
    @LaithCpE 5 місяців тому

    We have tested this feature, it is working fine on windows, android devices, however, it is not working on iPhones, it seems the iPhones doesn't support EAP-TTLS/PAP by default, any workaround for this?

    • @keytos
      @keytos 5 місяців тому

      Hi, yes there is, you must create a profile for the iPhone, www.keytos.io/docs/cloud-radius/setup-radius-in-mdm/in-device/#how-to-configure-eap-ttlspap-on-macos-for-radius-authentication-with-entra-id-passwords

  • @jl6693
    @jl6693 5 місяців тому

    nice graphics but the amount of content does not match the title.

    • @keytos
      @keytos 5 місяців тому

      Thanks for the feedback, we have updated the title to match the content

  • @sariyanzero5817
    @sariyanzero5817 6 місяців тому

    hay i cannot login to keytos with my Gmail am i supposed to have a work email for this to work?

    • @keytos
      @keytos 6 місяців тому

      yes, this is only for Microsoft 365 work accounts

  • @sukhera89
    @sukhera89 6 місяців тому

    wooooowwwwwwwww

  • @Raja-ct9xq
    @Raja-ct9xq 7 місяців тому

    Can we try Ezca demo edition for free ?? Also, Ezca is based on Ejbca or Mspki in the backend ?

    • @keytos
      @keytos 7 місяців тому

      Yes, you can try it for free no credit card required www.keytos.io/docs/azure-pki/getting-started/registering-a-new-tenant/selecting-a-plan/select_plan_in_ezca/ We use our own in house built Certificate Authority as our backend this was built to be cloud native allowing us to scale faster while being more affordable.

  • @Dtr146
    @Dtr146 7 місяців тому

    Good I got here before a lot of people see this. This only affects you if you're on a public Wi-Fi and it is configured to where you can see other users on the network. If you use public Wi-Fi is a lot. Then yes you definitely need this update. If you're just at home on your Wi-Fi. As long as somebody doesn't get access to your internet. You are fine. They need to physically be on your network. They can't just drop a packet from outside the network without authentication. Yes it is a severe vulnerability and it affects all versions of Windows. But it only affects people who are on the same Wi-Fi as the attacker. This needs to be clarified.

    • @Neirto9
      @Neirto9 5 місяців тому

      you saved me from tons of hours of investigation, pretty appreciated. cheers man

    • @aridlintm
      @aridlintm 4 місяці тому

      As i said on the other channel of this guy (for whatever reason he has 2 of them). Attacker needs to be in range of your wifi card. The malicious packet is sent to the device itself. If you are not connect anywhere you are still vulnereable

    • @Dtr146
      @Dtr146 4 місяці тому

      ​@@aridlintm Okay, first off, you have to be using your laptop per se if you're out in public. Not connected to a Wi-Fi. If you put your laptop to sleep, it's not sending or receiving packets anymore. Unless you are connected to a Wi-Fi. The only way that somebody could be in proximity to you without you being connected to a wireless network is if you are using your machine, out in public, willy-nilly without an internet connection, and who does that?

  • @JetSoftProHQ
    @JetSoftProHQ 7 місяців тому

    Thanks for the interesting and exemplary information. At JetSoftPro, a software development service, we see these trends in cybersecurity continuing today. The trend is also constant verification of protection, such as a penetration test or a simulation of a phishing attack

  • @haislrekajsolre7876
    @haislrekajsolre7876 7 місяців тому

    nice info

  • @info781
    @info781 8 місяців тому

    They sound different to me.

    • @keytos
      @keytos 8 місяців тому

      You are correct, they are different, but the underlying technology is the same for both

  • @HikaruAkitsuki
    @HikaruAkitsuki 8 місяців тому

    Is that Cloudflare doing that thing with their lava lamps?

    • @keytos
      @keytos 8 місяців тому

      They do use lava lamps for some of their random generators, but for most encryption they use the regular random generators that are approved by the industry www.cloudflare.com/learning/ssl/lava-lamp-encryption/

  • @marcusbk7317
    @marcusbk7317 8 місяців тому

    From this video, i dont see how OSCP is better than a CRL.

    • @keytos
      @keytos 8 місяців тому

      It is not better, they are both great tools for checking revocation, one offloads the search to the server and the other to the device. Most devices use CRL but for devices or networks that cannot handle large CRLs, OCSP is a great option.

  • @keytos
    @keytos 8 місяців тому

    www.keytos.io/blog/passwordless/what-are-ssh-certificates.html

  • @shongwethulisile2861
    @shongwethulisile2861 8 місяців тому

    Informative. Thank you

    • @keytos
      @keytos 8 місяців тому

      Glad it was helpful!

  • @leac3
    @leac3 9 місяців тому

    I could not listen to you. Please, volume down.

    • @keytos
      @keytos 9 місяців тому

      thanks for the feedback we will make sure to change it in our next videos

  • @pcread
    @pcread 9 місяців тому

    music is too loud

    • @keytos
      @keytos 9 місяців тому

      thanks for the feedback we will make sure to change it in our next videos

  • @ishwaryanarayan1010
    @ishwaryanarayan1010 10 місяців тому

    Do you have any job opportunities for cyber security professional?

    • @keytos
      @keytos 8 місяців тому

      you can always check our www.keytos.io/careers page for the latest job postings

  • @adamcodes716
    @adamcodes716 11 місяців тому

    I can't create a subscription without entering a credit card number. Is this really free, or is it only free for a month?

    • @keytos
      @keytos 11 місяців тому

      you should be able to create a test subscription by clicking skip for now. It is only free for a month, after the first month it is $200 per CA per month and can be charged either to your credit card or to your Azure account.

  • @lindacohen9169
    @lindacohen9169 Рік тому

    Great explanation! The spokesman makes the issue clear and interesting.

  • @komidawi
    @komidawi Рік тому

    I have to admit it was a very concise video - both short and helpful :)

  • @sheikhfaizal2851
    @sheikhfaizal2851 Рік тому

    Thanks for sharing, but your face blocks the content. Can't see some stuff :(((

    • @keytos
      @keytos Рік тому

      Sorry about that, here is the presentation with all the information marketing.keytos.io/hubfs/Presentations/Cybersecurity%20Trends%20for%202024.pdf

  • @LivingInCloud1
    @LivingInCloud1 Рік тому

    Very interesting!

  • @bubbanc
    @bubbanc Рік тому

    I notice there is no password or other authorization information other than the SCEP URL being unique and difficult to guess. If someone has your SCEP URL could they enroll into your service without having any passphrase and obtain a certificate for your infrastructure? If the SCEP URL is the only thing authorizing enrollment creation, then it might be good to note that in the UI (please keep this URL private). I also assume that that URL is not embedded into the certs issued?

    • @keytos
      @keytos Рік тому

      Hi thanks for your comment - while the experience seems simple, what happens in the backend is more complex; we talk about it at 4:30, but the gist is that each request has an encrypted password that is set by the MDM and EZCA (Intune sets their own, some MDM solutions only support a static password that is encrypted with the CA public key meaning that the CA is the only one that can access it, and some support dynamic challenge requests meaning that each specific request has it's own password set by the CA (this one is also encrypted), if you are interested, we have a full deep dive on how SCEP works in this video ua-cam.com/video/da6LrQJcSgs/v-deo.html please let us know if you have other questions

  • @zomgoose
    @zomgoose Рік тому

    Awesome! Thanks!

  • @mr-teal
    @mr-teal Рік тому

    Great video! i am studying for my enterprise network administration exam for university and this was great for providing clarity on the difference between private and public CA's

    • @keytos
      @keytos Рік тому

      Glad we could help:)

  • @NikTown-m1s
    @NikTown-m1s Рік тому

    Is it possible to place pages on a captured subdomain?

    • @keytos
      @keytos Рік тому

      yes, anyone with an Azure account can create those resources and create pages. This is why we recommend all organizations to verify that they do not have any dangling DNS that can be exploited.

  • @igalfs
    @igalfs Рік тому

    TIL

  • @thefauxpod3668
    @thefauxpod3668 Рік тому

    That loop was CLEAN

  • @thefauxpod3668
    @thefauxpod3668 Рік тому

    Sir Tificate rules!!

  • @stefandekooter
    @stefandekooter Рік тому

    Hi, does Keytos have a OCSP endpoint in their offerings? Specifically in EZCA?

    • @keytos
      @keytos Рік тому

      Hi Currently, EZCA only supports CRL. OCSP support is coming by end of Q3 2023

    • @keytos
      @keytos Рік тому

      We are happy to announce that now you can setup your EZCA ca with OCSP docs.keytos.io/azure-pki/creating-your-first-ca/first_subordinate_ca/#ocsp-online-certificate-status-protocol-settings