ProBackend
cloud security incidents
54 minutes ago5 min read

Breach at the Beach: Hands-On Entra ID CTF for Security & Compliance Analysts

Varonis Threat Labs created Breach at the Beach, a free CTF that teaches cybersecurity professionals how threats exploit legitimate Entra ID features for data exfiltration. Players earn CPE credits while learning to detect non-human identity attacks without AI assistance—essential skills for security and compliance analysts in the AI era.

By Morgan Sterling | Cloud Security Incidents


The Ocean of Identity Threats

Cybersecurity can feel like standing on a beach on a perfect summer day—calm waters, clear skies, pristine waves. But anyone who's waded in knows there's something unknown lurking beneath the surface. That's exactly how Varonis Threat Labs researchers Doron Kapah and Mark Vaitsman view modern identity security today.

This reality inspired them to create Breach at the Beach—an immersive capture-the-flag (CTF) training experience designed to teach defenders what real Entra ID breaches look like on the frontlines, specifically through the lens of a security & compliance analyst.

Why Entra ID Matters in the AI Era

Entra ID isn't just another identity provider. It's the control plane for entire enterprises—connecting users, applications, permissions, automation, and increasingly, AI-powered workflows. The rise of non-human identities, AI agents, service principals, automated processes, has fundamentally changed what a compromise looks like.

"In today's AI era, a lot of identities are non-human identities," explains Mark Vaitsman, Security Research Team Leader at Varonis. "If there is a compromise in Entra, a threat actor can pivot themselves into a non-human identity, and it can quickly turn into a stealthy and scalable data exfiltration attempt."

The techniques embedded throughout Breach at the Beach aren't theoretical. They reflect real cases Kapah and Vaitsman have encountered firsthand in customer environments, making each challenge a practical lesson grounded in current threats facing security & compliance analysts today.

The CTF Experience: Learning by Doing

Breach at the Beach puts players in the shoes of security defenders investigating an Entra ID breach. Pixel, Varonis' famous threat-detecting cat mascot, is on beach vacation when she discovers an Entra ID breach and switches to investigator mode. Players trace the threat actor's steps through Pixel's investigation, uncovering what sensitive data the attacker targets and hopefully stopping them before it's too late.

The experience teaches several critical lessons:

  • How threats abuse legitimate features, not misconfigurations, Players learn to recognize when normal functionality gets weaponized rather than hunting for broken controls
  • How to detect threats without AI assistance, The CTF deliberately avoids LLMs that could solve challenges, forcing players to absorb the actual lessons embedded in the experience
  • How to eliminate noise from complex logs, Working through evolving Entra ID log environments tests players' ability to create clarity from chaos

"We got feedback that the challenge was tough, but also very educational," says Kapah. "Even seasoned CTF staff at the booth told us they learned something new."

Who Should Play and How to Earn Credits

Breach at the Beach is free and available online at https://breachatthebeach.com. It's designed for all cybersecurity professionals, including red teamers, blue teamers, CISOs, threat intelligence practitioners, and especially security & compliance analysts seeking hands-on experience.

Completing each of the four CTF stages earns:

  • 1 CPE credit (continuing professional education)
  • A themed badge

Finish all four stages to receive a certificate of completion shareable on LinkedIn. (To earn CPE credits, use an active email address during registration.)

Upcoming Events: Black Hat USA 2026 and DEF CON 34

Varonis Threat Labs researchers are bringing Breach at the Beach to major security conferences:

Black Hat USA 2026
August 3-6, 2026 | Las Vegas Convention Center
Booth #2948 (Varonis)
Online players and Black Hat attendees who complete the CTF by August 6 will be entered into a drawing for a $2,000 USD Marriott Hotels gift card.

DEF CON 34 Cloud Village
August 6-9, 2026 | Las Vegas Convention Center
Attendees can compete in the Cloud Village's Capture the Flag challenges with top players eligible for various prizes. Registration opens prior to the event.

The Bigger Picture: Identity Hygiene and Least Privilege

Beyond specific technical lessons, Breach at the Beach helps players understand what good identity hygiene looks like and how to implement least privilege in their own environments, a critical skill as organizations balance AI adoption with security infrastructure that hasn't kept pace.

"There is no way you can be a good red teamer if you're not familiar with the blue team side," Vaitsman notes. "And you probably will not be able to be a good CISO if you're not familiar with the attacker side."

The Research Behind the CTF

Doron Kapah and Mark Vaitsman spent months developing Breach at the Beach, drawing from their extensive experience investigating data exfiltration attacks in cloud-native environments. The CTF was first tested at RSAC 2026's Cloud Village, where feedback highlighted how it didn't feel like a task but rather a creative challenge that kept players entertained and inspired.

"The elimination of AI assistance helps players absorb the lessons embedded in the experience rather than quickly learning them to compete," explains Kapah. This design choice ensures that security & compliance analysts leaving the CTF will have genuinely internalized key defensive strategies.

Key Takeaways for Security Professionals

For any professional working with Microsoft 365, Entra ID, or cloud security infrastructure, Breach at the Beach offers several insights:

  1. Understand attack flows: Reading about attacks is not enough, you need to experience them firsthand
  2. Recognize weaponized legitimate features: Many breaches don't exploit vulnerabilities but rather misuse of normal functionality
  3. Develop noise-filtering skills: Modern log environments are complex; the ability to find signals in chaos is crucial
  4. Practice identity hygiene: Least privilege implementation starts with understanding how compromises happen

As organizations accelerate AI adoption, the attack surface expands dramatically. Breach at the Beach helps defenders prepare for this new reality by providing practical, hands-on experience with the very threats they need to defend against.


This article was sponsored by Varonis. The original research and insights come from Varonis Threat Labs researchers Doron Kapah and Mark Vaitsman.

the ocean of identity threats

More blogs