Ever wonder how one of the top participants in the Microsoft bug bounty program was finding security issues across Azure for many years? Or what about the other side? Ever wonder what the perspective was like from a MSRC security engineer working on these submissions and finding a more holistic approach towards them? In this talk, Cameron Vincent and Sean Hinchee from Microsoft bring you the best of both worlds, with a focus on AuthZ/Authorization related issues, which is an area where many services and companies have been failing. Not only will you hear about the offensive side from a former full time bug bounty hunter, you’ll also get to hear from a MSRC engineer that was dealing with these submissions firsthand. Cameron Vincent discusses how he hunted across Microsoft and other services for AuthZ/Authorization issues, along with some example and techniques. Sean Hinchee talks about what the defensive side was like, diving deep into some open-source tools that he developed to help try and catch these types of authorization issues at a more automated scale.