Open cardosec

Case C042AF · Identity & AD · L5 Expert

Entra Connect Server Compromised

Practise as: Incident drill · Deep dive

Live alertEDR flags AADInternals running as local admin on the Entra Connect sync server. Password hash sync and Seamless SSO are both enabled.

  1. 01 What happened?
  2. 02 What is the impact?
  3. 03 What do you do?
What a strong answer covers

Try it out loud first. Then check yourself:

  1. Treat as Tier 0 breach: with PHS the AD connector account (MSOL_) holds replication rights, so DCSync is possible
  2. Local admin can extract the stored AD connector and Entra sync account credentials; assume both are compromised
  3. Seamless SSO: the AZUREADSSOACC$ key lets an attacker forge Kerberos tickets to Entra for synced users; roll it
  4. Hunt: replication by MSOL_ from hosts other than the sync server, new cloud admins, auth method and federation changes
  5. Contain: isolate the server, rotate connector credentials, roll the SSO key; if DCSync occurred, reset krbtgt twice

If the interviewer pushes back

  • If pass-through authentication were enabled instead, how could an attacker on the agent host abuse it?

Go deeper

cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.