Case C042AF · Identity & AD · L5 Expert
Entra Connect Server Compromised
Practise as: Incident drill · Deep dive
Live alertEDR flags AADInternals running as local admin on the Entra Connect sync server. Password hash sync and Seamless SSO are both enabled.
- 01 What happened?
- 02 What is the impact?
- 03 What do you do?
What a strong answer covers
Try it out loud first. Then check yourself:
- Treat as Tier 0 breach: with PHS the AD connector account (MSOL_) holds replication rights, so DCSync is possible
- Local admin can extract the stored AD connector and Entra sync account credentials; assume both are compromised
- Seamless SSO: the AZUREADSSOACC$ key lets an attacker forge Kerberos tickets to Entra for synced users; roll it
- Hunt: replication by MSOL_ from hosts other than the sync server, new cloud admins, auth method and federation changes
- Contain: isolate the server, rotate connector credentials, roll the SSO key; if DCSync occurred, reset krbtgt twice
If the interviewer pushes back
- If pass-through authentication were enabled instead, how could an attacker on the agent host abuse it?
Go deeper
cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.