logo

Entra Connect Attacker Tradecraft: Part 3

ID: 0ad4aad9-e87a-5ca1-93cf-3a9f010b7bb0

STIX ID: report--0ad4aad9-e87a-5ca1-93cf-3a9f010b7bb0

Feed Name: SpecterOps Blog

Threat Score
75/100

Date Published: 2025-07-30

Date Updated: 2026-04-30

Author: Daniel Heinsen

...
...

This writeup demonstrates how an attacker who compromises an Entra Connect sync account (or otherwise can modify device userCertificate attributes) can inject certificates into any device object in a tenant, complete device registration, and obtain device authentication material. Using these forged device identities an attacker can bypass conditional access policies, impersonate devices to acquire Intune MDM and PKCS certificates, and potentially use those certificates to authenticate to on‑premises resources and compromise separate domains within the same tenant.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.