Lateral Movement from Azure to On-Prem AD
ID: 2cdd7a18-7c4f-5556-bc96-1285195577c6
STIX ID: report--2cdd7a18-7c4f-5556-bc96-1285195577c6
Feed Name: SpecterOps Blog
This report explains how attackers or compromised administrators with Global Admin or Intune Administrator roles can leverage Microsoft Endpoint Manager to deploy PowerShell scripts that run as SYSTEM on hybrid Azure AD-joined devices, enabling lateral movement from Azure to on-prem AD, even across untrusted domains. It shows how to enumerate target devices, configure and assign scripts via Endpoint Manager, and highlights detection artifacts (Intune logs and registry hashes) alongside prevention guidance such as auditing privileged role assignments and identifying Intune-managed endpoints.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
