Azure Seamless SSO: When Cookie Theft Doesn’t Cut It
ID: ff52d6fd-cb7c-59d0-86ed-d21fb2b4f870
STIX ID: report--ff52d6fd-cb7c-59d0-86ed-d21fb2b4f870
Feed Name: SpecterOps Blog
The report demonstrates a cloud privilege escalation path from an AD-synced user to Entra ID Global Administrator by combining BloodHound graph analysis, Azure Seamless SSO (via browser-based device code auth), PIM eligibility activation, and Azure Automation runbooks to add secrets to a service principal, then creating an application with Microsoft Graph roles to assign Global Administrator. It illustrates how legitimate identity flows and misconfigurations across on-prem AD and Azure resources enable lateral movement and full tenant compromise, emphasizing the importance of mapping relationships and authentication paths.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
