logo

Azure AD Kerberos Tickets: Pivoting to the Cloud

ID: e74079f1-e4d5-56a0-8d4b-b47a3551969f

STIX ID: report--e74079f1-e4d5-56a0-8d4b-b47a3551969f

Feed Name: TrustedSec blog

Threat Score
80/100

Date Published: 2025-03-19

Date Updated: 2026-05-01

...
...

This report demonstrates a practical attack path in hybrid Azure AD environments where an attacker who extracts the AZUREADSSOACC$ machine account NTLM hash and on-prem SIDs can use AADInternals and ROADtools to request Kerberos tickets, obtain Azure AD tokens, impersonate service accounts (including AD Sync), elevate to global administrator, create users, and gain subscription-owner access—achieving full cloud compromise and persistence even if on-premises passwords are changed; the report recommends rotating the AZUREADSSOACC$ key and enforcing conditional access for service accounts.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.