logo

Emerging Attacker Exploit: Microsoft Cross-Tenant Synchronization by Arpan Sarkar

ID: 9a7d41d1-d8d0-51d1-9a01-4c80df57b46b

STIX ID: report--9a7d41d1-d8d0-51d1-9a01-4c80df57b46b

Feed Name: Vectra AI Blog

Threat Score
70/100

Date Published: 2023-08-01

Date Updated: 2026-05-01

...
...

Vectra Research describes a new attack vector abusing Microsoft Cross-Tenant Synchronization (CTS) that allows an attacker with a compromised privileged account to synchronize a user from a compromised tenant into a target tenant (lateral movement) or deploy a rogue CTS configuration to maintain persistent access (backdoor). The report outlines assumptions, detailed attack steps for lateral movement and persistence, prerequisites (privileged roles and certain licenses), detection coverage by Vectra’s AI-driven detections, and recommends testing and monitoring using the MAAD Attack Framework to emulate and defend against these techniques.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.