Red Teaming Microsoft: Part 1 – Active Directory Leaks via Azure
ID: 3f3fa1aa-96d5-5eb0-9e65-4824a34ab907
STIX ID: report--3f3fa1aa-96d5-5eb0-9e65-4824a34ab907
Feed Name: Black Hills Infosec Blog
This technical write-up explains how an attacker or red team can leverage existing authenticated web sessions, the Azure Portal, and Azure CLI to enumerate Azure AD objects (users, groups, devices, applications/service principals), export directory data, and create guest accounts that — depending on sync configuration — can provide backdoor access to on-prem resources; it highlights gaps in default configurations and defensive mitigations such as restricting Azure AD portal access and using Conditional Access.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
