logo

Red Teaming Microsoft: Part 1 – Active Directory Leaks via Azure

ID: 3f3fa1aa-96d5-5eb0-9e65-4824a34ab907

STIX ID: report--3f3fa1aa-96d5-5eb0-9e65-4824a34ab907

Feed Name: Black Hills Infosec Blog

Threat Score
70/100

Date Published: 2018-08-31

Date Updated: 2026-04-27

Author: BHIS

...
...

This technical write-up explains how an attacker or red team can leverage existing authenticated web sessions, the Azure Portal, and Azure CLI to enumerate Azure AD objects (users, groups, devices, applications/service principals), export directory data, and create guest accounts that — depending on sync configuration — can provide backdoor access to on-prem resources; it highlights gaps in default configurations and defensive mitigations such as restricting Azure AD portal access and using Conditional Access.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.