H3-2024-0029
Active Directory User has Entra Administrator Role
Category | CREDENTIALS |
Base Score | 8.0 |
Description
An on-premises Active Directory user has an Admin role in a synchronized Microsoft Entra ID tenant.
Impact
Attackers who are able to compromise the domain user's credential can log into the Entra ID tenant with elevated privileges. Attacker's may also forge valid credentials after compromising the on-premises domain using a Kerberos Silver Ticket Attack if Azure Seamless SSO is enabled. Compromise of an Entra ID Global Administrator gives an attacker full access to any associated cloud resources.