Skip to content

H3-2024-0029

Active Directory User has Entra Administrator Role

Category CREDENTIALS
Base Score 8.0

Description

An on-premises Active Directory user has an Admin role in a synchronized Microsoft Entra ID tenant.

Impact

Attackers who are able to compromise the domain user's credential can log into the Entra ID tenant with elevated privileges. Attacker's may also forge valid credentials after compromising the on-premises domain using a Kerberos Silver Ticket Attack if Azure Seamless SSO is enabled. Compromise of an Entra ID Global Administrator gives an attacker full access to any associated cloud resources.

References