CTD-000034

Privileged AD user synced to Microsoft Entra ID

High
Active Directory Entra ID Hybrid
Privilege Escalation
v29

Signature Identity

CTD-000034
Threat ID
29
Version
IOE
Indicator Type

Threat Description

It is best practice from Microsoft to avoid syncing accounts to Microsoft Entra ID that have high privileges in your existing Active Directory instance. A threat actor might compromise a regular user account in the tenant to get access to its privileged counterpart in the Active Directory.

NOTE: Cayosoft Guardian defines privileged users in Active Directory as users with adminCount=1. By design Active Directory uses this attribute to protect members of administrative groups.

According to security best practices it is not recommended re-using admin accounts, instead these accounts must be de-provisioned. If an account has administrative permissions, it might also obtain access to other resources using these administrative permissions and keep this access even after it is removed from the administrative groups. Learn more about AdminSdHolder and SDProp – Microsoft Community Hub.

MITRE ATT&CK: Attack Tactics

Privilege Escalation

D3FEND: Defend Tactics

Domain Account Monitoring User Account Permissions

Remediation

To remediate the issue, a synchronization must be disabled for the account in the Microsoft Entra connect configuration and then a user account in the tenant must be deleted.

  1. To exclude specific privileged account from synchronization, follow the Microsoft’s article about filtering configuration.

Frequently Asked Questions

What does Privileged AD user synced to Microsoft Entra ID mean?

This refers to the synchronization of high-privilege accounts from Active Directory to Microsoft Entra ID, allowing attackers to gain elevated permissions and access sensitive resources.

It enables an attacker to gain elevated permissions, allowing them to perform actions that would normally be restricted to privileged users. This can lead to unauthorized access, data breaches, and privilege escalation.

An attacker can exploit this by using a compromised regular user account in the tenant to gain access to its corresponding high-privilege account in Active Directory, thereby elevating their privileges and accessing sensitive resources.

Cayosoft Guardian continuously monitors the synchronization of high-privilege accounts between Active Directory and Microsoft Entra ID, detecting potential security issues related to unauthorized access and privilege elevation.

Cayosoft Guardian alerts administrators to potential security issues, enabling them to disable synchronization for high-privilege accounts and prevent unauthorized access to sensitive resources.

Stop AD Threats As They Happen

Cayosoft Protector provides continuous monitoring and real-time alerts across your entire Microsoft Identity stack

Classification
Systems
Active Directory Entra ID Hybrid
Themes
Account protection Privileged Access Management
Attack Tactics
Privilege Escalation
Defend Tactics
Domain Account Monitoring User Account Permissions
Indicator Types
IOE
Related Threats
CTD-000139
Kerberos Constrained Delegation: krbtgt Risks
Critical
CTD-000122
Active Directory Schema Update Permission Risks
Critical