CTD-000073

Password hash synchronization not enabled in hybrid environment

Medium
Active Directory Entra ID Hybrid
Credential Access Impact
v30

Signature Identity

CTD-000073
Threat ID
30
Version
IOE
Indicator Type

Threat Description

  • Without password hash synchronization (PHS) enabled, threat actors might find leaked credentials and use them to access your environment. With PHS enabled, Microsoft Entra ID can detect if your user’s credentials are leaked.
  • PHS should also be enabled as your backup authentication method. With PSH enabled, users will be able to log in to Microsoft 365 even if your on-premises Active Directory is not available.
  • MITRE ATT&CK: Attack Tactics

    Credential Access Impact

    D3FEND: Defend Tactics

    Application Configuration Hardening Domain Account Monitoring

    Remediation

    To enable Password Hash Sync feature:

    1. Log in to the server with Microsoft Entra Connect.
    2. Open Microsoft Entra Connect.
    3. Click Configure.
    4. On the Additional tasks page, select Customize synchronization options.
    5. Click Next.
    6. Enter credentials for your global administrator.
    7. On the Connect your directories screen, click Next.
    8. On the Domain and OU filtering screen, click Next.
    9. On the Optional features screen, check Password hash synchronization.
    10. Click Next.
    11. On the Ready to configure screen click Configure.
    12. Once the configuration completes, click Exit.

    Frequently Asked Questions

    What does Password hash synchronization not enabled in hybrid environment mean?

    In a hybrid environment, password hash synchronization (PHS) is a feature that allows Microsoft Entra ID to detect and use leaked password hashes for authentication. When PHS is not enabled, user credentials are vulnerable to exploitation.

    Although PHS is not enabled, the presence of leaked credentials does not grant administrative control, but increases the risk of credential abuse and account takeover. Attackers can attempt unauthorized access using compromised user credentials.

    Attackers can use leaked password hashes to attempt authentication through brute-force attacks or by using stolen credentials for lateral movement and privilege escalation, ultimately gaining access to the environment.

    Cayosoft Guardian detects password hash synchronization not enabled in a hybrid environment by continuously monitoring Microsoft Entra ID and Active Directory configuration settings. When PHS is found to be disabled, Guardian flags it as a security issue so administrators are aware of the exposure.

    Cayosoft Guardian helps reduce the risk of password hash synchronization not enabled in a hybrid environment by alerting administrators to enable PHS, allowing Microsoft Entra ID to detect and use leaked password hashes for authentication, reducing the vulnerability to attackers attempting unauthorized access.

    Stop AD Threats As They Happen

    Cayosoft Protector provides continuous monitoring and real-time alerts across your entire Microsoft Identity stack

    Classification
    Systems
    Active Directory Entra ID Hybrid
    Themes
    Forest-wide
    Attack Tactics
    Credential Access Impact
    Defend Tactics
    Application Configuration Hardening Domain Account Monitoring
    Indicator Types
    IOE
    Related Threats
    CTD-000139
    Kerberos Constrained Delegation: krbtgt Risks
    Critical
    CTD-000122
    Active Directory Schema Update Permission Risks
    Critical