CTD-000035

Privileged Microsoft Entra account synced from on-premise

High
Active Directory Entra ID Hybrid
Privilege Escalation
v162

Signature Identity

CTD-000035
Threat ID
162
Version
IOE
Indicator Type

Threat Description

A synced user account that is an active or eligible member of the Microsoft Entra administrative roles poses a threat to your Microsoft Entra tenant. If your on-premises account is compromised, a threat actor can get access to your Microsoft Entra resources as well.

MITRE ATT&CK: Attack Tactics

Privilege Escalation

D3FEND: Defend Tactics

Domain Account Monitoring

Remediation

  1. Remove synced users from all Microsoft Entra roles with administrative permissions.
    Follow the instructions to deassign Microsoft Entra roles using the Microsoft Entra admin center.
  2. Avoid using on-premises synced accounts for Microsoft Entra role assignments.

Frequently Asked Questions

What does Privileged Microsoft Entra account synced from on-premise mean?

A user account that is an active or eligible member of the Microsoft Entra administrative roles, having been synced from your on-premises Active Directory. This means that if your on-premises account is compromised, a threat actor can gain access to your Microsoft Entra resources with elevated permissions due to their direct membership in administrative roles.

This condition enables attackers to access Microsoft Entra resources with elevated permissions, allowing them to perform administrative actions and potentially escalate privileges. The attacker gains direct membership in administrative roles, which matters because it bypasses normal permission checks.

The attacker uses the compromised account's direct membership in administrative roles to access sensitive resources within your Microsoft Entra tenant and perform actions that would normally require elevated permissions. This supports later attacker activity, such as lateral movement or privilege escalation.

Cayosoft Guardian detects Privileged Microsoft Entra account synced from on-premise by continuously monitoring the membership of your on-premises Active Directory accounts in Microsoft Entra administrative roles, flagging any suspicious or unauthorized access to these roles.

Cayosoft Guardian helps reduce the risk by alerting administrators to remove synced users from all Microsoft Entra roles with elevated permissions, and providing ongoing monitoring to detect any re-assignment or re-sync attempts that could compromise security. This provides visibility into potential threats and supports investigation and response efforts.

Stop AD Threats As They Happen

Cayosoft Protector provides continuous monitoring and real-time alerts across your entire Microsoft Identity stack

Classification
Systems
Active Directory Entra ID Hybrid
Themes
Account protection
Attack Tactics
Privilege Escalation
Defend Tactics
Domain Account Monitoring
Indicator Types
IOE
Related Threats
CTD-000139
Kerberos Constrained Delegation: krbtgt Risks
Critical
CTD-000122
Active Directory Schema Update Permission Risks
Critical