Microsoft Entra ID Connect Attacks

Entra ID Connect (formerly Azure AD Connect) synchronizes on-premises AD to Azure AD/Entra ID. The sync server holds credentials for both environments — compromise it and you can extract the MSOL service account hash for DCSync, dump the Azure AD Global Admin password hash stored locally, or abuse the sync account's cloud privileges. This covers PHS, PTA, Seamless SSO, and the full attack chain.

Related Articles