Most domains are no longer islands: Entra Connect (formerly Azure AD Connect) synchronises on-premises AD into an Entra ID (Azure AD) tenant, and that bridge is a two-way attack path. The Connect server is a Tier-0 asset that is routinely protected like an ordinary member server, yet it holds the keys to both directories. Owning it, or the accounts it creates, pivots from on-premises Domain Admin to cloud Global Administrator and back.
The sync account holds DCSync#
Entra Connect creates an on-premises connector account (named MSOL_ or AAD_). When password hash synchronization is enabled, it holds Replicate Directory Changes and Replicate Directory Changes All on the domain, which is DCSync. From local admin on the Connect server, recover that account's cleartext credentials from the sync configuration, then DCSync the whole domain (including krbtgt):
# AADInternals: extract the sync credentials from the Connect server
Get-AADIntSyncCredentials
# -> on-prem connector (MSOL_) account + cloud sync account creds; use the MSOL_ cred for DCSync
A basic-synchronization, pass-through-authentication, or federated install without hash sync may not grant the connector Replicate Directory Changes All, so confirm the account's rights before relying on the DCSync path.
Seamless SSO: the AZUREADSSOACC$ account#
If Seamless SSO is enabled, a computer account AZUREADSSOACC$ exists in on-premises AD. Its key signs Kerberos tickets for the cloud SSO service, so its NT hash (via DCSync) lets you forge a silver ticket impersonating any synced user to the cloud:
# With the AZUREADSSOACC$ hash, forge a ticket for the Azure AD SSO SPN and ride it into the tenant
# (AADInternals Open-AADIntOffice365Portal / ticket forging against the aadg.windows.net.nsatc.net SPN)
Primary refresh tokens#
On a joined endpoint, the primary refresh token (PRT) is the device's cloud SSO credential. Stealing it (with the matching session key) gives cloud access as that user without their password or MFA, a direct on-prem-to-cloud pivot from a workstation.
Exploitation notes#
- The Connect server is effectively both a domain controller and a tenant admin in reach, so compromising it is the shortest hybrid takeover; treat it as Tier-0 when scoping.
- The
MSOL_DCSync path means the Connect server is an alternative route to the whole domain even when the DCs themselves are hard to reach. - In pass-through authentication tenants, the PTA agent on the Connect server can be backdoored to intercept or validate any cloud logon, a durable authentication backdoor.
AADInternalsis the established toolkit once you hold local admin on the sync server.
Tools#
- AADInternals (Nestori Syynimaa): sync-credential extraction, token forging, PTA and SSO abuse.
- Impacket / mimikatz: DCSync with the recovered
MSOL_orAZUREADSSOACC$material.