Cross-tenant access settings decide how one tenant trusts identities and claims from another. When a tenant inbound-trusts another tenant's MFA or compliant-device claims, compromising the trusted tenant lets you satisfy the target's conditional access with claims minted in the tenant you control. Cross-tenant synchronization can even provision accounts from one tenant into another.
Abuse the trust#
# read the target's cross-tenant access policy (as an authenticated principal)
az rest --method GET --url "https://graph.microsoft.com/v1.0/policies/crossTenantAccessPolicy/partners"
# if inbound trust accepts the home tenant's MFA/compliant-device claims, a token from the
# controlled tenant satisfies the target's device/MFA conditional access
Exploitation notes#
- Inbound trust of MFA means you do not re-MFA from the trusted tenant: own that tenant and its claims pass into the target.
- Cross-tenant synchronization provisions users from a source tenant into the target, a path to a standing account if you control the source.
- B2B direct connect shares resources (for example Teams shared channels) across the trust, widening reachable data.
Tools#
- az cli / Graph (
crossTenantAccessPolicy). - ROADtools: cross-tenant policy enumeration.