For most of 2019, I was digging into Office 365 and Azure AD and looking at features as part of the development of the new Trimarc Microsoft Cloud Security Assessment which focuses on improving customer Microsoft Office 365 and Azure AD security posture. As I went through each of them, I found one that was …
Tag: PIM
May 27 2020
From Azure AD to Active Directory (via Azure) – An Unanticipated Attack Path
- Access management for Azure resources, ActiveDirectory, Azure AD PIM, Azure Owner, Azure RBAC, Azure root, AzureAD, Company Administrator, Compromise Azure Domain Controller, Compromise Azure VM, Elevate Access, EnableAdminAccount, From Azure AD to Azure, Global Admin to Azure, Global Administrator, Global Administrator Elevate Access, MFA, Microsoft.Compute/virtualMachines/runCommand/, net localgroup, Office 365 Security, PIM, Privileged Identity Manager, Run PowerShell on Azure VM, runCommand, RunPowerShellScript, User Access Administrator, Virtual Machine Contributor
- 5 comments
Jan 12 2020
What is Azure Active Directory?
Many are familiar with Active Directory, the on-premises directory and authentication system that is available with Windows Server, but exactly what is Azure Active Directory? Azure Active Directory (Azure AD or AAD) is a multi-tenant cloud directory and authentication service. Azure AD is the directory service that Office 365 (and Azure) leverages for account, groups, …
- AAD, AccountTokenTheft, ActiveDirectory, ActiveSync, AD, ADAL, ADALPowerShell, AttackingMicrosoftCloud, AttackingOffice365, Azure AD Account Enumeration, AzureActiveDirectory, AzureAD, AzureADPasswordSpray, AzureADPowerShellModule, AzurePIM, CloudAD, ExchangeOnlineModule, GlobalAdmin, GlobalReader, MicrosoftCloud, MicrosoftCloudSecurity, MSOnline, O365, O365Creeper, O365PasswordSpray, Office365, Office365PasswordSpray, Office365security, OWA, PasswordSprayDetection, PasswordSpraying, PIM, PrivilegedIdentityManagement, WhatIsAzureActiveDirectory, WhatIsAzureAD
Recent Posts
- Attacking Active Directory Group Managed Service Accounts (GMSAs)
- From Azure AD to Active Directory (via Azure) – An Unanticipated Attack Path
- What is Azure Active Directory?
- Slides Posted for Black Hat USA 2019 Talk: Attacking & Defending the Microsoft Cloud
- AD Reading: Windows Server 2019 Active Directory Features
Trimarc Active Directory Security Services
Have concerns about your Active Directory environment?
Trimarc helps enterprises improve their security posture.
Find out how... TrimarcSecurity.com
Popular Posts
- Attack Methods for Gaining Domain Admin Rights in…
- PowerShell Encoding & Decoding (Base64)
- Kerberos & KRBTGT: Active Directory’s…
- Finding Passwords in SYSVOL & Exploiting Group…
- Securing Domain Controllers to Improve Active…
- Securing Windows Workstations: Developing a Secure Baseline
- Mimikatz DCSync Usage, Exploitation, and Detection
- Detecting Kerberoasting Activity
- Scanning for Active Directory Privileges &…
- The Most Common Active Directory Security Issues and…
Categories
- ActiveDirectorySecurity
- Apple Security
- Cloud Security
- Continuing Education
- Entertainment
- Exploit
- Hacking
- Hardware Security
- Hypervisor Security
- Linux/Unix Security
- Malware
- Microsoft Security
- Mitigation
- Network/System Security
- PowerShell
- RealWorld
- Security
- Security Conference Presentation/Video
- Security Recommendation
- Technical Article
- Technical Reading
- Technical Reference
- TheCloud
- Vulnerability
Tags
ActiveDirectory
Active Directory
ActiveDirectoryAttack
ActiveDirectorySecurity
Active Directory Security
ADReading
ADSecurity
AD Security
DCSync
DEFCON
DomainController
EMET5
GoldenTicket
HyperV
Invoke-Mimikatz
KB3011780
KDC
Kerberos
KerberosHacking
KRBTGT
LAPS
LSASS
MCM
MicrosoftEMET
MicrosoftWindows
mimikatz
MS14068
PassTheHash
PowerShell
PowerShellCode
PowerShellHacking
PowerShellv5
PowerSploit
Presentation
Security
SIDHistory
SilverTicket
SneakyADPersistence
SPN
TGS
TGT
Windows10
WindowsServer2008R2
WindowsServer2012
WindowsServer2012R2