Az- Synchronising New Users
Syncing AzureAD users to on-prem to escalate from on-prem to AzureAD
I order to synchronize a new user from AzureAD to the on-prem AD these are the requirements:
The AzureAD user needs to have a proxy address (a mailbox)
License is not required
Should not be already synced
When a user like these is found in AzureAD, in order to access it from the on-prem AD you just need to create a new account with the proxyAddress the SMTP email.
An automatically, this user will be synced from AzureAD to the on-prem AD user.
Notice that to perform this attack you don't need Domain Admin, you just need permissions to create new users.
Also, this won't bypass MFA.
Moreover, this was reported an account sync is no longer possible for admin accounts.
References
Last updated