• Tech News
  • Fintech
  • Startup
  • Games
  • Ar & Vr
  • Reviews
  • How To
  • More
    • Mobile Tech
    • Pc & Laptop
    • Security
What's Hot

Xiaomi Robot Vacuum 5 Pro review: A robot vacuum you can trust to do its job

February 5, 2026

10 Hidden iPhone Features You’re Missing in iOS 26

February 4, 2026

Apple Watch Ultra 3 review: Incremental, but still superb

February 4, 2026
Facebook Twitter Instagram
  • Contact
  • Privacy Policy
  • Terms & Conditions
Facebook Twitter Instagram Pinterest VKontakte
Behind The ScreenBehind The Screen
  • Tech News
  • Fintech
  • Startup
  • Games
  • Ar & Vr
  • Reviews
  • How To
  • More
    • Mobile Tech
    • Pc & Laptop
    • Security
Behind The ScreenBehind The Screen
Home»Tech News»Users warned over Azure Active Directory authentication flaw
Tech News

Users warned over Azure Active Directory authentication flaw

September 14, 2022No Comments4 Mins Read
Facebook Twitter Pinterest LinkedIn Tumblr Email
Users warned over Azure Active Directory authentication flaw
Share
Facebook Twitter LinkedIn Pinterest Email

Researchers at Secureworks’ Counter Risk Unit (CTU) have warned of a brand new and probably critical vulnerability affecting the pass-through authentication (PTA) hybrid identification authentication methodology utilized in Azure Energetic Listing (AD).

PTA is one in every of three authentication choices used for hybrid identities in Azure AD, the others being password-hash synchronisation (PHS) and identification federation.

It’s thought-about a superb possibility for organisations that can’t or don’t want to synchronise password hashes to the cloud, or mockingly people who want stronger authentication controls. In the case of identification federation, which is often applied with the AD Federation Providers (AD FS), PTA is commonly held to be safer – AD FS was notably exploited within the SolarWinds assault.

PTA works by putting in brokers on on-premise servers, as much as a most of 40 per tenant. When a consumer accesses a service utilizing the Azure AD identification platform, corresponding to Microsoft 365, and supplies their credentials, Azure AD encrypts them and sends an authentication request to one of many brokers, which decrypts these credentials, logs in with them, and returns the outcomes to the consumer.

Nonetheless, the CTU analysis staff has now demonstrated a profitable proof of idea (PoC) for an exploit that if left unchecked can be utilized by a menace actor to take advantage of the PTA’s core set up processes and steal the agent’s identification by exporting the certificates that it makes use of for certificate-based authentication (CBA).

With this certificates handy, a menace actor can carry out quite a lot of malicious actions, because the CTU staff defined in its disclosure discover.

See also  Instagram launches new tool to help hacked users regain account access

“The compromised certificates can be utilized with the attacker-controlled PTA agent to create an undetectable backdoor, permitting menace actors to log in utilizing invalid passwords, collect credentials and carry out distant denial of service assaults,” stated the staff. “Attackers can renew the certificates when it expires to take care of persistence within the community for years. A compromised certificates can’t be revoked by an organisation’s directors.”

Nonetheless, having shared the analysis with Microsoft some months in the past, Microsoft has insisted PTA is working as supposed and has given no indication of any plans to deal with the vulnerability.

The Microsoft Safety Response Middle stated: “Our staff accomplished the evaluation for this concern and we perceive that the assault floor for this requires compromising a excessive safety asset by gaining administrative entry within the first place.

“If the client adopted our hardening steering however the attacker nonetheless has entry to the server that runs the PTA agent then they already had entry to the consumer credentials, therefore we consider this vulnerability in itself doesn’t pose an extra danger.

“As a mitigation mechanism, we do have the power to dam brokers on the server facet based mostly on buyer escalations and moreover we’re trying into methods to enhance our audit logs as an improved detection mechanism.”

However, the Secureworks CTU is recommending Azure AD customers carry out the next actions to guard their tenants:

  • Deal with all on-premise hybrid identification parts, together with servers with PTA brokers, as tier zero servers;
  • Take into account adopting different hybrid authentication strategies, corresponding to PHS or identification federation;
  • Monitor for exercise indicative of compromise, corresponding to somebody logging in with an incorrect password – this exercise will be seen within the Azure AD portal, additionally by way of the beta model of the Microsoft Graph sign-ins report. If a probably compromised PTA agent is seen, it may be invalidated by making a help request within the Azure AD portal.
  • Introduce multi-factor authentication to forestall cyber criminals exploiting a PTA agent.
See also  Plaid backs Gemini users for crypto purchases

Source link

active Authentication Azure Directory flaw Users warned
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Related Posts

Amazfit Active 2 review: A great budget smartwatch for Android and iPhone

December 9, 2025

Oppo A40 review: Absurdly cheap, but for casual users only

August 14, 2025

Stuck in the Past? This Many iPhone Users Haven’t Upgraded to iOS 18

June 7, 2025

Are European iPhone Users About to Start Losing Features?

June 3, 2025
Add A Comment

Comments are closed.

Editors Picks

USB-C Mouse, Magic Keyboard, and Trackpad May Show Up in Early 2024

December 12, 2023

Skullgirls 2nd Encore adds DLC character Marie

August 6, 2022

Poco X5 5G review

February 6, 2023

Apple’s Hit Miniseries ‘Masters of the Air’ Debuts in January

October 6, 2023

Subscribe to Updates

Get the latest news and Updates from Behind The Scene about Tech, Startup and more.

Top Post

Xiaomi Robot Vacuum 5 Pro review: A robot vacuum you can trust to do its job

10 Hidden iPhone Features You’re Missing in iOS 26

Apple Watch Ultra 3 review: Incremental, but still superb

Behind The Screen
Facebook Twitter Instagram Pinterest Vimeo YouTube
  • Contact
  • Privacy Policy
  • Terms & Conditions
© 2026 behindthescreen.fr - All rights reserved.

Type above and press Enter to search. Press Esc to cancel.