Beyond On-Premises: Exploring the Post-Domain Admin Landscape in the Cloud

By Sriraam Natarajan , Venkatraman Kumar on 01 Jun 2023 @ Securityfest
πŸ“Ή Video πŸ”— Link
#cloud-security #red-team
Focus Areas: Cloud Security

Presentation Material

Abstract

Organizations are increasingly relying on cloud services from Azure, as there is native support from Microsoft. After obtaining Domain Admin privileges, it is essential to always think of attack paths or scenarios to escalate our privileges or describe the maximum impact. One such thing is escalating privileges to Azure Services. This talk demonstrates attack paths for obtaining Global Administrator privileges on Azure AD from domain admin privileges on the on-premise network. Multiple domains can be registered under a single tenant, hence after obtaining global admin privileges on Azure it is possible for the adversary to gain administrative access over these domains.

Presented at Security Fest 2023.