Skip to content

Entra ID Hybrid Pentest

NodeZero's Entra ID Hybrid Pentest is a gray-box–style pentest that uses an Azure credential and a privileged Active Directory (AD) credential to enumerate and exploit attack paths to compromising your Entra ID tenant. The Entra ID Hybrid Pentest (formerly called Azure Entra ID) runs from a Docker container within your private enterprise network.

Why should I Run a NodeZero Entra ID Hybrid Pentest?

How to Run an Entra ID Hybrid Pentest


Why Should I Run a NodeZero Entra ID Hybrid Pentest?

An Entra ID Hybrid pentest is a security test focused on determining misconfigurations within your Active Directory and Entra ID hybrid environment that could lead to a full tenant compromise.

The NodeZero Entra ID Hybrid Pentest is a gray-box style pentest requiring a privileged AD credential with DCSync permissions and an initial Entra user credential. The privileged AD credential allows NodeZero to simulate an internal Domain Compromise that could enable common attack techniques, such as Entra Connect credential dumping and Azure Seamless SSO Silver Ticket attacks.

By providing an initial Entra credential, NodeZero is able to simulate an initial credential compromise and enumerate the Entra ID environment. This initial collection also allows NodeZero to highlight possible privilege escalation misconfigurations for other users within the tenant.


How to Run an Entra ID Hybrid Pentest

From NodeZero's "Run Pentest" page, the Entra ID Hybrid Pentest can be found under the Identity category.

Scope

The Entra ID Hybrid Pentest requires a Domain Controller (DC) IP Address. NodeZero will connect to the DC utilizing the privileged domain credential (see below) to query AD via LDAP(S) and gather details about the domain's hybrid Entra ID setup. This includes the location of the Entra Connect application.

Additionally, NodeZero will perform a DCSync attack against the DC to simulate a Domain Compromise, and will collect the credential for the AZUREADSSOACC$ Machine Account, if present. It will use this credential to perform Kerberos Silver Ticket Attacks, if possible.

Host will be in scope

The host running Entra Connect – once enumerated – is automatically considered in scope for the Entra ID Hybrid pentest.

Privileged Domain Credential

The Entra ID Hybrid pentest requires a Privileged Domain Credential with DCSync privileges – much like the NodeZero AD Password Audit. This allows NodeZero to simulate a Domain Compromise, enabling NodeZero to evaluate several common attack vectors and demonstrate how an on-premise compromise could enable an attacker to compromise your Entra ID tenant.

Azure Credential

An initial Azure Entra ID user credential is required for the Entra ID Hybrid pentest. As of October 2024, Microsoft mandated the use of Multi-Factor Authentication (MFA) for Azure services. NodeZero uses the Device Code Flow (a.k.a. OAuth Device Authorization Grant) to request an initial credential for the Entra ID Hybrid Pentest.

During configuration, users will be asked to provide their Entra tenant ID instead of a username/password. Once the pentest begins, users will receive an email notification that NodeZero is ready for them to return to the Portal. There, they complete the authentication and authorization steps required for NodeZero to access the tenant. (For details, see Injecting an Entra ID MFA Credential.)

This allows NodeZero to simulate an initial access vector to your Entra environment. Since Entra allows users to enumerate a significant portion of the tenant's configuration by default, this credential does not need to be privileged.

Once NodeZero enumerates the environment using this credential, NodeZero will attempt to find and exploit a path to compromising the tenant, using the credential as a starting point. Also, NodeZero will show any paths to full tenant compromise that it enumerates from other users, using Azurehound.