Sunday, 1 Mar 2026
Subscribe
logo
  • Global
  • AI
  • Cloud Computing
  • Edge Computing
  • Security
  • Investment
  • Sustainability
  • More
    • Colocation
    • Quantum Computing
    • Regulation & Policy
    • Infrastructure
    • Power & Cooling
    • Design
    • Innovations
    • Blog
Font ResizerAa
Data Center NewsData Center News
Search
  • Global
  • AI
  • Cloud Computing
  • Edge Computing
  • Security
  • Investment
  • Sustainability
  • More
    • Colocation
    • Quantum Computing
    • Regulation & Policy
    • Infrastructure
    • Power & Cooling
    • Design
    • Innovations
    • Blog
Have an existing account? Sign In
Follow US
© 2022 Foxiz News Network. Ruby Design Company. All Rights Reserved.
Data Center News > Blog > Design > Unfixed Microsoft Entra ID Authentication Bypass Threatens Hybrid IDs
Design

Unfixed Microsoft Entra ID Authentication Bypass Threatens Hybrid IDs

Last updated: August 20, 2024 1:52 pm
Published August 20, 2024
Share
Unfixed Microsoft Entra ID Authentication Bypass Threatens Hybrid IDs
SHARE

Researchers have discovered a method to manipulate the credential validation course of in Microsoft Entra ID identification environments that they are saying attackers can use to bypass authentication in hybrid identification infrastructures.

The assault would require an adversary to have admin entry on a server internet hosting a Go-By Authentication (PTA) agent, a element that enables customers to sign up to cloud providers utilizing on-premises Microsoft Entra ID (previously Azure Energetic Listing) credentials.

They will then use that entry to log in as an Entra ID person throughout totally different on-premises domains with out the necessity for separate authentication, researchers from Cymulate stated in a report.

Turning PTA Right into a Double-Agent

“This vulnerability successfully turns the PTA agent right into a double agent, permitting attackers to log in as any synced AD person with out realizing their precise password,” Cymulate safety researcher Ilan Kalendarov wrote.

“This might probably grant entry to a world admin person if such privileges had been assigned, no matter their unique synced AD area,” and allow lateral motion to totally different on-premises domains.

Microsoft didn’t reply instantly to a Darkish Studying request for remark. However in accordance with Cymulate, Microsoft plans to repair code on its finish to handle the problem. Nevertheless, the corporate additionally has described the assault approach as presenting solely a medium-severity menace, the Israel-based safety vendor stated.

Associated:Essential AWS Vulnerabilities Permit S3 Assault Bonanza

Earlier this month at Black Hat USA 2024, a safety researcher at Semperis disclosed another issue with Entra ID that allowed attackers to entry to a company’s complete cloud surroundings.

See also  Microsoft Teams in the EU Crosshairs

Attackers are more and more specializing in cloud identification providers resembling Entra ID, Okta, and Ping, as a result of as soon as they’re able to compromise one in all these suppliers, they’ve full entry to enterprise information in SaaS apps.

Read the rest of this article in Dark Reading.

Source link

TAGGED: Authentication, Bypass, Entra, hybrid, IDS, Microsoft, Threatens, Unfixed
Share This Article
Twitter Email Copy Link Print
Previous Article Fortera Fortera Raises $85M in Series C Funding
Next Article Talus Biosciences Talus Bioscience Raises $11.2M in New Funding
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Your Trusted Source for Accurate and Timely Updates!

Our commitment to accuracy, impartiality, and delivering breaking news as it happens has earned us the trust of a vast audience. Stay ahead with real-time updates on the latest events, trends.
FacebookLike
TwitterFollow
InstagramFollow
YoutubeSubscribe
LinkedInFollow
MediumFollow
- Advertisement -
Ad image

Popular Posts

MindSpire Raises £850k in Pre-Seed Funding

MindSpire, a Tunbridge Wells, Kent, UK-based neurotech startup creating medical gadgets, raised £850K in Pre-Seed…

May 18, 2025

Power-Hungry Data Centers Are Gobbling Up Texas Amid AI Boom

(Bloomberg Markets) -- One enterprise could lastly be getting too huge for Texas: knowledge facilities, these…

August 1, 2024

Intern allegedly sabotages ByteDance AI project, leading to dismissal

ByteDance, the creator of TikTok, just lately skilled a safety breach involving an intern who…

October 26, 2024

Assessing the State of Data Center Supply Chains in H2 2024

The information heart provide chain has improved in comparison with a 12 months or two…

August 12, 2024

How VPS-Optimized Demo Trading and Technical Analysis are Transforming Investment Due Diligence

The world of investing has been profoundly impacted by expertise, with digital platforms elementary in…

November 11, 2024

You Might Also Like

The growing case for passwordless authentication in a digital world
Innovations

The growing case for passwordless authentication in a digital world

By saad
Binary number system, bits, binary numbers on an LCD display abstract wide background, banner, backdrop. Calculator screen macro, closeup, nobody. Math and computer science, electrical engineering
Global Market

Data stored in glass could last over 10,000 years, Microsoft says

By saad
IBM launches FlashSystem with AI capabilities
Design

IBM launches FlashSystem with AI capabilities

By saad
StorMagic welcomes Scott Mann as global SVP of sales
Design

StorMagic welcomes Scott Mann as global SVP of sales

By saad
Data Center News
Facebook Twitter Youtube Instagram Linkedin

About US

Data Center News: Stay informed on the pulse of data centers. Latest updates, tech trends, and industry insights—all in one place. Elevate your data infrastructure knowledge.

Top Categories
  • Global Market
  • Infrastructure
  • Innovations
  • Investments
Usefull Links
  • Home
  • Contact
  • Privacy Policy
  • Terms & Conditions

© 2024 – datacenternews.tech – All rights reserved

Welcome Back!

Sign in to your account

Lost your password?
We use cookies to ensure that we give you the best experience on our website. If you continue to use this site we will assume that you are happy with it.
You can revoke your consent any time using the Revoke consent button.