Monday, 9 Feb 2026
Subscribe
logo
  • Global
  • AI
  • Cloud Computing
  • Edge Computing
  • Security
  • Investment
  • Sustainability
  • More
    • Colocation
    • Quantum Computing
    • Regulation & Policy
    • Infrastructure
    • Power & Cooling
    • Design
    • Innovations
    • Blog
Font ResizerAa
Data Center NewsData Center News
Search
  • Global
  • AI
  • Cloud Computing
  • Edge Computing
  • Security
  • Investment
  • Sustainability
  • More
    • Colocation
    • Quantum Computing
    • Regulation & Policy
    • Infrastructure
    • Power & Cooling
    • Design
    • Innovations
    • Blog
Have an existing account? Sign In
Follow US
© 2022 Foxiz News Network. Ruby Design Company. All Rights Reserved.
Data Center News > Blog > Design > Unfixed Microsoft Entra ID Authentication Bypass Threatens Hybrid IDs
Design

Unfixed Microsoft Entra ID Authentication Bypass Threatens Hybrid IDs

Last updated: August 20, 2024 1:52 pm
Published August 20, 2024
Share
Unfixed Microsoft Entra ID Authentication Bypass Threatens Hybrid IDs
SHARE

Researchers have discovered a method to manipulate the credential validation course of in Microsoft Entra ID identification environments that they are saying attackers can use to bypass authentication in hybrid identification infrastructures.

The assault would require an adversary to have admin entry on a server internet hosting a Go-By Authentication (PTA) agent, a element that enables customers to sign up to cloud providers utilizing on-premises Microsoft Entra ID (previously Azure Energetic Listing) credentials.

They will then use that entry to log in as an Entra ID person throughout totally different on-premises domains with out the necessity for separate authentication, researchers from Cymulate stated in a report.

Turning PTA Right into a Double-Agent

“This vulnerability successfully turns the PTA agent right into a double agent, permitting attackers to log in as any synced AD person with out realizing their precise password,” Cymulate safety researcher Ilan Kalendarov wrote.

“This might probably grant entry to a world admin person if such privileges had been assigned, no matter their unique synced AD area,” and allow lateral motion to totally different on-premises domains.

Microsoft didn’t reply instantly to a Darkish Studying request for remark. However in accordance with Cymulate, Microsoft plans to repair code on its finish to handle the problem. Nevertheless, the corporate additionally has described the assault approach as presenting solely a medium-severity menace, the Israel-based safety vendor stated.

Associated:Essential AWS Vulnerabilities Permit S3 Assault Bonanza

Earlier this month at Black Hat USA 2024, a safety researcher at Semperis disclosed another issue with Entra ID that allowed attackers to entry to a company’s complete cloud surroundings.

See also  Why Infrastructure Matters in the Race for Adoption

Attackers are more and more specializing in cloud identification providers resembling Entra ID, Okta, and Ping, as a result of as soon as they’re able to compromise one in all these suppliers, they’ve full entry to enterprise information in SaaS apps.

Read the rest of this article in Dark Reading.

Source link

TAGGED: Authentication, Bypass, Entra, hybrid, IDS, Microsoft, Threatens, Unfixed
Share This Article
Twitter Email Copy Link Print
Previous Article Fortera Fortera Raises $85M in Series C Funding
Next Article Talus Biosciences Talus Bioscience Raises $11.2M in New Funding
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Your Trusted Source for Accurate and Timely Updates!

Our commitment to accuracy, impartiality, and delivering breaking news as it happens has earned us the trust of a vast audience. Stay ahead with real-time updates on the latest events, trends.
FacebookLike
TwitterFollow
InstagramFollow
YoutubeSubscribe
LinkedInFollow
MediumFollow
- Advertisement -
Ad image

Popular Posts

Film festival showcases what artificial intelligence can do on the big screen

Runway's third-annual AI Movie Competition kicks off with a screening at Lincoln Middle's Alice Tully…

June 7, 2025

Securitas to deploy AI mm-wave screening in data centres

Securitas has struck a strategic partnership with Rohde & Schwarz to combine millimetre-wave folks screening…

September 29, 2025

ServiceNow Acquires Raytion

ServiceNow (NYSE: NOW), a Santa Clara, CA-based supplier of an AI platform for enterprise transformation,…

July 25, 2024

Infosecurity Europe 2024: Ransomware and AI threats drive surge in cybersecurity investments

Infosecurity Europe, the premier info safety occasion, will happen at ExCeL London from 4-6 June…

May 24, 2024

Serbian authorities hacking and installing spyware on activists’ phones

Police in Serbia are utilizing cell system hacking instruments to interrupt into the telephones of…

December 16, 2024

You Might Also Like

Riello UPS announces new M2X modular power system
Design

Riello UPS announces new M2X modular power system

By saad
Microsoft unveils method to detect sleeper agent backdoors
AI

Microsoft unveils method to detect sleeper agent backdoors

By saad
Enhancing transparency and efficiency across Europe's financial markets
Design

Enhancing transparency and efficiency across Europe’s financial markets

By saad
Orion DataGuard enhances security for hyperscale data centres
Design

Orion DataGuard enhances security for hyperscale data centres

By saad
Data Center News
Facebook Twitter Youtube Instagram Linkedin

About US

Data Center News: Stay informed on the pulse of data centers. Latest updates, tech trends, and industry insights—all in one place. Elevate your data infrastructure knowledge.

Top Categories
  • Global Market
  • Infrastructure
  • Innovations
  • Investments
Usefull Links
  • Home
  • Contact
  • Privacy Policy
  • Terms & Conditions

© 2024 – datacenternews.tech – All rights reserved

Welcome Back!

Sign in to your account

Lost your password?
We use cookies to ensure that we give you the best experience on our website. If you continue to use this site we will assume that you are happy with it.
You can revoke your consent any time using the Revoke consent button.