Sunday, 14 Dec 2025
Subscribe
logo
  • Global
  • AI
  • Cloud Computing
  • Edge Computing
  • Security
  • Investment
  • Sustainability
  • More
    • Colocation
    • Quantum Computing
    • Regulation & Policy
    • Infrastructure
    • Power & Cooling
    • Design
    • Innovations
    • Blog
Font ResizerAa
Data Center NewsData Center News
Search
  • Global
  • AI
  • Cloud Computing
  • Edge Computing
  • Security
  • Investment
  • Sustainability
  • More
    • Colocation
    • Quantum Computing
    • Regulation & Policy
    • Infrastructure
    • Power & Cooling
    • Design
    • Innovations
    • Blog
Have an existing account? Sign In
Follow US
© 2022 Foxiz News Network. Ruby Design Company. All Rights Reserved.
Data Center News > Blog > Design > Unfixed Microsoft Entra ID Authentication Bypass Threatens Hybrid IDs
Design

Unfixed Microsoft Entra ID Authentication Bypass Threatens Hybrid IDs

Last updated: August 20, 2024 1:52 pm
Published August 20, 2024
Share
Unfixed Microsoft Entra ID Authentication Bypass Threatens Hybrid IDs
SHARE

Researchers have discovered a method to manipulate the credential validation course of in Microsoft Entra ID identification environments that they are saying attackers can use to bypass authentication in hybrid identification infrastructures.

The assault would require an adversary to have admin entry on a server internet hosting a Go-By Authentication (PTA) agent, a element that enables customers to sign up to cloud providers utilizing on-premises Microsoft Entra ID (previously Azure Energetic Listing) credentials.

They will then use that entry to log in as an Entra ID person throughout totally different on-premises domains with out the necessity for separate authentication, researchers from Cymulate stated in a report.

Turning PTA Right into a Double-Agent

“This vulnerability successfully turns the PTA agent right into a double agent, permitting attackers to log in as any synced AD person with out realizing their precise password,” Cymulate safety researcher Ilan Kalendarov wrote.

“This might probably grant entry to a world admin person if such privileges had been assigned, no matter their unique synced AD area,” and allow lateral motion to totally different on-premises domains.

Microsoft didn’t reply instantly to a Darkish Studying request for remark. However in accordance with Cymulate, Microsoft plans to repair code on its finish to handle the problem. Nevertheless, the corporate additionally has described the assault approach as presenting solely a medium-severity menace, the Israel-based safety vendor stated.

Associated:Essential AWS Vulnerabilities Permit S3 Assault Bonanza

Earlier this month at Black Hat USA 2024, a safety researcher at Semperis disclosed another issue with Entra ID that allowed attackers to entry to a company’s complete cloud surroundings.

See also  Microsoft invests €3.2 billion in AI and the cloud in Germany

Attackers are more and more specializing in cloud identification providers resembling Entra ID, Okta, and Ping, as a result of as soon as they’re able to compromise one in all these suppliers, they’ve full entry to enterprise information in SaaS apps.

Read the rest of this article in Dark Reading.

Source link

TAGGED: Authentication, Bypass, Entra, hybrid, IDS, Microsoft, Threatens, Unfixed
Share This Article
Twitter Email Copy Link Print
Previous Article Fortera Fortera Raises $85M in Series C Funding
Next Article Talus Biosciences Talus Bioscience Raises $11.2M in New Funding
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Your Trusted Source for Accurate and Timely Updates!

Our commitment to accuracy, impartiality, and delivering breaking news as it happens has earned us the trust of a vast audience. Stay ahead with real-time updates on the latest events, trends.
FacebookLike
TwitterFollow
InstagramFollow
YoutubeSubscribe
LinkedInFollow
MediumFollow
- Advertisement -
Ad image

Popular Posts

Anthropic just launched a new platform that lets everyone in your company collaborate on AI — not just the tech team

Be part of our each day and weekly newsletters for the most recent updates and…

March 8, 2025

Coin-sized device uses nut waste and drops of water to generate green energy

Waterloo researchers developed a coin-sized gadget that may generate electrical energy as water evaporates from…

August 27, 2025

A Guide to Data Center Circuit Breaker Design and Deployment

Identical to properties and workplaces, information middle circuit breakers are important to serving to regulate…

December 12, 2024

Keysource issues warning to data centres as overconfidence threatens sustainability progress

That’s in line with unbiased analysis performed by knowledge centre resolution supplier, Keysource.Findings present that…

January 28, 2025

Featured.com Acquires Help A Reporter Out

Featured.com, a Scottsdale, AZ-based platform that connects subject-matter specialists with journalists, acquired Assist A Reporter…

April 17, 2025

You Might Also Like

Microsoft ‘Promptions’ fix AI prompts failing to deliver
AI

Microsoft ‘Promptions’ fix AI prompts failing to deliver

By saad
Veeam and HPE introduce updates to streamline hybrid cloud recovery
Cloud Computing

Veeam and HPE updates aim to streamline hybrid cloud recovery

By saad
New Microsoft cloud updates support Indonesia’s long-term AI goals
AI

Microsoft cloud updates support Indonesia’s long-term AI goals

By saad
Microsoft datacenter
Global Market

Microsoft loses two senior AI infrastructure leaders as data center pressures mount

By saad
Data Center News
Facebook Twitter Youtube Instagram Linkedin

About US

Data Center News: Stay informed on the pulse of data centers. Latest updates, tech trends, and industry insights—all in one place. Elevate your data infrastructure knowledge.

Top Categories
  • Global Market
  • Infrastructure
  • Innovations
  • Investments
Usefull Links
  • Home
  • Contact
  • Privacy Policy
  • Terms & Conditions

© 2024 – datacenternews.tech – All rights reserved

Welcome Back!

Sign in to your account

Lost your password?
We use cookies to ensure that we give you the best experience on our website. If you continue to use this site we will assume that you are happy with it.
You can revoke your consent any time using the Revoke consent button.