Saturday, 11 Apr 2026
Subscribe
logo
  • Global
  • AI
  • Cloud Computing
  • Edge Computing
  • Security
  • Investment
  • Sustainability
  • More
    • Colocation
    • Quantum Computing
    • Regulation & Policy
    • Infrastructure
    • Power & Cooling
    • Design
    • Innovations
    • Blog
Font ResizerAa
Data Center NewsData Center News
Search
  • Global
  • AI
  • Cloud Computing
  • Edge Computing
  • Security
  • Investment
  • Sustainability
  • More
    • Colocation
    • Quantum Computing
    • Regulation & Policy
    • Infrastructure
    • Power & Cooling
    • Design
    • Innovations
    • Blog
Have an existing account? Sign In
Follow US
© 2022 Foxiz News Network. Ruby Design Company. All Rights Reserved.
Data Center News > Blog > Design > Unfixed Microsoft Entra ID Authentication Bypass Threatens Hybrid IDs
Design

Unfixed Microsoft Entra ID Authentication Bypass Threatens Hybrid IDs

Last updated: August 20, 2024 1:52 pm
Published August 20, 2024
Share
Unfixed Microsoft Entra ID Authentication Bypass Threatens Hybrid IDs
SHARE

Researchers have discovered a method to manipulate the credential validation course of in Microsoft Entra ID identification environments that they are saying attackers can use to bypass authentication in hybrid identification infrastructures.

The assault would require an adversary to have admin entry on a server internet hosting a Go-By Authentication (PTA) agent, a element that enables customers to sign up to cloud providers utilizing on-premises Microsoft Entra ID (previously Azure Energetic Listing) credentials.

They will then use that entry to log in as an Entra ID person throughout totally different on-premises domains with out the necessity for separate authentication, researchers from Cymulate stated in a report.

Turning PTA Right into a Double-Agent

“This vulnerability successfully turns the PTA agent right into a double agent, permitting attackers to log in as any synced AD person with out realizing their precise password,” Cymulate safety researcher Ilan Kalendarov wrote.

“This might probably grant entry to a world admin person if such privileges had been assigned, no matter their unique synced AD area,” and allow lateral motion to totally different on-premises domains.

Microsoft didn’t reply instantly to a Darkish Studying request for remark. However in accordance with Cymulate, Microsoft plans to repair code on its finish to handle the problem. Nevertheless, the corporate additionally has described the assault approach as presenting solely a medium-severity menace, the Israel-based safety vendor stated.

Associated:Essential AWS Vulnerabilities Permit S3 Assault Bonanza

Earlier this month at Black Hat USA 2024, a safety researcher at Semperis disclosed another issue with Entra ID that allowed attackers to entry to a company’s complete cloud surroundings.

See also  Google, Microsoft Partner With Energy Firms to Clean Up the Grid | DCN

Attackers are more and more specializing in cloud identification providers resembling Entra ID, Okta, and Ping, as a result of as soon as they’re able to compromise one in all these suppliers, they’ve full entry to enterprise information in SaaS apps.

Read the rest of this article in Dark Reading.

Source link

TAGGED: Authentication, Bypass, Entra, hybrid, IDS, Microsoft, Threatens, Unfixed
Share This Article
Twitter Email Copy Link Print
Previous Article Fortera Fortera Raises $85M in Series C Funding
Next Article Talus Biosciences Talus Bioscience Raises $11.2M in New Funding
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Your Trusted Source for Accurate and Timely Updates!

Our commitment to accuracy, impartiality, and delivering breaking news as it happens has earned us the trust of a vast audience. Stay ahead with real-time updates on the latest events, trends.
FacebookLike
TwitterFollow
InstagramFollow
YoutubeSubscribe
LinkedInFollow
MediumFollow
- Advertisement -
Ad image

Popular Posts

Autonomous truck company Aurora delays hauling freight without human drivers until April

A self-driving tractor trailer maneuvers round a take a look at observe in Pittsburgh, Thursday,…

October 31, 2024

Equinix pioneers next-generation energy solutions for data centres

Equinix, Inc. (Nasdaq: EQIX), recognised globally for digital infrastructure, is actively collaborating with main vitality…

August 14, 2025

Biden-Harris plan funds $269M for U.S. microelectronics growth

The Division of Protection is offering a $269 million funding to strengthen the US microelectronics…

October 2, 2024

Sifflet Raises $18M in Funding

Sifflet, a NYC-based supplier of an information observability platform, has raised $18M USD in funding. Backers included…

June 19, 2025

Cisco patches actively exploited zero-day flaw in Nexus switches

Cisco has launched patches for a number of collection of Nexus switches to repair a…

July 3, 2024

You Might Also Like

Rebellions secures new investment to support AI infrastructure
Design

Rebellions secures new investment to support AI infrastructure

By saad
CoreWeave secures AI cloud capacity deal with Meta through 2032
Design

CoreWeave secures AI cloud capacity deal with Meta through 2032

By saad
Microsoft open-source toolkit secures AI agents at runtime
AI

Microsoft open-source toolkit secures AI agents at runtime

By saad
Nscale moves into power with AIPCorp deal, building 8GW U.S. AI campus to bypass energy bottlenecks
Edge Computing

Nscale moves into power with AIPCorp deal, building 8GW U.S. AI campus to bypass energy bottlenecks

By saad
Data Center News
Facebook Twitter Youtube Instagram Linkedin

About US

Data Center News: Stay informed on the pulse of data centers. Latest updates, tech trends, and industry insights—all in one place. Elevate your data infrastructure knowledge.

Top Categories
  • Global Market
  • Infrastructure
  • Innovations
  • Investments
Usefull Links
  • Home
  • Contact
  • Privacy Policy
  • Terms & Conditions

© 2024 – datacenternews.tech – All rights reserved

Welcome Back!

Sign in to your account

Lost your password?
We use cookies to ensure that we give you the best experience on our website. If you continue to use this site we will assume that you are happy with it.
You can revoke your consent any time using the Revoke consent button.