Monday, 16 Jun 2025
Subscribe
logo
  • Global
  • AI
  • Cloud Computing
  • Edge Computing
  • Security
  • Investment
  • Sustainability
  • More
    • Colocation
    • Quantum Computing
    • Regulation & Policy
    • Infrastructure
    • Power & Cooling
    • Design
    • Innovations
    • Blog
Font ResizerAa
Data Center NewsData Center News
Search
  • Global
  • AI
  • Cloud Computing
  • Edge Computing
  • Security
  • Investment
  • Sustainability
  • More
    • Colocation
    • Quantum Computing
    • Regulation & Policy
    • Infrastructure
    • Power & Cooling
    • Design
    • Innovations
    • Blog
Have an existing account? Sign In
Follow US
© 2022 Foxiz News Network. Ruby Design Company. All Rights Reserved.
Data Center News > Blog > Design > Unfixed Microsoft Entra ID Authentication Bypass Threatens Hybrid IDs
Design

Unfixed Microsoft Entra ID Authentication Bypass Threatens Hybrid IDs

Last updated: August 20, 2024 1:52 pm
Published August 20, 2024
Share
Unfixed Microsoft Entra ID Authentication Bypass Threatens Hybrid IDs
SHARE

Researchers have discovered a method to manipulate the credential validation course of in Microsoft Entra ID identification environments that they are saying attackers can use to bypass authentication in hybrid identification infrastructures.

The assault would require an adversary to have admin entry on a server internet hosting a Go-By Authentication (PTA) agent, a element that enables customers to sign up to cloud providers utilizing on-premises Microsoft Entra ID (previously Azure Energetic Listing) credentials.

They will then use that entry to log in as an Entra ID person throughout totally different on-premises domains with out the necessity for separate authentication, researchers from Cymulate stated in a report.

Turning PTA Right into a Double-Agent

“This vulnerability successfully turns the PTA agent right into a double agent, permitting attackers to log in as any synced AD person with out realizing their precise password,” Cymulate safety researcher Ilan Kalendarov wrote.

“This might probably grant entry to a world admin person if such privileges had been assigned, no matter their unique synced AD area,” and allow lateral motion to totally different on-premises domains.

Microsoft didn’t reply instantly to a Darkish Studying request for remark. However in accordance with Cymulate, Microsoft plans to repair code on its finish to handle the problem. Nevertheless, the corporate additionally has described the assault approach as presenting solely a medium-severity menace, the Israel-based safety vendor stated.

Associated:Essential AWS Vulnerabilities Permit S3 Assault Bonanza

Earlier this month at Black Hat USA 2024, a safety researcher at Semperis disclosed another issue with Entra ID that allowed attackers to entry to a company’s complete cloud surroundings.

See also  Microsoft, Meta, Google Launch New AI Connectivity Standard for Data Centers

Attackers are more and more specializing in cloud identification providers resembling Entra ID, Okta, and Ping, as a result of as soon as they’re able to compromise one in all these suppliers, they’ve full entry to enterprise information in SaaS apps.

Read the rest of this article in Dark Reading.

Source link

TAGGED: Authentication, Bypass, Entra, hybrid, IDS, Microsoft, Threatens, Unfixed
Share This Article
Twitter Email Copy Link Print
Previous Article Fortera Fortera Raises $85M in Series C Funding
Next Article Talus Biosciences Talus Bioscience Raises $11.2M in New Funding
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Your Trusted Source for Accurate and Timely Updates!

Our commitment to accuracy, impartiality, and delivering breaking news as it happens has earned us the trust of a vast audience. Stay ahead with real-time updates on the latest events, trends.
FacebookLike
TwitterFollow
InstagramFollow
YoutubeSubscribe
LinkedInFollow
MediumFollow
- Advertisement -
Ad image

Popular Posts

Is current tech rules fostering or stifling progress?

As AI reshapes the digital panorama, tech firms discover themselves in a high-stakes recreation of…

October 1, 2024

Qualcomm and Mistral AI bring generative AI directly to edge devices

Qualcomm companions with Mistral AI to combine new generative AI fashions into Snapdragon-powered gadgets. Mistral…

November 8, 2024

Sware Raises $6M in Series B Funding

Sware, a Boston, MA-based supplier of a software program validation resolution for progressive life sciences…

June 8, 2024

EU and Japan reinforce tech and digital partnership

The EU and Japan not too long ago held their third Digital Partnership Council in…

May 13, 2025

OutSystems unveils no-code AI Agent Builder

Low-code growth platform supplier OutSystems has launched AI Agent Builder, a no-code software for constructing…

March 15, 2024

You Might Also Like

Schneider Electric accelerates the development and deployment of AI Factories
Design

Schneider Electric accelerates the development and deployment of AI Factories

By saad
Nvidia CEO Sees Tenfold Boost to Europe’s AI Computing Power
Design

Nvidia CEO Sees Tenfold Boost to Europe’s AI Computing Power

By saad
Why Prefabricated Concrete Is Ideal for Data Center Construction
Design

Why Prefabricated Concrete Is Ideal for Data Center Construction

By saad
TSMC Evaluates Building Advanced Chip Plant in the UAE
Design

TSMC Evaluates Building Advanced Chip Plant in the UAE

By saad
Data Center News
Facebook Twitter Youtube Instagram Linkedin

About US

Data Center News: Stay informed on the pulse of data centers. Latest updates, tech trends, and industry insights—all in one place. Elevate your data infrastructure knowledge.

Top Categories
  • Global Market
  • Infrastructure
  • Innovations
  • Investments
Usefull Links
  • Home
  • Contact
  • Privacy Policy
  • Terms & Conditions

© 2024 – datacenternews.tech – All rights reserved

Welcome Back!

Sign in to your account

Lost your password?
We use cookies to ensure that we give you the best experience on our website. If you continue to use this site we will assume that you are happy with it.OkNoPrivacy policy
You can revoke your consent any time using the Revoke consent button.Revoke consent