
How Hackers Persist & Privesc in Microsoft 365
Source: YouTube · John Hammond · published Nov 5, 2024 · 27:14
This video demonstrates how attackers can exploit dynamic groups in Entra ID to maintain persistence and escalate privileges in Microsoft 365 environments 0:00.
Key Takeaways:
• Entra ID contains two types of groups: Microsoft 365 groups for application access and security groups for resource control, both of which can be exploited by attackers 3:07.
• Dynamic groups automatically add users based on predefined rules and require a Microsoft Entra ID P1 license, creating a potential attack vector when improperly configured 3:45.
• Using Graph Runner, attackers can automate post-exploitation activities against Microsoft Graph API after gaining initial access through phishing 9:10.
• Attackers can invite guest accounts with usernames that match dynamic group rules, causing automatic addition to privileged groups for privilege escalation 16:04.
• Security group cloning creates confusion by duplicating groups with identical names, potentially leading administrators to accidentally grant permissions to malicious groups 22:19.
Defensive measures include restricting users' ability to create security groups and limiting guest user invitation capabilities to prevent these attack vectors 25:17.
Sources:
Generate CPE Credits
Generate a professional CPE document from this video's transcript.
Estimated credit: 0.5 CPE hours
Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.
Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.
Free account. One generation at a time, with a daily limit.
CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.
Transcript Preview
First 800 characters of the transcript
in this video I'll show you how hackers can maintain persistence and even potentially escalate their privileges inside of an entra ID or Microsoft 365 environment now to get started first I want to set up our environment so I'll open up the entra ID tenant in my web browser Firefox that is at the usual microsoftonline login at login. microsoftonline.com and from there I'll go ahead and log in as the M365 admin or the Global administrator for this tenant this was a developer tenant that I had created previously in another video just qfz z. onmicrosoft.com so I'll sign in here enter my password I will need to do some multiactor authentication work approving the sign in and now I can log in now bear in mind I'm logging in as the global administrator just to set up the environment so that we a…