Analytics BIOC
Informational
✕
First-time directory sync of an on-premises domain user to an existing cloud account
First-time synchronization of an on-premises domain user with an existing cloud account.
- Module:
- Identity Threat Detection (ITDR), SaaS Threat Detection
- Licensed by:
- Identity Threat Detection (ITDR)
- Data source:
- AzureAD Audit Log
ATT&CK tactics: Persistence (TA0003)
ATT&CK techniques: Valid Accounts (T1078)
Attacker's goals:
Attackers may leverage DirectorySync to move laterally from a compromised on-premise environment into the cloud tenant, allowing them to bypass the cloud's security boundaries and take over high-value cloud identities.
Investigative actions:
Check if the cloud account was an administrator (Global Admin, etc.) before this sync. Determine if the on-premise user was recently created or if its 'proxyAddress' attribute was recently modified. Confirm if the organization intended to transition this account from Cloud-Only to Hybrid. Verify the consistency between the on-premises 'ObjectGUID' and the newly assigned 'ImmutableID' in Azure AD.
- Test period:
- N/A (single event)
- Deduplication:
- 1 Day