Le Lézard
Classified in: Science and technology

Preempt Finds Flaw in Office 365 with Azure AD Connect Which Could Result in Domain Compromise


SAN FRANCISCO, Dec. 12, 2017 /PRNewswire/ -- Preempt, a leader in adaptive threat prevention that helps enterprises eliminate insider threats and security breaches, today announced its research team has uncovered a vulnerability with Microsoft Office 365 when integrated with an on-premises Active Directory Domain Services (AD DS) using Azure AD Connect software that unnecessarily gives users elevated administrator privileges, making them "stealthy"  administrators. Preempt provided responsible disclosure to Microsoft which has issued a customer security advisory today regarding the vulnerability.

Preempt Security Logo (PRNewsfoto/Preempt)

Preempt discovered this surprising issue was occurring when customers were installing Microsoft Office 365 with Azure AD Connect software for on-premise AD DS integration (hybrid deployment). Preempt customers have been protected from this flaw since October by providing in-depth defense with both alerting on stealthy administrators and real-time prevention when suspicious behavior is detected.

"Most Active Directory audit systems easily alert on excessive privileges, but will often miss users who have elevated domain privileges indirectly through domain discretionary access control list (DACL) configuration," said Roman Blachman, CTO and co-founder at Preempt. "We refer to these users as stealthy admins. The majority of our customers' have Office 365 hybrid deployments and almost every one of them were vulnerable to this because Azure AD Connect was installed in express settings and created this flaw."

This discovered vulnerability points to a much larger issue as more companies move to the cloud. This vulnerability piles on to previously detected issues, including Microsoft Advisory 4033453, that has discovered an issue with writeback feature - granting Azure AD administrators complete control over on-premises AD DS infrastructure. Privileged users are often overlooked and are not managed correctly when synchronized with the cloud, due to limited toolset in comparison to the on-premises solutions. With the introduced cloud identity management, new management and security challenges are introduced.

By identifying stealthy administrative accounts through not-so-obvious delegation, Preempt helps enterprises ensure that privileged accounts are used consistent with corporate security policies. Unlike privileged identity management (PIM) or privileged access management (PAM) solutions that lack support for behavioral policy and adaptive response, Preempt is able to understand the full relational context of user identity and behavior allowing enterprises to not only identify such risks as MSOnline (MSOL) privilege escalations, but also detect and proactively prevent compromise of such accounts. Without Preempt's real-time discovery, detection and enforcement, the possibility of a malicious attacker being able to gain domain administrator privileges through such vulnerabilities and cause damage, is significant for enterprises. 

For organizations who need to determine if they are at risk of stealthy administrators in their organization either from cloud environments such as the Azure AD Connect account flaw or for other reasons, Preempt has developed a free tool, Preempt Inspector, that can provide a free enterprise health assessment for passwords, stealthy administrators and more.

The Free Preempt Inspector tool can be downloaded here: http://inspector.preempt.com.   

Additional Resources:

To learn more about the Microsoft vulnerability, or to learn how to protect your organization for this flaw or from stealthy administrators in general, check out the following resources:

Detailed Blog:

Videos:

About Preempt

Preempt protects organizations by eliminating insider threats and security breaches. Threats are not black or white and the Preempt Platform is the only solution that delivers adaptive threat prevention that continuously preempts threats based on identity, behavior and risk. This ensures that both security threats and risky employee activities are responded to with the right level of security at the right time. The platform easily scales to provide comprehensive identity based protection across organizations of any size. The company is headquartered in San Francisco, CA. Learn more about us at www.preempt.com.

 

For further information, please contact:
Jacqueline Velasco
Lumina Communications for Preempt
T: 408-680-0564
E: [email protected]

 

SOURCE Preempt


These press releases may also interest you

at 08:50
WiSA Technologies, Inc. , a leading innovator in wireless audio technology for intelligent devices and next-generation home entertainment systems, announced today the signing of a WiSA E licensing agreement with a top-three consumer electronics...

at 08:48
Baseus Technology, a leading global consumer electronics brand, is inviting consumers to join them at the Global Sources Mobile Electronics 2024 event in Hong Kong where they will be unveiling a range of advanced and innovative Baseus technologies...

at 08:48
The Midwest Institute for Nonsurgical Therapy (MINT), a leading provider of minimally invasive medical procedures, is proud to announce the introduction of Prostate Artery Embolization (PAE) for the treatment of Benign Prostatic Hyperplasia (BPH),...

at 08:47
More than three years after establishment, Stramsen Biotech, Inc, is one of the leading plant-based biotech start-up companies in the world. After initial valuation in 2023, it has now officially been valued at $6.5 Billion, according to a...

at 08:46
Not being able to verify the identity of who you are talking to can cost you. The $25M video call deepfake in Hong Kong, the socially engineered ransomware attacks on MGM and the theft of $16M from baseball great Shohei Ohtani are just three recent...

at 08:45
Applied Insight LLC, a cloud and technology services leader in the government market, announced today it has won a sizable and strategic five-year contract to provide artificial intelligence development to an existing U.S. Intelligence Community...



News published on and distributed by: