GPEN Azure AD Integration Practice Question
A penetration tester gains Global Administrator privileges in a Microsoft Entra ID tenant and needs to establish persistent access that survives credential resets and standard administrative remediation. Which TWO methods can the tester implement to maintain covert administrative access?
⚠ Common exam trap
Many candidates mistakenly select user-level persistence techniques like creating shadow user accounts, which are easily flagged by standard Microsoft Entra ID protection alerts and quickly remediated during routine account audits.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Registering a new multi-tenant application with Graph API application permissions such as Directory.AccessAsUser.All or RoleManagement.ReadWrite.Directory.
Persistent access in Microsoft Entra ID often relies on abusing application permissions and service principals rather than traditional user accounts. By creating a malicious application registration with high-privilege Microsoft Graph API permissions or injecting a rogue federated domain trust, an attacker ensures long-term access that remains unaffected by standard user password resets or typical admin auditing.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Creating a new custom user account with an elevated administrative role and a static password that never expires.
Why it's wrong here
A new account with a static password is visible in the directory and removable by any Global Administrator, so it fails the persistence requirement. It is tempting because standalone credentials do survive password resets of existing users, but covert persistence needs objects such as service principals or federated credentials that standard remediation overlooks.
- ✓
Registering a new multi-tenant application with Graph API application permissions such as Directory.AccessAsUser.All or RoleManagement.ReadWrite.Directory.
Why this is correct
Application registrations with high-privilege Microsoft Graph API permissions operate independently of individual user accounts. They allow an external or internal actor to query directory objects, modify roles, and generate fresh access tokens without requiring user logins.
- ✓
Configuring a rogue external federation trust using custom token-signing certificates to forge arbitrary user and administrator identity assertions.
Why this is correct
Establishing an unauthorized domain federation trust allows an attacker to issue self-signed SAML tokens claiming administrative identity attributes. Microsoft Entra ID trusts these cryptographic assertions, granting complete administrative control over the tenant without valid user passwords.
- ✗
Injecting unauthorized security group membership changes directly into the on-premises Active Directory synchronized container.
Why it's wrong here
While modifying on-premises AD groups affects hybrid tenants, it is an on-premises persistence vector rather than a native cloud persistence mechanism. Cloud-only administrative actions and conditional access policies can still block access if properly isolated.
- ✗
Enabling device registration writeback to push malicious device objects from the cloud directory into local organizational units.
Why it's wrong here
Device registration writeback is designed to support hybrid conditional access by syncing cloud device states to local Active Directory. It does not provide direct administrative persistence or allow an attacker to bypass cloud security monitoring controls.
About these practice questions
This GPEN question is part of Courseiva's 298-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GPEN practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GPEN exam.