GPEN · domain
Azure AD Integration
This domain covers attacking and defending hybrid identity in Microsoft Entra ID (Azure AD), including Azure AD Connect synchronization, Pass-Through Authentication, AD FS federation, and token/session abuse. Questions test whether you can trace an on-premises compromise to cloud privilege escalation, choose valid mitigations, and maintain persistence using real Entra ID and Windows identity features.
Focused practice
Practice Azure AD Integration questions
Scored sessions drawing only from this domain — pick a length below.
What this domain covers
What to know about Azure AD Integration
You must map an on-premises identity compromise to its Entra ID impact by identifying the sync method, sourceAnchor attribute, and authentication path. The most important thing is correctly determining whether credentials, tokens, or federation certificates grant cloud access and persistence.
Azure AD Connect sync methods: password hash sync, Pass-Through Authentication, and federation with AD FS
ms-DS-ConsistencyGuid and ImmutableID mapping for sourceAnchor and cloud identity correlation
Password spray mitigation using Entra ID Password Protection, smart lockout, and Conditional Access
AD FS token signing certificate theft, Golden SAML, and primary refresh token abuse for persistence
Watch out for
Common Azure AD Integration exam traps
- ▸Assuming any synchronized on-premises user can directly modify cloud-only attributes without directory role or writeback permissions
- ▸Confusing Pass-Through Authentication with password hash synchronization when assessing credential theft and spray impact
- ▸Treating AD FS as equivalent to cloud authentication and missing token-signing certificate or Golden SAML persistence paths
Question index
All Azure AD Integration questions (15)
Click any question to see the full explanation, or start a practice session above.
During a penetration test, you have gained access to a Microsoft Entra ID tenant with Global Administrator privileges. You want to establish a backdoor that allows you to authenticate as any user in the tenant without knowing their password, even if your Global Administrator account is removed. Which of the following methods would best achieve this?
Hard2Which THREE of the following are valid methods to mitigate the risk of password spray attacks in an integrated Azure AD environment?
Hard3You are conducting an internal penetration test for a client that uses Microsoft Entra ID (Azure AD) with on-premises Active Directory. You have obtained a low-privileged domain user's credentials. You want to enumerate Entra ID users and groups without triggering sign-in logs on the compromised user. Which of the following techniques would be MOST effective for this goal?
Medium4During an assessment, you find that 'Device Writeback' is enabled. What is the security concern regarding the registration of these devices in Azure AD?
Hard5During an internal penetration test, an attacker compromises a standard user account in a hybrid Azure AD environment. The organization synchronizes on-premises identities using Azure AD Connect with Pass-Through Authentication enabled. Which technique allows the attacker to compromise additional cloud and on-premises identities without triggering standard cloud MFA prompts?
Medium6During an internal penetration test of a hybrid Microsoft Entra ID environment, you compromise a standard on-premises user account. You notice that the account's on-premises userPrincipalName is jdoe@corp.local, but the corresponding cloud account has the userPrincipalName jdoe@corp.com. Which attribute should you modify on-premises to change the cloud sign-in address for this synchronized user?
Medium7Which of the following describes the risk of 'Guest User' accounts in an Azure AD integration scenario?
Medium8Which of the following is a primary benefit of using Managed Identities for Azure resources?
Medium9When analyzing a hybrid identity environment, you notice the use of 'Seamless Single Sign-On'. What is the potential impact if the 'AZUREADSSOACC' computer object in the on-premises Active Directory is compromised?
Hard10Why is 'Password Writeback' considered a significant security risk in hybrid identity integrations?
Medium11A penetration tester gains Global Administrator privileges in a Microsoft Entra ID tenant and needs to establish persistent access that survives credential resets and standard administrative remediation. Which TWO methods can the tester implement to maintain covert administrative access?
Hard12During a penetration test of a Microsoft Entra ID environment, you discover that an on-premises user account has the ms-DS-ConsistencyGuid attribute set to a value that matches the ImmutableID of a cloud user with higher privileges. What is the most likely security implication of this configuration?
Medium13You are performing a penetration test on a Microsoft Entra ID tenant that uses federated authentication with Active Directory Federation Services (AD FS). You have obtained a user's credentials and want to maintain persistent access even if the user's password is changed. Which of the following methods would best achieve this?
Medium14You are conducting an internal penetration test for a client that uses Microsoft Entra ID with on-premises Active Directory. You have obtained Domain Admin credentials in the on-premises domain. The client has deployed Microsoft Entra Connect with Seamless Single Sign-On (SSO) enabled. Which of the following actions would allow you to authenticate as any synchronized user to cloud services like Microsoft 365 WITHOUT knowing their password?
Medium15During an assessment, you discover a federated identity setup using AD FS. What is a common security risk associated with the reliance on the token-signing certificate in this architecture?
MediumOther domains
All GPEN exam domains
Frequently asked questions
- What does the Azure AD Integration domain cover on the GPEN exam?
- You must map an on-premises identity compromise to its Entra ID impact by identifying the sync method, sourceAnchor attribute, and authentication path. The most important thing is correctly determining whether credentials, tokens, or federation certificates grant cloud access and persistence.
- How many questions are in this domain?
- This page lists all 15 Azure AD Integration questions in the GPEN question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
- What is the best way to practise this domain?
- Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
- Can I practise only Azure AD Integration questions?
- Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.