Courseiva

GPEN · domain

Azure AD Integration

This domain covers attacking and defending hybrid identity in Microsoft Entra ID (Azure AD), including Azure AD Connect synchronization, Pass-Through Authentication, AD FS federation, and token/session abuse. Questions test whether you can trace an on-premises compromise to cloud privilege escalation, choose valid mitigations, and maintain persistence using real Entra ID and Windows identity features.

15 questions10 medium5 hard

Focused practice

Practice Azure AD Integration questions

Scored sessions drawing only from this domain — pick a length below.

What this domain covers

What to know about Azure AD Integration

You must map an on-premises identity compromise to its Entra ID impact by identifying the sync method, sourceAnchor attribute, and authentication path. The most important thing is correctly determining whether credentials, tokens, or federation certificates grant cloud access and persistence.

Azure AD Connect sync methods: password hash sync, Pass-Through Authentication, and federation with AD FS

ms-DS-ConsistencyGuid and ImmutableID mapping for sourceAnchor and cloud identity correlation

Password spray mitigation using Entra ID Password Protection, smart lockout, and Conditional Access

AD FS token signing certificate theft, Golden SAML, and primary refresh token abuse for persistence

Watch out for

Common Azure AD Integration exam traps

  • ▸Assuming any synchronized on-premises user can directly modify cloud-only attributes without directory role or writeback permissions
  • ▸Confusing Pass-Through Authentication with password hash synchronization when assessing credential theft and spray impact
  • ▸Treating AD FS as equivalent to cloud authentication and missing token-signing certificate or Golden SAML persistence paths

Question index

All Azure AD Integration questions (15)

Click any question to see the full explanation, or start a practice session above.

1

During a penetration test, you have gained access to a Microsoft Entra ID tenant with Global Administrator privileges. You want to establish a backdoor that allows you to authenticate as any user in the tenant without knowing their password, even if your Global Administrator account is removed. Which of the following methods would best achieve this?

Hard
2

Which THREE of the following are valid methods to mitigate the risk of password spray attacks in an integrated Azure AD environment?

Hard
3

You are conducting an internal penetration test for a client that uses Microsoft Entra ID (Azure AD) with on-premises Active Directory. You have obtained a low-privileged domain user's credentials. You want to enumerate Entra ID users and groups without triggering sign-in logs on the compromised user. Which of the following techniques would be MOST effective for this goal?

Medium
4

During an assessment, you find that 'Device Writeback' is enabled. What is the security concern regarding the registration of these devices in Azure AD?

Hard
5

During an internal penetration test, an attacker compromises a standard user account in a hybrid Azure AD environment. The organization synchronizes on-premises identities using Azure AD Connect with Pass-Through Authentication enabled. Which technique allows the attacker to compromise additional cloud and on-premises identities without triggering standard cloud MFA prompts?

Medium
6

During an internal penetration test of a hybrid Microsoft Entra ID environment, you compromise a standard on-premises user account. You notice that the account's on-premises userPrincipalName is jdoe@corp.local, but the corresponding cloud account has the userPrincipalName jdoe@corp.com. Which attribute should you modify on-premises to change the cloud sign-in address for this synchronized user?

Medium
7

Which of the following describes the risk of 'Guest User' accounts in an Azure AD integration scenario?

Medium
8

Which of the following is a primary benefit of using Managed Identities for Azure resources?

Medium
9

When analyzing a hybrid identity environment, you notice the use of 'Seamless Single Sign-On'. What is the potential impact if the 'AZUREADSSOACC' computer object in the on-premises Active Directory is compromised?

Hard
10

Why is 'Password Writeback' considered a significant security risk in hybrid identity integrations?

Medium
11

A penetration tester gains Global Administrator privileges in a Microsoft Entra ID tenant and needs to establish persistent access that survives credential resets and standard administrative remediation. Which TWO methods can the tester implement to maintain covert administrative access?

Hard
12

During a penetration test of a Microsoft Entra ID environment, you discover that an on-premises user account has the ms-DS-ConsistencyGuid attribute set to a value that matches the ImmutableID of a cloud user with higher privileges. What is the most likely security implication of this configuration?

Medium
13

You are performing a penetration test on a Microsoft Entra ID tenant that uses federated authentication with Active Directory Federation Services (AD FS). You have obtained a user's credentials and want to maintain persistent access even if the user's password is changed. Which of the following methods would best achieve this?

Medium
14

You are conducting an internal penetration test for a client that uses Microsoft Entra ID with on-premises Active Directory. You have obtained Domain Admin credentials in the on-premises domain. The client has deployed Microsoft Entra Connect with Seamless Single Sign-On (SSO) enabled. Which of the following actions would allow you to authenticate as any synchronized user to cloud services like Microsoft 365 WITHOUT knowing their password?

Medium
15

During an assessment, you discover a federated identity setup using AD FS. What is a common security risk associated with the reliance on the token-signing certificate in this architecture?

Medium

Frequently asked questions

What does the Azure AD Integration domain cover on the GPEN exam?
You must map an on-premises identity compromise to its Entra ID impact by identifying the sync method, sourceAnchor attribute, and authentication path. The most important thing is correctly determining whether credentials, tokens, or federation certificates grant cloud access and persistence.
How many questions are in this domain?
This page lists all 15 Azure AD Integration questions in the GPEN question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
What is the best way to practise this domain?
Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
Can I practise only Azure AD Integration questions?
Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.
giac-gpen GIAC-GPEN azure ad integration Practice Questions