Courseiva
Azure AD Integration →hardMultiple Choice

GPEN Azure AD Integration Practice Question

During a penetration test, you have gained access to a Microsoft Entra ID tenant with Global Administrator privileges. You want to establish a backdoor that allows you to authenticate as any user in the tenant without knowing their password, even if your Global Administrator account is removed. Which of the following methods would best achieve this?

⚠ Common exam trap

The trap here is focusing on creating or modifying accounts, which are easily removed, while the most persistent backdoor is altering the tenant's trust configuration to enable token forgery.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Modify the tenant's federation settings to point to an attacker-controlled identity provider.

Modifying the tenant's federation settings to trust an attacker-controlled identity provider allows the attacker to forge SAML tokens for any user. This backdoor is highly persistent because it survives the removal of the attacker's Global Administrator account. It enables authentication as any user without knowing their password, making it an effective persistence mechanism.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Assign the 'Company Administrator' role to a service principal.

    Why it's wrong here

    The 'Company Administrator' role is a deprecated role equivalent to Global Administrator. Assigning it to a service principal grants the service principal Global Administrator privileges, but it does not allow impersonation of arbitrary users. It is also a detectable and less stealthy method compared to modifying federation settings.

  • ✗

    Create a new user account with the same privileges as a Global Administrator.

    Why it's wrong here

    Creating a new user account with Global Administrator privileges provides a backdoor account, but it does not allow you to authenticate as any existing user. Additionally, this account can be easily detected and removed. The goal is to impersonate any user, not just have a separate privileged account.

  • ✗

    Add a new credential to an existing application with high privileges.

    Why it's wrong here

    Adding a credential to an existing application can provide persistent access, but it does not allow you to authenticate as any user. It only grants access as the application itself, which may have limited permissions. To authenticate as any user, you need a method that can impersonate users, such as modifying the federation configuration.

  • ✓

    Modify the tenant's federation settings to point to an attacker-controlled identity provider.

    Why this is correct

    By modifying the federation settings to trust an attacker-controlled identity provider, you can forge SAML tokens for any user in the tenant. This allows you to authenticate as any user, including Global Administrators, without knowing their passwords. This backdoor persists even if your Global Administrator account is removed, as long as the federation settings remain unchanged. This is a known persistence technique.

About these practice questions

One of 298 original GPEN practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GPEN practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GPEN exam.