During a penetration test, you have gained access to a Microsoft Entra ID tenant with Global Administrator privileges. You want to establish a backdoor that allows you to authenticate as any user in the tenant without knowing their password, even if your Global Administrator account is removed. Which of the following methods would best achieve this?
By modifying the federation settings to trust an attacker-controlled identity provider, you can forge SAML tokens for any user in the tenant. This allows you to authenticate as any user, including Global Administrators, without knowing their passwords. This backdoor persists even if your Global Administrator account is removed, as long as the federation settings remain unchanged. This is a known persistence technique.
Why this answer
Modifying the tenant's federation settings to trust an attacker-controlled identity provider allows the attacker to forge SAML tokens for any user. This backdoor is highly persistent because it survives the removal of the attacker's Global Administrator account. It enables authentication as any user without knowing their password, making it an effective persistence mechanism.
Exam trap
The trap here is focusing on creating or modifying accounts, which are easily removed, while the most persistent backdoor is altering the tenant's trust configuration to enable token forgery.