Courseiva

CCNA Azure Ad Integration Questions

15 questions · Azure Ad Integration topic · All types, answers revealed

1
MCQhard

During a penetration test, you have gained access to a Microsoft Entra ID tenant with Global Administrator privileges. You want to establish a backdoor that allows you to authenticate as any user in the tenant without knowing their password, even if your Global Administrator account is removed. Which of the following methods would best achieve this?

A.Assign the 'Company Administrator' role to a service principal.
B.Create a new user account with the same privileges as a Global Administrator.
C.Add a new credential to an existing application with high privileges.
D.Modify the tenant's federation settings to point to an attacker-controlled identity provider.
AnswerD

By modifying the federation settings to trust an attacker-controlled identity provider, you can forge SAML tokens for any user in the tenant. This allows you to authenticate as any user, including Global Administrators, without knowing their passwords. This backdoor persists even if your Global Administrator account is removed, as long as the federation settings remain unchanged. This is a known persistence technique.

Why this answer

Modifying the tenant's federation settings to trust an attacker-controlled identity provider allows the attacker to forge SAML tokens for any user. This backdoor is highly persistent because it survives the removal of the attacker's Global Administrator account. It enables authentication as any user without knowing their password, making it an effective persistence mechanism.

Exam trap

The trap here is focusing on creating or modifying accounts, which are easily removed, while the most persistent backdoor is altering the tenant's trust configuration to enable token forgery.

2
Multi-Selecthard

Which THREE of the following are valid methods to mitigate the risk of password spray attacks in an integrated Azure AD environment?

Select 3 answers
A.Enforce Multi-Factor Authentication for all users.
B.Disable all legacy authentication protocols.
C.Implement Identity Protection to detect and block risky sign-ins.
D.Increase the minimum password length to 50 characters.
E.Require all users to use the same password for both on-premises and cloud.
AnswersA, B, C

MFA is the most effective control against password spraying. Even if an attacker guesses the password, the secondary factor prevents them from gaining access. It neutralizes the utility of the guessed credential, forcing the attacker to find another way to circumvent the authentication process entirely.

Why this answer

Password spray attacks target common passwords across many accounts. Protecting against this requires a layered approach: enforcing MFA to render weak passwords useless, blocking legacy authentication to prevent bypasses, and utilizing identity protection to detect anomalous logins. These controls are essential for modernizing identity security and protecting against high-volume, low-effort credential attacks that plague hybrid environments.

Exam trap

Candidates often select controls like self-service password reset or password complexity rules, which fail to specifically address password spray attacks targeting multiple accounts with common passwords.

3
MCQmedium

You are conducting an internal penetration test for a client that uses Microsoft Entra ID (Azure AD) with on-premises Active Directory. You have obtained a low-privileged domain user's credentials. You want to enumerate Entra ID users and groups without triggering sign-in logs on the compromised user. Which of the following techniques would be MOST effective for this goal?

A.Authenticate to Microsoft Graph with the compromised user's credentials and enumerate users and groups.
B.Use the Azure AD Connect synchronization account to query the Microsoft Graph API.
C.Use the Microsoft Entra admin center with the compromised user's credentials to browse users and groups.
D.Query the on-premises Active Directory for objects synchronized to Entra ID using the user's existing domain access.
AnswerD

Querying on-premises AD uses the user's existing domain authentication, which does not create Entra ID sign-in logs. Since synchronized objects exist in both directories, enumerating on-premises AD can reveal a significant portion of Entra ID users and groups without touching the cloud identity provider, achieving stealth.

Why this answer

The objective is to enumerate Entra ID objects without creating sign-in logs on the compromised user. Querying on-premises Active Directory leverages the existing domain session and does not generate cloud authentication events. This method can reveal synchronized users and groups, providing valuable intelligence while maintaining operational security.

Exam trap

The trap here is assuming that any cloud enumeration requires authenticating to Entra ID, overlooking that synchronized on-premises objects can be enumerated locally without generating cloud logs.

4
MCQhard

During an assessment, you find that 'Device Writeback' is enabled. What is the security concern regarding the registration of these devices in Azure AD?

A.It allows the cloud to push malware to on-premises devices.
B.It allows untrusted devices to satisfy Conditional Access requirements.
C.It automatically grants the devices administrative access to the cloud tenant.
D.It requires all devices to be hardware-encrypted with TPM 2.0.
AnswerB

Devices synced to Azure AD are marked as 'known' or 'compliant' depending on the policy. If an attacker joins a rogue device to the on-premises domain, it gets synced to the cloud. This device may then be treated as trusted, bypassing security controls that require a 'compliant' or 'managed' device.

Why this answer

Device Writeback registers on-premises devices in Azure AD. If an attacker manages to join an unauthorized device to the domain, it is automatically synchronized to the cloud. Once in the cloud, this device might satisfy Conditional Access requirements, allowing an attacker to bypass device-based security controls.

This expands the trusted device pool, which is a major security loophole if device registration is not tightly controlled.

Exam trap

Candidates often assume 'Device Writeback' is purely a management feature for device inventory. They miss the security implication that trusted status is automatically granted to synchronized on-premises devices.

5
MCQmedium

During an internal penetration test, an attacker compromises a standard user account in a hybrid Azure AD environment. The organization synchronizes on-premises identities using Azure AD Connect with Pass-Through Authentication enabled. Which technique allows the attacker to compromise additional cloud and on-premises identities without triggering standard cloud MFA prompts?

A.Injecting malicious golden tickets into Azure AD Connect sync engine database tables to forge valid cloud security tokens.
B.Exploiting seamless single sign-on kerberos ticket requests to harvest master keys directly from the Azure AD service bus.
C.Abusing compromised credentials against legacy authentication endpoints or poorly secured client applications that bypass modern conditional access and MFA controls.
D.Modifying the cloud synchronization agent configuration file to downgrade password hashing algorithms from PBKDF2 to plain text.
AnswerC

Pass-through authentication relies on valid directory credentials. When attackers capture these credentials, they often target legacy protocols like POP3, IMAP, or SMTP which traditionally do not enforce modern conditional access policies or multi-factor authentication challenges.

Why this answer

Pass-Through Authentication validates user credentials directly against the on-premises Active Directory by passing the raw credentials through the authentication agent. When an attacker compromises an active session or abuses legacy authentication protocols that bypass conditional access and multi-factor authentication requirements, they can pivot between cloud and on-premises domains seamlessly without triggering supplementary challenges.

Exam trap

Candidates often assume cloud-based conditional access policies automatically intercept all on-premises authentication flows, forgetting that legacy protocols or poorly configured authentication agents can bypass modern multi-factor verification entirely.

6
MCQmedium

During an internal penetration test of a hybrid Microsoft Entra ID environment, you compromise a standard on-premises user account. You notice that the account's on-premises userPrincipalName is jdoe@corp.local, but the corresponding cloud account has the userPrincipalName jdoe@corp.com. Which attribute should you modify on-premises to change the cloud sign-in address for this synchronized user?

A.sAMAccountName
B.proxyAddresses
C.mail
D.userPrincipalName
AnswerD

The userPrincipalName attribute in the on-premises directory is synchronized to Microsoft Entra ID as the user's sign-in name, provided the domain is verified. Changing it to match the desired cloud UPN (e.g., jdoe@corp.com) will update the cloud userPrincipalName after synchronization. This is the correct attribute to modify to control the cloud sign-in address.

Why this answer

In a hybrid Microsoft Entra ID environment, the on-premises userPrincipalName attribute is synchronized to the cloud as the user's sign-in name, provided the domain is verified. Changing this attribute to the desired cloud UPN will update the cloud sign-in address after synchronization. Other attributes like proxyAddresses, mail, and sAMAccountName do not control the cloud UPN.

Exam trap

The trap here is confusing the mail attribute or proxyAddresses with the userPrincipalName, assuming that email-related attributes control the cloud sign-in address.

7
MCQmedium

Which of the following describes the risk of 'Guest User' accounts in an Azure AD integration scenario?

A.Guest users are automatically granted Global Administrator privileges.
B.Guest accounts can only be created by the Global Administrator.
C.Guest users can potentially enumerate directory objects unless restricted.
D.Guest users are exempt from Conditional Access policies.
AnswerC

By default, guest users can read directory information, including the list of users, groups, and applications. Restricting these permissions via the 'External Collaboration Settings' in Azure AD is a mandatory hardening step to ensure that external entities cannot perform reconnaissance on the internal directory structure.

Why this answer

Guest accounts in Azure AD often have default permissions that allow them to enumerate directory objects. If these guests are not properly scoped using 'External Collaboration Settings', an attacker can use a compromised guest account to map the internal organizational structure, identify high-value targets, and find misconfigured applications. This reconnaissance is often the first step in a broader, more successful targeted attack against the internal environment.

Exam trap

Candidates often assume that guest accounts are harmless because they have 'limited' access. They fail to realize that the default directory enumeration permissions can leak sensitive information about the entire organization.

8
MCQmedium

Which of the following is a primary benefit of using Managed Identities for Azure resources?

A.It allows the resource to access any other resource in the tenant by default.
B.It removes the need to store and manage credentials in application code.
C.It provides a mechanism to impersonate any user in the directory.
D.It bypasses the need for MFA when accessing sensitive databases.
AnswerB

By using a managed identity, the application uses the platform's identity to authenticate. The platform manages the secret rotation, and the application never sees or handles the credentials. This prevents common vulnerabilities related to credential exposure, such as hardcoding secrets in source control or configuration files.

Why this answer

Managed Identities eliminate the need for developers to manage credentials (like service principal secrets) within their application code. By having Azure handle the identity, the risk of credential leakage via hardcoded strings or insecure configuration files is virtually eliminated. This is a critical security improvement for cloud-native applications, as it relies on the platform to rotate secrets automatically and securely.

Exam trap

Test-takers often select options related to improving network speed or bypassing firewall restrictions, misunderstanding that managed identities solve credential management and storage challenges.

9
MCQhard

When analyzing a hybrid identity environment, you notice the use of 'Seamless Single Sign-On'. What is the potential impact if the 'AZUREADSSOACC' computer object in the on-premises Active Directory is compromised?

A.The attacker can directly modify the Azure AD tenant settings.
B.The attacker can generate valid Kerberos tickets to facilitate cloud authentication.
C.The attacker can permanently disable synchronization between on-premises and cloud.
D.All password hash synchronization processes will immediately cease.
AnswerB

Seamless SSO works by providing a Kerberos ticket that Azure AD trusts. If the computer object is controlled by an attacker, they can abuse its service key to request and forge tickets for any user account synchronized in the directory, allowing for seamless, unauthorized cloud authentication.

Why this answer

The AZUREADSSOACC object is a computer account created in AD with a Kerberos service principal name. If compromised, an attacker can request Kerberos tickets to impersonate users or potentially extract the decryption key. This allows the attacker to silently authenticate as others to the cloud, bypassing the need for secondary checks, making it a critical pivot point in hybrid identity attacks.

Exam trap

Candidates often confuse this with Golden Ticket attacks on standard domain controllers. They fail to recognize that the AZUREADSSOACC account is a unique object specifically for cloud authentication.

10
MCQmedium

Why is 'Password Writeback' considered a significant security risk in hybrid identity integrations?

A.It stores plaintext passwords on the Azure AD Connect server.
B.It allows cloud-based compromise to escalate into the on-premises domain.
C.It requires the on-premises firewall to allow inbound connections from the internet.
D.It automatically disables the on-premises password policy.
AnswerB

By allowing the cloud to set on-premises passwords, the trust boundary is reversed. An attacker who compromises a high-privileged account in Azure AD can use the writeback feature to reset passwords for Domain Admins or other sensitive accounts, granting them full control over the on-premises infrastructure.

Why this answer

Password Writeback enables the cloud to update passwords on-premises. While convenient, it creates a bidirectional path. If an attacker gains control of a cloud-based administrator account, they can reset the password of any on-premises user, including sensitive accounts.

This effectively elevates the cloud's influence over the on-premises environment, turning a cloud-only compromise into a full-scale domain-wide security disaster.

Exam trap

Test-takers frequently confuse Password Writeback with single sign-on or directory synchronization benefits, overlooking the critical bidirectional security risk of cloud-to-on-premises escalation.

11
Multi-Selecthard

A penetration tester gains Global Administrator privileges in a Microsoft Entra ID tenant and needs to establish persistent access that survives credential resets and standard administrative remediation. Which TWO methods can the tester implement to maintain covert administrative access?

Select 2 answers
A.Creating a new custom user account with an elevated administrative role and a static password that never expires.
B.Registering a new multi-tenant application with Graph API application permissions such as Directory.AccessAsUser.All or RoleManagement.ReadWrite.Directory.
C.Configuring a rogue external federation trust using custom token-signing certificates to forge arbitrary user and administrator identity assertions.
D.Injecting unauthorized security group membership changes directly into the on-premises Active Directory synchronized container.
E.Enabling device registration writeback to push malicious device objects from the cloud directory into local organizational units.
AnswersB, C

Application registrations with high-privilege Microsoft Graph API permissions operate independently of individual user accounts. They allow an external or internal actor to query directory objects, modify roles, and generate fresh access tokens without requiring user logins.

Why this answer

Persistent access in Microsoft Entra ID often relies on abusing application permissions and service principals rather than traditional user accounts. By creating a malicious application registration with high-privilege Microsoft Graph API permissions or injecting a rogue federated domain trust, an attacker ensures long-term access that remains unaffected by standard user password resets or typical admin auditing.

Exam trap

Many candidates mistakenly select user-level persistence techniques like creating shadow user accounts, which are easily flagged by standard Microsoft Entra ID protection alerts and quickly remediated during routine account audits.

12
MCQmedium

During a penetration test of a Microsoft Entra ID environment, you discover that an on-premises user account has the ms-DS-ConsistencyGuid attribute set to a value that matches the ImmutableID of a cloud user with higher privileges. What is the most likely security implication of this configuration?

A.It allows the on-premises user to reset the privileged user's password.
B.It enables password hash synchronization for the privileged user.
C.It causes a synchronization error that prevents the user from logging in.
D.It allows the on-premises user to authenticate to the cloud as the privileged user.
AnswerD

The ms-DS-ConsistencyGuid is used as the source anchor for synchronization. If it matches the ImmutableID of a privileged cloud user, the on-premises user will be linked to that cloud account during synchronization, effectively allowing the on-premises user to take over the cloud identity and authenticate as the privileged user. This is a severe privilege escalation vulnerability.

Why this answer

The ms-DS-ConsistencyGuid attribute is used as the source anchor when Microsoft Entra Connect is configured to use it. If an attacker can modify this attribute on an on-premises user to match the ImmutableID of a privileged cloud user, the next synchronization will link the on-premises account to the cloud account. The attacker can then authenticate to the cloud as the privileged user, achieving privilege escalation.

Exam trap

The trap here is assuming that the ms-DS-ConsistencyGuid is just a random identifier and not recognizing its role as the source anchor that can be manipulated to link accounts.

13
MCQmedium

You are performing a penetration test on a Microsoft Entra ID tenant that uses federated authentication with Active Directory Federation Services (AD FS). You have obtained a user's credentials and want to maintain persistent access even if the user's password is changed. Which of the following methods would best achieve this?

A.Configure an Azure AD application with a client secret and assign it the 'Directory.Read.All' permission.
B.Create a new user account in Entra ID with Global Administrator privileges.
C.Forge a SAML token using the AD FS token-signing certificate.
D.Register a new device in Entra ID and use it to obtain a Primary Refresh Token (PRT).
AnswerC

In a federated environment, the AD FS token-signing certificate is used to sign SAML tokens. If an attacker can export this certificate's private key (e.g., from the AD FS server), they can forge SAML tokens for any user, including Global Administrators. These tokens are accepted by Entra ID as valid authentication, allowing persistent access regardless of password changes. This is a powerful persistence technique.

Why this answer

In AD FS federated environments, the token-signing certificate is the root of trust. If an attacker compromises the AD FS server and exports the token-signing certificate's private key, they can forge SAML tokens for any user. These tokens are accepted by Entra ID, providing persistent access even after password changes.

This is a critical persistence technique in federated identity setups.

Exam trap

The trap here is focusing on user-level persistence methods like device registration or app creation, while the most powerful persistence in federated environments is compromising the token-signing certificate.

14
MCQmedium

You are conducting an internal penetration test for a client that uses Microsoft Entra ID with on-premises Active Directory. You have obtained Domain Admin credentials in the on-premises domain. The client has deployed Microsoft Entra Connect with Seamless Single Sign-On (SSO) enabled. Which of the following actions would allow you to authenticate as any synchronized user to cloud services like Microsoft 365 WITHOUT knowing their password?

A.Extract the AZUREADSSOACC computer account password hash from the on-premises Active Directory and forge Kerberos service tickets for the cloud service principal.
B.Retrieve the on-premises user's password hash from the domain controller and use it to authenticate to Microsoft Entra ID via password hash synchronization.
C.Leverage the Seamless SSO computer account to perform a Silver Ticket attack against the on-premises domain controller and then access cloud resources.
D.Use the Directory Synchronization Account credentials to modify the source anchor attribute of a targeted user to point to a new on-premises object.
AnswerA

The AZUREADSSOACC computer account is created in on-premises Active Directory when Seamless SSO is configured. Its password hash is used to sign Kerberos tickets for the Azure AD service principal. With Domain Admin rights, an attacker can extract this hash and forge service tickets, allowing authentication as any synchronized user without their password. This is a known attack path in hybrid identity environments.

Why this answer

With Domain Admin privileges, an attacker can extract the password hash of the AZUREADSSOACC computer account, which is used for Seamless Single Sign-On. This hash allows forging Kerberos service tickets for the Azure AD service principal, enabling authentication as any synchronized user without their password. This is a critical risk in hybrid identity configurations where Seamless SSO is enabled.

Exam trap

The trap here is assuming that password hash synchronization or directory synchronization account compromise directly allows cloud authentication, when actually Seamless SSO's AZUREADSSOACC account is the key target.

15
MCQmedium

During an assessment, you discover a federated identity setup using AD FS. What is a common security risk associated with the reliance on the token-signing certificate in this architecture?

A.The certificate is public knowledge and can be used to decrypt all cloud traffic.
B.Compromise of the private signing key allows for the creation of unauthorized authentication tokens.
C.AD FS requires the certificate to be stored in an unsecured plaintext file on the web server.
D.The relying party cannot verify the identity if the certificate expires.
AnswerB

If the private key is exposed, an attacker can sign fraudulent SAML assertions. These assertions are trusted by Azure AD as valid identity claims, effectively allowing the attacker to sign in as any user without needing their password or passing the actual identity provider's authentication checks.

Why this answer

The token-signing certificate is the foundation of trust in a federated environment. If an attacker compromises the private key of this certificate, they can forge SAML tokens for any user in the directory. This bypasses Multi-Factor Authentication and allows for complete identity impersonation, making the protection of the AD FS server and its associated secrets a critical objective for both defenders and attackers.

Exam trap

Candidates often think about password cracking or brute force. They overlook that the signing certificate is the 'root of trust' for federated identities, making it the most critical target.

Ready to test yourself?

Try a timed practice session using only Azure Ad Integration questions.