Courseiva
Azure AD Integration →hardMultiple Choice

GPEN Azure AD Integration Practice Question

When analyzing a hybrid identity environment, you notice the use of 'Seamless Single Sign-On'. What is the potential impact if the 'AZUREADSSOACC' computer object in the on-premises Active Directory is compromised?

⚠ Common exam trap

Candidates often confuse this with Golden Ticket attacks on standard domain controllers. They fail to recognize that the AZUREADSSOACC account is a unique object specifically for cloud authentication.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The attacker can generate valid Kerberos tickets to facilitate cloud authentication.

The AZUREADSSOACC object is a computer account created in AD with a Kerberos service principal name. If compromised, an attacker can request Kerberos tickets to impersonate users or potentially extract the decryption key. This allows the attacker to silently authenticate as others to the cloud, bypassing the need for secondary checks, making it a critical pivot point in hybrid identity attacks.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The attacker can directly modify the Microsoft Entra ID tenant settings.

    Why it's wrong here

    Compromising the SSO computer account does not grant administrative rights to the Microsoft Entra ID tenant. It specifically facilitates the generation of Kerberos tickets for authentication purposes. While dangerous for identity impersonation, it does not provide the direct privilege escalation required to change tenant-wide configuration settings.

  • ✓

    The attacker can generate valid Kerberos tickets to facilitate cloud authentication.

    Why this is correct

    Seamless SSO works by providing a Kerberos ticket that Microsoft Entra ID trusts. If the computer object is controlled by an attacker, they can abuse its service key to request and forge tickets for any user account synchronized in the directory, allowing for seamless, unauthorized cloud authentication.

  • ✗

    The attacker can permanently disable synchronization between on-premises and cloud.

    Why it's wrong here

    The SSO account is used for authentication, not synchronization. Disabling or tampering with the SSO account will break the single sign-on experience for users, but it does not disable the Microsoft Entra Connect synchronization engine, which runs under a separate, highly privileged service account.

  • ✗

    All password hash synchronization processes will immediately cease.

    Why it's wrong here

    Password hash synchronization is independent of the Seamless SSO feature. The sync process relies on the Microsoft Entra Connect synchronization service and its associated permissions. Compromising the SSO object does not interact with the PHS pipeline, meaning credential synchronization will continue functioning as intended.

About these practice questions

Courseiva writes every GPEN question from scratch — 298 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GPEN practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GPEN exam.