GPEN Azure AD Integration Practice Question
When analyzing a hybrid identity environment, you notice the use of 'Seamless Single Sign-On'. What is the potential impact if the 'AZUREADSSOACC' computer object in the on-premises Active Directory is compromised?
⚠ Common exam trap
Candidates often confuse this with Golden Ticket attacks on standard domain controllers. They fail to recognize that the AZUREADSSOACC account is a unique object specifically for cloud authentication.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The attacker can generate valid Kerberos tickets to facilitate cloud authentication.
The AZUREADSSOACC object is a computer account created in AD with a Kerberos service principal name. If compromised, an attacker can request Kerberos tickets to impersonate users or potentially extract the decryption key. This allows the attacker to silently authenticate as others to the cloud, bypassing the need for secondary checks, making it a critical pivot point in hybrid identity attacks.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The attacker can directly modify the Microsoft Entra ID tenant settings.
Why it's wrong here
Compromising the SSO computer account does not grant administrative rights to the Microsoft Entra ID tenant. It specifically facilitates the generation of Kerberos tickets for authentication purposes. While dangerous for identity impersonation, it does not provide the direct privilege escalation required to change tenant-wide configuration settings.
- ✓
The attacker can generate valid Kerberos tickets to facilitate cloud authentication.
Why this is correct
Seamless SSO works by providing a Kerberos ticket that Microsoft Entra ID trusts. If the computer object is controlled by an attacker, they can abuse its service key to request and forge tickets for any user account synchronized in the directory, allowing for seamless, unauthorized cloud authentication.
- ✗
The attacker can permanently disable synchronization between on-premises and cloud.
Why it's wrong here
The SSO account is used for authentication, not synchronization. Disabling or tampering with the SSO account will break the single sign-on experience for users, but it does not disable the Microsoft Entra Connect synchronization engine, which runs under a separate, highly privileged service account.
- ✗
All password hash synchronization processes will immediately cease.
Why it's wrong here
Password hash synchronization is independent of the Seamless SSO feature. The sync process relies on the Microsoft Entra Connect synchronization service and its associated permissions. Compromising the SSO object does not interact with the PHS pipeline, meaning credential synchronization will continue functioning as intended.
About these practice questions
Courseiva writes every GPEN question from scratch — 298 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GPEN practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GPEN exam.