Courseiva
Azure AD Integration →mediumMultiple Choice

GPEN Azure AD Integration Practice Question

You are conducting an internal penetration test for a client that uses Microsoft Entra ID with on-premises Active Directory. You have obtained Domain Admin credentials in the on-premises domain. The client has deployed Microsoft Entra Connect with Seamless Single Sign-On (SSO) enabled. Which of the following actions would allow you to authenticate as any synchronized user to cloud services like Microsoft 365 WITHOUT knowing their password?

⚠ Common exam trap

The trap here is assuming that password hash synchronization or directory synchronization account compromise directly allows cloud authentication, when actually Seamless SSO's AZUREADSSOACC account is the key target.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Extract the AZUREADSSOACC computer account password hash from the on-premises Active Directory and forge Kerberos service tickets for the cloud service principal.

With Domain Admin privileges, an attacker can extract the password hash of the AZUREADSSOACC computer account, which is used for Seamless Single Sign-On. This hash allows forging Kerberos service tickets for the Microsoft Entra ID service principal, enabling authentication as any synchronized user without their password. This is a critical risk in hybrid identity configurations where Seamless SSO is enabled.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Extract the AZUREADSSOACC computer account password hash from the on-premises Active Directory and forge Kerberos service tickets for the cloud service principal.

    Why this is correct

    The AZUREADSSOACC computer account is created in on-premises Active Directory when Seamless SSO is configured. Its password hash is used to sign Kerberos tickets for the Microsoft Entra ID service principal. With Domain Admin rights, an attacker can extract this hash and forge service tickets, allowing authentication as any synchronized user without their password. This is a known attack path in hybrid identity environments.

  • ✗

    Retrieve the on-premises user's password hash from the domain controller and use it to authenticate to Microsoft Entra ID via password hash synchronization.

    Why it's wrong here

    Password hash synchronization synchronizes a hash of the user's on-premises password hash to Microsoft Entra ID, but it does not allow pass-the-hash attacks directly against Entra ID. The synchronized hash is further processed and cannot be used to authenticate as the user in the cloud without knowing the original password. This method does not provide a way to authenticate as any user without their password.

  • ✗

    Leverage the Seamless SSO computer account to perform a Silver Ticket attack against the on-premises domain controller and then access cloud resources.

    Why it's wrong here

    A Silver Ticket attack involves forging a Kerberos service ticket for a specific service using the service account's password hash. While the AZUREADSSOACC account is a computer account, a Silver Ticket for on-premises services would not directly grant access to cloud services. The attack must target the Microsoft Entra ID service principal specifically, not the domain controller, to achieve cloud authentication.

  • ✗

    Use the Directory Synchronization Account credentials to modify the source anchor attribute of a targeted user to point to a new on-premises object.

    Why it's wrong here

    The Directory Synchronization Account is used by Microsoft Entra Connect to read and write directory data. While modifying the source anchor could cause synchronization issues or potentially allow account takeover if an attacker controls the new object, it does not directly provide a method to authenticate as any synchronized user without a password. It requires additional steps and may not work if the source anchor is immutable.

Visual reference

Client Server SYN (seq=100) SYN-ACK (seq=200, ack=101) ACK (ack=201) Connection established — data transfer begins

About these practice questions

One of 298 original GPEN practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GPEN practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GPEN exam.