First-time directory sync of an on-premises domain user to an existing cloud account
Synopsis
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
1 Day
Required Data
AzureAD Audit Log
Detection Modules
Identity Threat Module, SaaS Threat Detection
ATT&CK Tactic
Persistence (TA0003)
ATT&CK Technique
Valid Accounts (T1078)
Severity
Informational
Description
First-time synchronization of an on-premises domain user with an existing cloud account.
Attacker's Goals
Attackers may leverage DirectorySync to move laterally from a compromised on-premise environment into the cloud tenant, allowing them to bypass the cloud's security boundaries and take over high-value cloud identities.
Investigative actions
Check if the cloud account was an administrator (Global Admin, etc.) before this sync.
Determine if the on-premise user was recently created or if its 'proxyAddress' attribute was recently modified.
Confirm if the organization intended to transition this account from Cloud-Only to Hybrid.
Verify the consistency between the on-premises 'ObjectGUID' and the newly assigned 'ImmutableID' in Azure AD.
Was this helpful?
