The Tool Desk
Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →Microsoft Threat Intelligence reported that attackers it linked to Iran used a privileged Azure AD Connect server to move from an on-premises environment into Azure AD, then deleted major cloud resources. The incident shows how excessive privileges on a synchronization account can turn a compromise of hybrid identity infrastructure into a cloud outage.
What Microsoft reported—and who it attributed the activity to
In an incident analysis published April 7, 2023, Microsoft Threat Intelligence attributed the destructive operation to MERCURY, which it linked to the Iranian government, and assessed that DEV-1084 likely worked in partnership. In Microsoft’s April 2023 naming update, those names map to Mango Sandstorm and Storm-1084, respectively. These are Microsoft’s attributions and assessments about this observed campaign, not evidence that all Iranian-linked groups use the same methods.
Microsoft said the activity affected both on-premises and cloud environments. Its account describes a sequence in which the attackers compromised privileged access, obtained credentials from the Azure AD Connect host, and used those credentials to reach Azure AD. The destructive cloud actions and the separate mailbox abuse followed that pivot.
How did the attackers get from on-premises Active Directory into Azure AD?
They gained access to the synchronization host
Microsoft said the attackers accessed the device running Azure AD Connect with a compromised privileged account. Microsoft assessed with high confidence that they used AADInternals to extract plaintext credentials from the synchronization host, including credentials associated with the Azure AD Connector account and the AD DS Connector account. They then used the credentials to pivot from the on-premises environment to Azure AD.
Quick wins for a faster PC:
Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Clear out junk files and repair common Windows errorsFree Scan →#1 Best Overall
- Available with the Cloud Labs which provide a hands-on, immersive mock IT infrastructure enabling students to test their skills with realistic security scenarios
- New Chapter on detailing network topologies
- The Table of Contents has been fully restructured to offer a more logical sequencing of subject matter
- Introduces the basics of network security—exploring the details of firewall security and how VPNs operate
- Increased coverage on device implantation and configuration
Microsoft said the initial access to the Azure AD Connect device occurred two weeks before ransomware deployment. The report does not establish that every Azure AD Connect compromise exposes cloud credentials; it describes the access and credential extraction Microsoft assessed in this incident.
The connector account had more cloud privilege than it needed
In this victim environment, the Azure AD Connector account had Global Administrator permissions because it had been set up for an older DirSync solution. It was also configured for single-factor authentication. Microsoft Threat Intelligence wrote: “The Azure AD Connector account is configured with single-factor authentication, making it easier for the attacker to gain entry and elevate privileges.” That statement refers to the account in this reported incident, not to connector accounts generally.
Rank #2
- equipped with atom n2600 d2700 processor, compatible with many freebsd based router systems, linux distros, or win.os supported, easy configuration and management
- Please note, this is a barebone only. A system memory, a storage drive and an operating system are needed to complete this system
- 13-19 inches 1u, 50w power, with power cord, make sure to use a big brand memory and ssd/hdd with quality assurance
- Designed with console, 2 x usb, 4 x lan, vga, power switch, size at 290 x 180 x 44mm
- There are 2 inside reserved fans on chassis, which could be removed freely or be turned on in a high temperature environment to ensure the best function of the product
What happened after the cloud pivot?
Attackers deleted Azure resources
On the day of the destructive cloud activity, Microsoft observed the actors claim Global Administrator permissions through Privileged Identity Management and elevate access to management groups and subscriptions. Within a few hours, they deleted server farms, virtual machines, storage accounts, and virtual networks. Microsoft assessed that the objective was data loss and denial of service.
They also abused mailbox permissions
Separately from the resource deletion, Microsoft reported mailbox-related activity. The actors granted an existing OAuth application the full_access_as_app permission with admin consent, added certificates to the application, and performed GetItem and search operations across mailboxes. They also gave the connector account permission to send on behalf of a high-ranking employee, then sent emails internally and externally.
Rank #3
- SonicWall TZ270W Appliance Only - No Service Subscription (02-SSC-2823) - Combines enterprise-grade firewalling with integrated 802.11ac Wave 2 Wi-Fi to deliver secure wired and wireless connectivity in one compact device for small offices and clinics.
- Blocks zero-day threats and ransomware with Capture ATP sandboxing enhanced by RTDMI, plus IPS and anti-malware scanning for layered protection.
- Eliminates the need for separate access points in smaller spaces thanks to built-in high-speed wireless that is simple to deploy and manage.
- Supports VPN, SD-WAN, and TLS 1.3 decryption to secure hybrid cloud access and remote workers while maintaining usability and performance.
- Delivers gigabit performance with up to 750,000 concurrent connections to handle growth in users, devices, and SaaS applications.
On-premises activity included ransomware staging
Microsoft said the attackers used highly privileged credentials and accessed domain controllers. They interfered with security tools through Group Policy Objects, placed a ransomware payload in domain controllers’ NETLOGON shares, and used a Group Policy-registered scheduled task to launch it. The payload encrypted files and changed their extension to DARKBIT.
What is Azure AD Connect, and why was it a target?
Azure AD Connect synchronizes identity information between an on-premises Active Directory Domain Services environment and Azure AD. In Microsoft’s newer documentation, Azure AD is called Microsoft Entra ID; Microsoft used the Azure AD name in its 2023 incident report. A synchronization host is therefore a sensitive bridge: access to it may expose credentials used to maintain the connection, while the cloud permissions assigned to synchronized identities can determine how far an attacker can go.
Rank #4
- Compact and Efficient Design: The FortiGate 40F is designed for small to mid-sized businesses and enterprise branch offices, featuring a compact, fanless desktop form factor that ensures quiet operation and minimizes space usage.
- Robust Connectivity Options: Equipped with 5 GE RJ45 ports, including 1 WAN port and 4 internal ports, this model provides essential connectivity and flexibility for various network configurations in a small-scale environment.
- High-Performance Security: Offers up to 1 Gbps IPS throughput and 600 Mbps threat protection throughput, using Fortinet’s purpose-built security processor technology to deliver industry-leading performance and protection for SSL encrypted traffic.
- Advanced Threat Protection: Integrated with Fortinet’s AI-powered FortiGuard Labs, the FortiGate 40F offers comprehensive cybersecurity, identifying and mitigating both known and unknown threats to maintain robust security across your network.
- Simplified Management and Deployment: Features a user-friendly management console that provides comprehensive network automation and visibility, coupled with Zero Touch Integration with Fortinet’s Security Fabric for easy deployment.
Microsoft’s hybrid protection guidance describes two broad on-premises-to-cloud trust paths: federation and account synchronization. It recommends disabling federation for Microsoft 365 authentication when possible, and limiting synchronized objects so they hold no cloud privileges beyond those of ordinary users—including privileges inherited indirectly through trusted roles or groups.
| Identity arrangement | Trust path to review | Practical control focus |
|---|---|---|
| Cloud-only identities | No on-premises federation or synchronization path is described for those identities in Microsoft’s guidance. | Review cloud roles and protect administrator sign-ins and sessions. |
| Federated authentication | On-premises federation can affect Microsoft 365 authentication. | Where possible, reduce reliance on federation; assess the on-premises systems and trust that support it. |
| Synchronized identities | Synchronization links on-premises identity infrastructure with cloud identities. | Protect and tightly administer the sync host; ensure synchronized objects have no unnecessary direct or inherited cloud privileges. |
The table describes architectural exposure and control priorities, not a guarantee that a cloud-only arrangement or any single control would prevent an attack.
Why did MFA not stop the cloud actions?
Microsoft said a second Global Administrator account in the victim environment had MFA, but the attackers accessed it through an already-open RDP session. The account’s MFA did not prevent activity through that established session. This is why authentication controls should be paired with protections for privileged endpoints and sessions, rather than treated as a complete defense once a user has signed in.
What should an organization review in a hybrid identity setup?
- Who can administer the synchronization host: restrict and regularly review privileged access to the server running Azure AD Connect.
- What connector identities can do: inventory their cloud roles and remove standing privileges that are not required. Check nested groups and trusted role assignments as well as direct permissions.
- How credentials are protected: assess where synchronization credentials reside and who can access the host that holds them.
- Whether legacy configuration remains: verify that older DirSync arrangements have not left a connector account with Global Administrator rights.
- How privileged sessions are controlled: review exposed or persistent RDP sessions and the safeguards that apply after authentication.
- Which trust model is necessary: assess federation and synchronization paths against Microsoft’s guidance, including whether federation can be disabled for Microsoft 365 authentication.
What should you do if the hybrid identity server may be compromised?
Prioritize containment and evidence preservation. CISA’s advisory AA22-320A recommends isolating affected systems, collecting and reviewing relevant logs, data, and artifacts, and considering third-party incident-response support. That advisory concerns a different suspected Iranian-government-sponsored intrusion, so its steps are general response guidance—not findings about, or a response plan tailored to, Microsoft’s incident.
- Isolate affected systems. Coordinate containment so compromised infrastructure cannot continue to be used to access other systems.
- Preserve and review evidence. Collect relevant logs, data, and artifacts from the identity server and affected environments; avoid actions that would unnecessarily destroy evidence.
- Assess the scope of access. Review privileged account use, synchronization credentials, cloud role elevation, resource deletion, and mailbox permissions or activity.
- Consider specialist help. CISA advises considering third-party incident-response support when responding to a suspected compromise.
The Microsoft account establishes no incident-specific victim count, named victim, or loss estimate. It also does not establish that any one mitigation would certainly have stopped the operation.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

