ENTRALOGIC
KF

22 checks · 18 evaluated · 4 not evaluated

B3Critical3 accounts

Privileged accounts synced from on-premises

A privileged cloud identity whose password lives in on-premises Active Directory inherits every weakness of that domain. A compromise on a domain controller becomes a compromise of the tenant.

Evidence

AccountRoleSourceOn-prem OULast synced
adm.legacy@vestholm.noGlobal AdministratorWindows Server ADOU=Admins20 Aug 2026 06:00
h.tveitan@vestholm.noUser AdministratorWindows Server ADOU=IT20 Aug 2026 06:00
m.brenna@vestholm.noExchange AdministratorWindows Server ADOU=IT20 Aug 2026 06:00

How this was derived

onPremisesSyncEnabled = true
AND roleDefinition.isPrivileged = true
Synced identities
381 of 412
Synced and privileged
3

If closed

+4 points3 privileged identities become cloud-onlyOn-prem compromise path closed

Fix

Give each of the three a cloud-only privileged identity, and leave the synced account with no role at all.

requires write access

Related findings

Sample report. Fictional group, fictional data.