B3Critical3 accounts
Privileged accounts synced from on-premises
A privileged cloud identity whose password lives in on-premises Active Directory inherits every weakness of that domain. A compromise on a domain controller becomes a compromise of the tenant.
Evidence
| Account | Role | Source | On-prem OU | Last synced |
|---|---|---|---|---|
| adm.legacy@vestholm.no | Global Administrator | Windows Server AD | OU=Admins | 20 Aug 2026 06:00 |
| h.tveitan@vestholm.no | User Administrator | Windows Server AD | OU=IT | 20 Aug 2026 06:00 |
| m.brenna@vestholm.no | Exchange Administrator | Windows Server AD | OU=IT | 20 Aug 2026 06:00 |
How this was derived
onPremisesSyncEnabled = true AND roleDefinition.isPrivileged = true
- Synced identities
- 381 of 412
- Synced and privileged
- 3
If closed
+4 points3 privileged identities become cloud-onlyOn-prem compromise path closed
Fix
Give each of the three a cloud-only privileged identity, and leave the synced account with no role at all.
requires write access
Related findings