Back to directory
WRITEUP #1147

Tampering with Conditional Access Policies Using Azure AD Graph API

CloudPrivilege escalation
by@Secureworks(Secureworks Counter Threat Unit)
Program
Microsoft (Azure)
Published
May 23, 2023
Added to HackDex
May 29, 2023
Read Full Writeuphttps://www.secureworks.com/research/tampering-with-conditional-access-policies-using-azure-ad-graph-api
RELATED WRITEUPS
Addressed AWS defaults risks: OIDC, Terraform and Anonymous to AdministratorAccess
CloudOIDC
Double Agent: Exploiting Pass-through Authentication Credential Validation in Azure AD
CloudPrivilege escalation
UnOAuthorized: Privilege Elevation Through Microsoft Applications
CloudPrivilege escalation
Escalating Privileges in Google Cloud via Open Groups
CloudPrivilege escalation
ConfusedFunction: A Privilege Escalation Vulnerability Impacting GCP Cloud Functions
CloudPrivilege escalation

Built with ❤️ by Shubham Rawat