Skip to content

Commit e3c98d1

Browse files
Update ATPDocs/remove-unsafe-permissions-sensitive-entra-connect.md
Co-authored-by: Devorah Cohen <[email protected]>
1 parent 08d765a commit e3c98d1

File tree

1 file changed

+1
-1
lines changed

1 file changed

+1
-1
lines changed

ATPDocs/remove-unsafe-permissions-sensitive-entra-connect.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -21,7 +21,7 @@ This article describes Microsoft Defender for Identity's Microsoft Entra Connect
2121
2222
## How can unsafe permissions on Microsoft Entra Connect accounts expose your hybrid identity to risk?
2323

24-
Entra Connect accounts like AD DS Connector account (also known as MSOL_) and Entra Seamless SSO computer account (AZUREADSSOACC) have powerful privileges, including replication and password reset rights. If these accounts are granted unsafe permissions, attackers could exploit them to gain unauthorized access, escalate privileges, or take control of hybrid identity infrastructure. This could lead to account takeovers, unauthorized directory modifications, and a broader compromise of both on-premises and cloud environments.
24+
Microsoft Entra Connect accounts like AD DS Connector account (also known as MSOL_) and Microsoft Entra Seamless SSO computer account (AZUREADSSOACC) have powerful privileges, including replication and password reset rights. If these accounts are granted unsafe permissions, attackers could exploit them to gain unauthorized access, escalate privileges, or take control of hybrid identity infrastructure. This could lead to account takeovers, unauthorized directory modifications, and a broader compromise of both on-premises and cloud environments.
2525

2626
## How do I use this security assessment to improve my hybrid organizational security posture?
2727

0 commit comments

Comments
 (0)