Who Would you Like to be Today?: Impersonation by Fake Azure Active Directory Identity Federation

Nestori Syynimaa · 2018

Azure Active Directory (AAD) is Microsoft's cloud-based directory and identity management service used by various service providers (SPs). For instance, Microsoft's own Office 365 is utilizing identity management services of AAD. Hundreds of external SPs are also providing services which are supporting AAD identities. Besides cloud-based managed identities, AAD also supports federated identities where authentication is performed by the external identity provider (IdP). Identity federation is based on a trust between SP and IdP. In this paper, we will report a vulnerability in AAD identity federation which enables undetectable identity impersonation. The vulnerability is caused by a design flaw in the trust to IdPs. We will also introduce some methods to detect the exploitation of the vulnerability and provide advice how to limit the risk of exploitation.

Read the paper · More papers on PaperTik