When the Cloud Becomes the Way In: Lateral Movement to On-Premises
Most organisations think about their security boundary in one direction. They worry about an attacker getting into the cloud, or getting into the on-premises network. What is less commonly considered is that these two environments are connected, and that a foothold in one is increasingly a route into the other.
Hybrid infrastructure is now the norm. Azure Active Directory syncing to an on-premises domain, workstations that are both domain-joined and cloud-managed, identity services that span both environments. The connectivity that makes this convenient for users creates lateral movement paths that are not well understood by most security teams.
The Sync Account: A Bridge with Keys to Both Sides
Organisations running Azure AD Connect, Microsoft's tool for synchronising on-premises Active Directory with Entra ID, create a service account in both environments to manage that sync. This account, typically prefixed with MSOL_ or ADSync, is granted highly privileged access on-premises, specifically the ability to replicate directory changes. In Active Directory terms, this is DCSync capability: the same permission used to extract password hashes from a domain controller.
If an attacker gains access to the Azure side of the environment and can identify or compromise this sync account, they do not need to pivot through a firewall or find a vulnerability in an on-premises system. They can use the account's replication permissions to pull credential material directly from the domain controller. The cloud becomes the path to full on-premises domain compromise.
For a business, this means a single compromised cloud account with the right permissions can result in an attacker gaining control of the entire on-premises network without ever touching a physical system.
This is not a theoretical path. It is one of the first things we look for in hybrid environment assessments, and the sync account is frequently over-privileged and under-monitored. The fix is straightforward: scope the sync account's permissions down to only what Azure AD Connect requires, and monitor it for any unusual activity. Microsoft's own guidance documents the minimum permissions needed and most environments grant significantly more than that.
Seamless SSO and Ticket Forgery
Microsoft's Seamless Single Sign-On feature uses a computer account in the on-premises domain, typically named AZUREADSSOACC$, to generate Kerberos tickets that allow cloud-authenticated users to access on-premises resources without being prompted to log in again. The Kerberos key for this account rarely changes. In many environments it has not been rotated since Seamless SSO was first enabled.
If an attacker can extract the password hash for this account, which requires domain-level access or the DCSync path described above, they can forge Kerberos Silver Tickets for any user in the on-premises environment. This grants access to on-premises services as any identity, including privileged accounts, without those accounts ever authenticating or generating a login event.
Tools like AADInternals make this straightforward once the hash is obtained. The impact is effectively arbitrary on-premises access without touching the domain controller directly. From a business perspective, this means an attacker can impersonate any member of staff, including senior leadership or IT administrators, across on-premises systems, with no alert generated and no login record created.
The remediation here is simple but frequently missed: rotate the AZUREADSSOACC$ account password regularly. Microsoft recommends doing this every 30 days and automatic rotation is now available through Entra Connect. Most organisations have never rotated it once.
Pass-the-PRT: Moving from Device to Domain
Devices that are hybrid Azure AD joined hold a Primary Refresh Token, a long-lived credential issued by Azure that allows the device to obtain access tokens for cloud services without re-authenticating. On a compromised device, this token can be extracted from memory and replayed from a different machine, a technique known as Pass-the-PRT.
The reason this matters for on-premises lateral movement is that hybrid-joined devices use their PRT to authenticate to on-premises resources through the Seamless SSO mechanism. An attacker who compromises a standard user's cloud session, extracts a PRT, and replays it can authenticate to on-premises resources as that user. Combined with a highly privileged account, this is a direct path from cloud identity compromise to on-premises access with no exploitation of on-premises systems required.
In practical terms, this means compromising a single user's device or cloud session can provide an attacker with authenticated access to on-premises file servers, internal applications, and business systems, without any network intrusion in the traditional sense. Reducing the blast radius here requires enforcing device compliance policies, restricting local administrator rights on endpoints, and enabling Continuous Access Evaluation, which ensures tokens are invalidated quickly after events like a user being disabled or a password reset rather than remaining valid until they naturally expire.
Azure Arc: Managing On-Premises from the Cloud
Azure Arc is Microsoft's service for extending Azure management to on-premises servers and infrastructure. Organisations use it to manage on-premises machines through the Azure portal, applying policies, running scripts, and monitoring resources centrally. It is legitimate, widely used, and creates an obvious attack path.
A machine enrolled in Azure Arc can be issued commands through the Azure management plane. An attacker with sufficient permissions in the Azure environment, Contributor or Owner access on the relevant resource group, can execute code on Arc-enrolled on-premises machines through the same interface an administrator would use. There is no need to traverse a network boundary or find a vulnerability in an on-premises system. The management channel is the attack path.
For a business this means that weak access controls in Azure can translate directly into the ability to run arbitrary commands on physical servers sitting in an on-premises server room. The Azure and on-premises environments are not separate risk domains. This is an emerging area and one that security teams are frequently unaware of when they enrol on-premises servers into Arc without reviewing the access controls on the Azure side. Reviewing role assignments on Arc-enrolled resource groups and applying least privilege to the Azure management plane is the starting point.
The Broader Point
These techniques share a common thread: the attack does not look like a traditional breach. There is no exploitation of a vulnerability, no brute-forced firewall, no lateral movement across subnets in the way a network monitoring tool would detect it. It is authenticated use of legitimate services, crossing the boundary between cloud and on-premises through the trust relationships that were built to make hybrid working convenient.
Securing a hybrid environment requires treating that boundary as a critical attack surface. The sync accounts, the SSO infrastructure, the device token estate, and the cloud management plane all need to be assessed with the same rigour applied to the domain controller itself. At Tarian Labs, cloud-to-on-premises lateral movement is a dedicated part of how we assess hybrid environments, because the path from a compromised Microsoft 365 account to domain admin is shorter than most organisations realise.
If your organisation runs a hybrid environment, the boundary between cloud and on-premises is an attack surface worth understanding.
Get in touch to discuss a hybrid environment assessment scoped to your infrastructure.