When Entra ID trusts SAML assertions minted on-premises, cloud security depends on the integrity of the local AD FS environment.
Preface
Hybrid identity federates on-premises AD DS with Microsoft Entra ID via AD FS. That creates an explicit cryptographic trust. If the on-premises tier is compromised, the cloud environment falls with it.
Problem
Nobelium (Midnight Blizzard) campaigns used two major post-compromise vectors:
- Golden SAML: Steal the AD FS token-signing private key and forge SAML assertions for any identity, with arbitrary group and role claims, bypassing password and MFA checks.
- MagicWeb: Replace legitimate AD FS security components and inject unauthorized claims during token generation without stealing the signing key.
AD FS servers often sit outside Tier 0 isolation, making them a bridge for on-premises-to-cloud lateral movement.
Solution
Align with CISA Hybrid Identity guidance and NIST SP 800-207:
- Transition to cloud-primary authentication: Migrate from AD FS to PHS or PTA with Seamless SSO.
- Isolate remaining AD FS as Tier 0: Same boundaries as domain controllers, host firewalls, no direct internet, PAW-only admin access.
- Monitor trust changes: Alert on Event ID 510 (SAML trust modification) and Event ID 307 (certificate rollover).
PowerShell: Migrate to Cloud-Managed Authentication
Connect-MgGraph -Scopes "Domain.ReadWrite.All"
Get-MgDomainFederationConfiguration -DomainId "enterprise.com"
Update-MgDomain -DomainId "enterprise.com" -AuthenticationType "Managed"