MSOL (Microsoft Online Services) account
Brute force
O365 BruteforceEnumerate the PHS account and server where AD Connect is installed.
Extract MSOL credentials
Administrative privileges needed
With the password
DCSync
Because AD Connect synchronizes hashes every two minutes, in an Enterprise Environment, the MSOL_ account will be excluded from tools like MDI. This will allow us to run DCSync without any alerts. 🥳
NXC

Get MSOL Credentials
MSOL account can perform a DCSync because the MSOL account has the Replicate Directory Changes All permissions
Last updated

