First-time directory sync of an on-premises domain user to an existing cloud account

Cortex XDR Analytics Alert Reference by data source

Product
Cortex XDR
Last date published
2026-06-15
Category
Analytics Alert Reference
Index by
data source

Synopsis

Activation Period

14 Days

Training Period

30 Days

Test Period

N/A (single event)

Deduplication Period

1 Day

Required Data

  • Requires:
    • AzureAD Audit Log

Detection Modules

Identity Threat Module

Detector Tags

ATT&CK Tactic

Persistence (TA0003)

ATT&CK Technique

Valid Accounts (T1078)

Severity

Informational

Description

First-time synchronization of an on-premises domain user with an existing cloud account.

Attacker's Goals

  • Attackers may leverage DirectorySync to move laterally from a compromised on-premise environment into the cloud tenant, allowing them to bypass the cloud's security boundaries and take over high-value cloud identities.

Investigative actions

  • Check if the cloud account was an administrator (Global Admin, etc.) before this sync.
  • Determine if the on-premise user was recently created or if its 'proxyAddress' attribute was recently modified.
  • Confirm if the organization intended to transition this account from Cloud-Only to Hybrid.
  • Verify the consistency between the on-premises 'ObjectGUID' and the newly assigned 'ImmutableID' in Azure AD.