Microsoft Security Tech Accelerator
Dec 06 2023, 07:00 AM - 12:00 PM (PST)
Microsoft Tech Community

Azure ATP lateral Movement

Iron Contributor

Hi everyone,


In Azure ATP,  you can see lateral movement maps giving you an idea how hackers can move from hop to hop to reach sensitive accounts.


My question, how can Azure ATP know that if John has a compromised identity, that he can access that TS because he is member of this group. How Azure ATP can know who is the administrators group on servers to do such simulation and map? because when John gets his TGT, it has list of what groups he is member of, and not a list of servers that those groups are set as administrates.

1 Reply
best response confirmed by Ammar Hasayen (Iron Contributor)

The Sensor can query endpoints for local administrators group membership.

(Giving that you allowed it as the documentation requests)