EIDFED-008: Pass-Through Authentication Agent Status

Plataforma
Entra ID / M365
Categoría
Entra ID Federation & Hybrid Identity
Severidad
Medium
Pilar de Zero Trust
Identity (peso 3)
Fixtures de referencia
3
Cobertura de ramas
Observada: los fixtures prueban los veredictos que ejercitan
Procedencia
baseline

Qué comprueba

Pass-Through Authentication (PTA) validates user passwords against on-premises Active Directory in real-time without storing password hashes in the cloud. PTA agents running on on-premises servers must be properly secured, monitored, and kept current, as a compromised PTA agent could be manipulated to accept any password or to intercept credentials during authentication. Agent health, version currency, and server security posture are critical to maintaining authentication integrity.

Valor recomendado

At least 2 PTA agents deployed on hardened servers with current agent versions and health monitoring enabled

Remediación

Review the PTA agent status in Entra ID > Hybrid management > Azure AD Connect > Pass-through authentication. Verify that at least two agents are deployed for redundancy and that all agents show a healthy status with current software versions. Ensure PTA agent servers are treated as Tier 0 assets with restricted administrative access, up-to-date security patches, and comprehensive event log monitoring.

Veredictos probados con fixtures

Cada veredicto de esta tabla está probado por un fixture de referencia en la suite de pruebas que valida el módulo. La tabla se deriva de la última ejecución en verde; no puede editarse a mano.

Escenarios de veredicto de EIDFED-008
EscenarioVeredicto esperado
cleanPASS
known-badWARN
no-dataNot Assessed

Mapeos a marcos de referencia

NIST SP 800-53
IA-2
MITRE ATT&CK
T1556