Auditing Directory Sync Trust

Audit bulk directory synchronization (LDAP, HR-system, IdP, or cross-directory feeds) between an external identity source and an application for trust misplaced in the sync feed: a sync that trusts a source attribute (group, department, an admin-like flag) to set local privilege or tenancy without validating it, a connector authenticated by a broad credential that can read and reshape the whole directory, a mapping that lets an external group name land on a privileged internal group, a sync that matches accounts by a spoofable key (email, external id) so an attacker record merges into an existing identity, and a source deletion that does not propagate so departed users linger. Use when an external directory feed drives account and privilege state and the application's trust in that feed is the boundary. The attacker-influenced source record is the source, the over-privileged, merged, or lingering internal account is the sink, and the unvalidated attribute mapping or spoofable match key is the bug.

UnboundCompute cfa44eb 11.4 KB Updated

File contents

UnboundCompute/security-agent-skills/tree/main/skills/auditing-directory-sync-trust commit cfa44eb2a1

Frequently asked questions

npx skillmds@latest add unboundcompute/auditing-directory-sync-trust