Dynamic Group Memberships exploitation
As a user, we can invite accounts that meet the criteria for the dynamic group, then when the guest account is ready to go, the user gains applied roles and is a member of the exploited dynamic group.
Steps
1) Check for Dynamic Groups
2) Verify Dynamic Membership Rules
3) Invite a New Guest User
4) Connect to the Tenant with AzureAD
5) Set Secondary Email for the User
6) Check if the User is Added to the Dynamic Group
Last updated