M365 Show -  Microsoft 365 Digital Workplace Daily

M365 Show - Microsoft 365 Digital Workplace Daily

Microsoft Security Pulse: Protect, Detect, Defend

What Makes AD Connect MSOL Users Vulnerable to Suspected DCSync Attacks

Mirko Peters - M365 Specialist's avatar
Mirko Peters - M365 Specialist
Aug 13, 2025
∙ Paid

You are at risk because the MSOL_ account has special rights. These rights let it copy directory data. AD Connect gives this account these rights. This helps it sync changes between your local Active Directory and Azure AD.
1. AD Connect picks which MSOL_ account to use for syncing.
2. It looks for missing rights and helps you add them.
3. The tool shows y…

User's avatar

Continue reading this post for free, courtesy of Mirko Peters - M365 Specialist.

Or purchase a paid subscription.
© 2026 Mirko Peters · Publisher Privacy ∙ Publisher Terms
Substack · Privacy ∙ Terms ∙ Collection notice
Start your SubstackGet the app
Substack is the home for great culture