Federation in Microsoft Entra ID allows your organisation to delegate authentication to an external identity provider. When a federated domain is added, users with email addresses in that domain can authenticate using tokens issued by the external provider — rather than being validated directly by Entra ID. This is a powerful and legitimate capability used for hybrid environments and SSO with external partners.
However, if an attacker has Global Admin access, adding a rogue federated domain is one of the most persistent and hard-to-detect backdoors available. Using a technique known as Golden SAML, an attacker who controls the external identity provider can forge authentication tokens for any user in the federated domain — including admin accounts — without those users needing to authenticate at all. This backdoor can survive password resets and MFA changes, because the trust relationship bypasses Entra ID's own credential validation.
If a malicious federated domain is added, an attacker who controls the associated identity provider can generate valid SAML assertions for any account in the federated domain. These assertions are trusted by Entra ID and grant full access to connected Microsoft 365 services without requiring the user's password or MFA.
This technique was used in the SolarWinds/SUNBURST attack to maintain persistent access across multiple victim organisations. Forensically, it's extremely difficult to detect because the access appears legitimate in Entra ID logs — the tokens are valid, the sign-ins succeed, and there are no failed authentication events.
The only reliable way to detect this is to catch the domain federation event itself — which is why alerting on new federated domain additions is critical.
Federated domain additions are a legitimate part of configuring hybrid identity environments and SSO integrations. Legitimate scenarios include:
In all cases, domain federation is a significant architectural change that should have a corresponding project ticket, change management record, or configuration review. Any addition that cannot be immediately matched to an approved change is suspicious.
Overe Auto-Response: The New Federated Domain Added alert can be configured in Overe to trigger automatic session revocation or account block for the initiating admin when this activity is detected. Review your Auto-Response settings under Org Config > Auto-Response — given the severity of this indicator, an automated response is strongly recommended.
After investigating a new federated domain alert, review these related risk areas: