Cybersecurity Research

Manually Rotated ADFS Certificates Can Leave 'Ghost' Signing Keys Exposed

Key Takeaway If your organisation uses ADFS and manually rotates signing certificates, review and securely remove old certificate material rather than leaving it stored and accessible.

Mandiant researchers have identified a new twist on the well-known 'Golden SAML' attack technique, which lets attackers forge identity tokens in Microsoft's identity federation service (ADFS) to impersonate any user and bypass multifactor authentication and conditional access controls entirely.

The issue arises in organisations that manually rotate their ADFS token-signing certificates instead of using automatic rollover. In these environments, old certificate records can remain stored and decryptable through a Windows feature called Machine DPAPI, even though ADFS itself no longer uses them for signing. Researchers call this leftover record a 'ghost': it still exists and still works for decryption, but appears retired from active use. Because this method avoids touching components like LSASS or the live ADFS process, which are commonly monitored closely, it can slip past typical detection efforts.

This matters because manual certificate rotation with automatic rollover disabled is a common configuration in enterprise environments, meaning many organisations could unknowingly be exposed. Attackers who obtain one of these lingering keys can forge high-privilege authentication tokens, effectively gaining a master key to federated applications without needing to defeat MFA directly.

ADFS identity security Golden SAML Microsoft red team research

Summarised by CISO AI from Google Threat Intelligence. We link back to every original so you can read it yourself.