Language:
Every Active Directory that uses the SSO feature of Microsoft Entra ID includes a special computer account, AZUREADSSOACC. This account holds the master secret used to authenticate users from the local domain to Microsoft Azure, and it is essential that you must protect it at all costs.
Changing the AZUREADSSOACC account key is a special operation that requires the use of a Microsoft script.
Introduction to Azure Active Directory Seamless Single Sign-On
Changing the Kerberos decryption key of the AZUREADSSOACC computer account
Name: Last Change of the Microsoft Entra SSO Account Password
Codename: C-AAD-SSO-PASSWORD
Severity: High