Executive Summary
Armadin researchers have detailed a technique and tool named PRTremote that allows attackers with local administrator privileges to bypass the Windows logon session boundary and extract Primary Refresh Tokens (PRTs). By leveraging the TASK_LOGON_INTERACTIVE_TOKEN logon type in Windows Scheduled Tasks, an operator can execute commands within a target user's active session without needing their password, NT hash, or MFA factors.
The attack chain involves using the native Microsoft binary BrowserCore.exe to request PRT cookies (x-ms-RefreshTokenCredential) through local session redirection. These cookies can then be redeemed for Entra ID access tokens that inherit the original user's Multi-Factor Authentication (MFA) and device compliance claims. This method is particularly dangerous because it avoids traditional detection triggers like process injection or token theft, relying instead on signed Microsoft binaries and legitimate task scheduling mechanisms.
This technique highlights a critical risk for organizations using Entra ID (formerly Azure AD) for Single Sign-On (SSO). It demonstrates that local administrative access on a workstation can be rapidly escalated to full cloud environment access, bypassing Conditional Access policies that rely on MFA or compliant devices. Security teams should prioritize monitoring for anomalous remote scheduled task registrations and hardening privileged access workstations.
