For example, within the 2023 MGM assault, the attacker straight accessed an account with Tremendous Admin permissions in Okta, which they combined with an inbound federation attack to impersonate any user within the tenant, get Azure admin privileges, and authenticate to the Azure-hosted VMware ecosystem in which they deployed ransomware. A Google