SolarWinds and Golden SAML (Dec 2020): The Supply-Chain Attack That Reached the Cloud
Retrospective: this article looks back at events from December 2020, written in 2026 with the benefit of hindsight.
On December 13, 2020, the world learned that attackers had compromised SolarWinds' Orion network monitoring software and inserted a backdoor — later called SUNBURST — into updates distributed to about 18,000 customers. The discovery came after cybersecurity firm FireEye disclosed it had been breached.
How it worked
The attackers, later attributed by the US government to Russia's foreign intelligence service (SVR), compromised SolarWinds' build environment and inserted malicious code into legitimate, digitally signed Orion updates distributed between March and June 2020. Most customers received the backdoor but were never targeted further. For a smaller set of high-value targets — including US government agencies and technology companies — the attackers moved to the next stage.
From on-premises to the cloud
A distinctive feature of the campaign was how attackers moved from on-premises networks into Microsoft 365 and Azure:
- Golden SAML: with access to an organization's AD FS server, attackers stole the token-signing certificate and forged SAML tokens to sign in to cloud services as any user, bypassing MFA.
- Abuse of applications and service principals: attackers added credentials to existing OAuth applications with mail access, or created new ones, to read email via Microsoft Graph.
- Federation trust changes in some cases, adding domains or modifying trust settings.
The response
CISA issued Emergency Directive 21-01 ordering agencies to disconnect Orion. Microsoft published detailed guidance for detecting the cloud techniques. The incident led to the US Executive Order on Improving the Nation's Cybersecurity in May 2021.
Lessons in hindsight
- Supply-chain compromise bypasses traditional perimeters.
- On-premises identity infrastructure (AD FS) is a path to the cloud. Moving to cloud authentication removes the token-signing risk.
- Non-human identities — apps and service principals — need monitoring as closely as users.
- Logging matters. Organizations with mail access auditing could see what was read.
- How to Move From AD FS to Cloud Authentication and Retire Token-Signing Risk How-To & Hardening
- Detecting Golden SAML: Entra Sign-In Logs and Sentinel KQL Detection & Response
- CIO Brief: Supply-Chain Risk After SolarWinds — What Boards Now Ask CIO Briefings