CTD-000038

Microsoft Entra tenant with unsecure access to Azure management

High
Entra ID
Command and Control Execution Lateral Movement Privilege Escalation
v27

Signature Identity

CTD-000038
Threat ID
27
Version
IOE
Indicator Type

Threat Description

Organizations use many Azure services and manage them from Azure Resource Manager based tools like Microsoft Entra admin center, Azure PowerShell, and Azure CLI. These tools can provide highly privileged access to resources. To protect these privileged resources, Microsoft recommends requiring multifactor authentication (MFA) for any user accessing these resources. Without MFA enforced, a threat actor might compromise an account and immediately get access to the privileged resources.

MITRE ATT&CK: Attack Tactics

Command and Control Execution Lateral Movement Privilege Escalation

D3FEND: Defend Tactics

Application Configuration Hardening

Remediation

To create a Conditional access policy:

  1. Sign in to the Microsoft Entra admin center as a Conditional Access Administrator, Security Administrator, or Global Administrator.
  2. Browse to Protection > Conditional Access.
  3. Select Create new policy.
  4. Give your policy a name. 
  5. Under Assignments, select Users.
    1. Under Include, select All users.
    2. Under Exclude, select Users and groups and choose your organization’s emergency access or break-glass accounts.
  6. Under Target resources select Cloud apps.
  7. Under Include select Select apps, choose Windows Azure Service Management API, and select Select.
  8. Under Access controls > Grant, select Grant accessRequire multifactor authentication, and select Select.
  9. Confirm your settings and set Enable policy to Report-only.
  10. Select Create to create to enable your policy.
  11. After confirming your settings, move the Enable policy toggle from Report-only to On.

Frequently Asked Questions

What does Microsoft Entra tenant with unsecure access to Azure management mean?

When a Microsoft Entra tenant has unsecured access to Azure management, it means that users can access highly privileged Azure resources without being required to use multifactor authentication (MFA). This allows an attacker who compromises an account to gain immediate and unrestricted access to these resources. Specifically, the Conditional Access policy is not enforcing MFA for accessing sensitive resources.

This issue is rated high severity because it enables a threat actor to bypass MFA requirements, allowing them to gain privileged access to resources without additional steps. The lack of MFA enforcement in the Conditional Access policy creates an exposure that can lead to rapid and severe compromise of the environment.

An attacker who compromises an account in a Microsoft Entra tenant with unsecured access to Azure management can immediately gain privileged access to resources, allowing them to perform actions that would normally require administrative control, such as creating or modifying sensitive data. The attacker gains the capability to escalate privileges and perform unauthorized actions.

Cayosoft Guardian detects Microsoft Entra tenant with unsecured access to Azure management by continuously monitoring Conditional Access policies across your Microsoft Entra tenant. When a policy is found to be missing MFA enforcement, Guardian flags it as a security issue so administrators are aware of the exposure and can take corrective action.

Cayosoft Guardian helps reduce the risk by alerting administrators to create and enable a Conditional Access policy that requires MFA for accessing privileged resources. Guardian also supports ongoing monitoring to ensure the policy remains enabled and effective, providing visibility into potential security issues and assisting response efforts.

Stop AD Threats As They Happen

Cayosoft Protector provides continuous monitoring and real-time alerts across your entire Microsoft Identity stack

Classification
Systems
Entra ID
Themes
Conditional Access Tenant-wide
Attack Tactics
Command and Control Execution Lateral Movement Privilege Escalation
Defend Tactics
Application Configuration Hardening
Indicator Types
IOE
Related Threats
CTD-000139
Kerberos Constrained Delegation: krbtgt Risks
Critical
CTD-000122
Active Directory Schema Update Permission Risks
Critical