CTD-000167

Entra ID tenant allowing multicast name resolution (LLMNR)

High
Entra ID Intune
Collection Credential Access
v10

Signature Identity

CTD-000167
Threat ID
10
Version
IOE
Indicator Type

Threat Description

Multicast Name Resolution (LLMNR) is a legacy protocol for name resolution in networks without DNS servers. In an Active Directory domain, LLMNR can expose the environment to spoofing and credential-harvesting attacks, such as responder attacks. Attackers can intercept and manipulate LLMNR requests to gain user credentials or redirect traffic.

MITRE ATT&CK: Attack Tactics

Collection Credential Access

D3FEND: Defend Tactics

Application Configuration Hardening

Remediation

  1. Sign in to Microsoft Intune Admin Center.
  2. Navigate to Devices>Configuration > Policies.
  3. Click Create policy.
    • Platform: Windows 10 and later
    • Profile type: Settings catalog
  4. Click Create.
  5. Click Add Settings in the Configuration settings page and search for:
    • Turn off multicast name resolution
    • Path: Administrative Templates >Network > DNS Client
  6. Set the policy to Enabled (this disables LLMNR).
  7. Click Next and assign it to All Devices on the Assignments page.
  8. Click Create to deploy the policy.

Frequently Asked Questions

What does Entra ID tenant allowing multicast name resolution (LLMNR) mean?

Entra ID tenant allowing multicast name resolution (LLMNR) means that the Multicast Name Resolution protocol is enabled in your Entra ID tenant, enabling name resolution in networks without DNS servers but potentially exposing your network to authentication bypass and credential-harvesting attacks.

Entra ID tenant allowing multicast name resolution (LLMNR) is rated high severity because it enables attackers to intercept and manipulate LLMNR requests, gaining user credentials or redirecting traffic without mutual authentication. This allows for unauthorized access and data breaches.

Attackers can intercept and manipulate LLMNR requests to gain user credentials or redirect traffic, exploiting the lack of mutual authentication in the protocol. This enables them to launch authentication bypass and credential-harvesting attacks, potentially leading to unauthorized access and data breaches.

Cayosoft Guardian detects Entra ID tenant allowing multicast name resolution (LLMNR) by continuously monitoring the configuration of your Entra ID tenant for settings that enable LLMNR, providing visibility into potential security issues.

Cayosoft Guardian helps reduce the risk by alerting administrators to disable LLMNR in their Entra ID tenant, preventing attackers from intercepting and manipulating requests. This reduces the likelihood of authentication bypass and credential-harvesting attacks.

Stop AD Threats As They Happen

Cayosoft Protector provides continuous monitoring and real-time alerts across your entire Microsoft Identity stack

Classification
Systems
Entra ID Intune
Themes
Infrastructure
Attack Tactics
Collection Credential Access
Defend Tactics
Application Configuration Hardening
Indicator Types
IOE
Related Threats
CTD-000139
Kerberos Constrained Delegation: krbtgt Risks
Critical
CTD-000122
Active Directory Schema Update Permission Risks
Critical