CTD-000020

Microsoft Entra tenant with Privileged Identity Management not being used

Medium
Entra ID
Privilege Escalation
v32

Signature Identity

CTD-000020
Threat ID
32
Version
IOE
Indicator Type

Threat Description

In a tenant with Privileged Identity Management (PIM), Microsoft Entra roles can be secured with an additional approval process and require MFA on activation. Without PIM, if a threat actor gets access to an account with membership in a powerful role such as Global Admin, he will be able to use it right away. PIM provides a time-based and approval-based role activation to mitigate the risks of excessive, unnecessary, or misused access permissions to important resources. These resources include resources in Microsoft Entra ID, Azure, and other Microsoft Online Services such as Microsoft 365 or Microsoft Intune.

MITRE ATT&CK: Attack Tactics

Privilege Escalation

D3FEND: Defend Tactics

Application Configuration Hardening

Remediation

  1. Deploy Privileged Identity Management (PIM).
  2. Assign users as eligible members to Microsoft Entra roles.

Frequently Asked Questions

What does Microsoft Entra tenant with Privileged Identity Management not being used mean?

When Privileged Identity Management (PIM) is not enabled on a Microsoft Entra tenant, the additional approval process and multi-factor authentication required for securing roles are disabled. This allows powerful roles, such as Global Admin, to be used immediately by an attacker who gains access to an account with membership in these roles.

The absence of PIM on a Microsoft Entra tenant allows attackers to escalate privileges and access sensitive resources, but it does not grant administrative control directly. This condition enables an attacker to use powerful roles immediately upon gaining access to an account with membership in these roles.

An attacker who gains access to an account with membership in a powerful role, such as Global Admin, can use that role immediately when PIM is disabled. This allows the attacker to escalate privileges and access sensitive resources in the tenant, including those in Microsoft Entra ID, Azure, and other Microsoft Online Services.

Cayosoft Guardian continuously monitors the configuration of the tenant's roles and permissions to detect when PIM is disabled. When this condition is found, Guardian flags it as a security issue so administrators are aware that powerful roles can be used immediately.

Cayosoft Guardian helps reduce the risk by alerting administrators to enable PIM and secure roles in the tenant. Additionally, Guardian supports ongoing monitoring so that if PIM is disabled later, the change is caught quickly, limiting the attacker's ability to escalate privileges.

Stop AD Threats As They Happen

Cayosoft Protector provides continuous monitoring and real-time alerts across your entire Microsoft Identity stack

Classification
Systems
Entra ID
Themes
Delegation Privileged Access Management
Attack Tactics
Privilege Escalation
Defend Tactics
Application Configuration Hardening
Indicator Types
IOE
Related Threats
CTD-000139
Kerberos Constrained Delegation: krbtgt Risks
Critical
CTD-000122
Active Directory Schema Update Permission Risks
Critical