CTD-000007

Microsoft Entra ID Administrative Units are not being used

Informational
Entra ID
Persistence
v36

Signature Identity

CTD-000007
Threat ID
36
Version
IOE
Indicator Type

Threat Description

Usage of Administrative Units enhances tenant’s protection against threats. When planning your access control strategy, there are three aspects to consider when you assign a role to your administrators: a specific set of permissions, over a specific scope, for a specific period of time. The least privilege means you grant your administrators exactly the permission they need to do their job. By limiting scopes with Administrative units, you limit what resources are at risk if the security principal is ever compromised.

MITRE ATT&CK: Attack Tactics

Persistence

D3FEND: Defend Tactics

Application Configuration Hardening

Remediation

Frequently Asked Questions

What does Microsoft Entra ID Administrative Units are not being used mean?

Microsoft Entra ID Administrative Units are not being used means that administrators do not have their privileges scoped to specific administrative units, allowing them to access a broader range of resources within the tenant. This configuration allows for broad privilege scope, which can increase the risk of unauthorized access and lateral movement if an administrator's credentials are compromised.

This finding is rated informational severity because it indicates that administrators have broad privilege scope, which can increase the risk of unauthorized access and lateral movement if an administrator's credentials are compromised. The lack of administrative units enables attackers to gain broad access to resources within the tenant.

When administrative units are not being used, an attacker who compromises an administrator's credentials gains broad privilege scope, allowing them to access more resources and potentially move laterally within the tenant. The attacker can also use the compromised credentials to perform actions that would otherwise be restricted by delegation boundaries.

Cayosoft Guardian detects Microsoft Entra ID Administrative Units are not being used by identifying tenants where administrative units are absent or not used for scoped administration. This allows administrators to take corrective action and limit the privilege scope of their accounts.

Cayosoft Guardian helps reduce the risk of Microsoft Entra ID Administrative Units are not being used by alerting administrators to create and use administrative units. This limits the privilege scope, reduces the blast radius, and establishes delegation boundaries, making it more difficult for attackers to move laterally within the tenant.

Stop AD Threats As They Happen

Cayosoft Protector provides continuous monitoring and real-time alerts across your entire Microsoft Identity stack

Classification
Systems
Entra ID
Themes
Delegation Privileged Access Management Tenant-wide
Attack Tactics
Persistence
Defend Tactics
Application Configuration Hardening
Indicator Types
IOE
Related Threats
CTD-000139
Kerberos Constrained Delegation: krbtgt Risks
Critical
CTD-000122
Active Directory Schema Update Permission Risks
Critical