CTD-000064

Microsoft Entra tenant with bulk changes of groups

Medium
Entra ID
Impact
v10

Signature Identity

CTD-000064
Threat ID
10
Version
IOC
Indicator Type

Threat Description

Bulk changes might be a result of threat activities. Also, it could be a mistake. Deletions or modifications of Microsoft Entra objects can lead to service outages.

NOTE: This threat rule includes a built-in lookback parameter set to 25 hours. Only events that occurred within this timeframe are processed by the rule.

MITRE ATT&CK: Attack Tactics

Impact

D3FEND: Defend Tactics

User Account Permissions

Remediation

To rollback unwanted changes:
  1. Go to Change History.
  2. Select unwanted changes.
  3. Roll them back.

Frequently Asked Questions

What does Microsoft Entra tenant with bulk changes of groups mean?

Bulk changes to group memberships involve multiple, possibly unauthorized, modifications. This can result from malicious activity or administrative errors.

This issue is rated medium severity because it can lead to service outages and potentially indicate threat activities. Although the changes themselves don't grant admin control, they can still cause operational disruptions due to compromised group permissions.

Attackers might exploit group membership modifications for unauthorized access or service disruption within your Microsoft Entra tenant. These changes can also serve as reconnaissance data for future attacks, aiding the attacker in planning their next steps and potentially leading to lateral movement.

Cayosoft Guardian continuously monitors group membership changes within your Microsoft Entra tenant. When it identifies multiple, possibly unauthorized, modifications, Guardian flags this as a security issue to alert administrators and provide visibility into the affected groups.

Cayosoft Guardian reduces risk by providing real-time monitoring, alerting administrators to potential issues, and supporting investigation through Change History in Microsoft Entra. This allows teams to review recent changes, identify potential issues, and roll back unwanted modifications.

Stop AD Threats As They Happen

Cayosoft Protector provides continuous monitoring and real-time alerts across your entire Microsoft Identity stack

Classification
Systems
Entra ID
Themes
Account protection
Attack Tactics
Impact
Defend Tactics
User Account Permissions
Indicator Types
IOC
Related Threats
CTD-000139
Kerberos Constrained Delegation: krbtgt Risks
Critical
CTD-000122
Active Directory Schema Update Permission Risks
Critical