CTD-000081

Stale privileged Microsoft Entra user account

Medium
Entra ID
Credential Access Privilege Escalation
v33

Signature Identity

CTD-000081
Threat ID
33
Version
IOE
Indicator Type

Threat Description

Shared, service, and emergency access accounts that authenticate using a password and are assigned to highly privileged administrative roles such as Global administrator or Security administrator should have their passwords rotated for multiple reasons.

Since multiple people have access to these accounts’ credentials, the credentials should be regularly changed to ensure that people that have left their roles can no longer access the accounts.

MITRE ATT&CK: Attack Tactics

Credential Access Privilege Escalation

D3FEND: Defend Tactics

Domain Account Monitoring

Remediation

To delete unused privileged account:
  1. Sign in to the Microsoft Entra admin center using a User administrator account for the organization.
  2. Browse to Identity > Users > All users.
  3. Search for and select the user you want to delete from your Microsoft Entra tenant.
  4. Select Delete.
  5. If it is a break-glass account, add this account to an exclusion list of this rule.

Frequently Asked Questions

What does Stale privileged Microsoft Entra user account mean?

A stale privileged Microsoft Entra user account refers to a shared, service, or emergency access account with an unrotated password. These accounts hold highly privileged administrative roles such as Global administrator or Security administrator and can be accessed by multiple users.

Stale privileged Microsoft Entra user account is rated medium severity because a stale password on a highly privileged account allows an attacker to authenticate using compromised credentials, gaining elevated access and increasing the risk of unauthorized activity. This can be achieved through successful authentication, which enables attackers to escalate privileges, move laterally, or access sensitive credentials.

Attackers can use a stale password on a highly privileged Microsoft Entra user account to gain elevated access through successful authentication. This enables malicious activities such as privilege escalation, lateral movement, or credential access.

Cayosoft Guardian continuously monitors password rotation policies for shared, service, and emergency access accounts in Microsoft Entra. When a stale password is detected, Guardian flags it as a security issue to alert administrators.

Cayosoft Guardian helps reduce the risk by detecting and flagging stale passwords on highly privileged accounts, enabling administrators to rotate credentials and minimize the risk of unauthorized activity. Guardian also supports ongoing monitoring to ensure password rotation policies are enforced.

Stop AD Threats As They Happen

Cayosoft Protector provides continuous monitoring and real-time alerts across your entire Microsoft Identity stack

Classification
Systems
Entra ID
Themes
Account protection
Attack Tactics
Credential Access Privilege Escalation
Defend Tactics
Domain Account Monitoring
Indicator Types
IOE
Related Threats
CTD-000139
Kerberos Constrained Delegation: krbtgt Risks
Critical
CTD-000122
Active Directory Schema Update Permission Risks
Critical