CTD-000040

Microsoft Entra guest account with unredeemed invite

Low
Entra ID
Initial Access Persistence
v37

Signature Identity

CTD-000040
Threat ID
37
Version
IOE
Indicator Type

Threat Description

Unredeemed invitations might be used by a threat actor to create a persistence in the tenant. As there are multiple attacks that use unredeemed invitations and there is no expiration for invitations, it is strongly recommended to delete such invitations.

MITRE ATT&CK: Attack Tactics

Initial Access Persistence

D3FEND: Defend Tactics

Application Configuration Hardening

Remediation

To delete a user, follow these steps:

  1. Sign in to the Microsoft Entra admin center.
  2. Go to Identity > Users > All users.
  3. Search for and select the user you want to delete from your Microsoft Entra tenant.
  4. Select Delete user.

Frequently Asked Questions

What does Microsoft Entra guest account with unredeemed invite mean?

An unredeemed invitation is a pending guest account in Microsoft Entra that has not been accepted or declined by the intended recipient. This situation can lead to security risks if left unaddressed, as it allows attackers to potentially exploit authentication and authorization mechanisms.

This issue is rated low severity because it typically requires additional attacker steps or context to become a serious threat. However, if left unaddressed, it can increase the likelihood of credential exposure and persistence in the tenant through exploitation of authentication and authorization mechanisms.

Attackers may use an unredeemed invitation to create a persistent presence in the tenant by exploiting the invitation to gain administrative control or using it as a foothold for further malicious activity. This is typically achieved through authentication and authorization mechanisms, allowing attackers to maintain persistence and potentially escalate privileges.

Cayosoft Guardian continuously monitors the tenant's invitations, identifying those that have not been redeemed. This provides administrators with visibility into potential security risks and enables them to take corrective action, such as deleting unredeemed invitations.

Cayosoft Guardian alerts administrators to delete unredeemed invitations, preventing potential security risks and supporting ongoing monitoring. This proactive approach helps teams maintain a secure environment within their tenant by providing visibility into authentication and authorization mechanisms.

Stop AD Threats As They Happen

Cayosoft Protector provides continuous monitoring and real-time alerts across your entire Microsoft Identity stack

Classification
Systems
Entra ID
Themes
Account protection Guest management
Attack Tactics
Initial Access Persistence
Defend Tactics
Application Configuration Hardening
Indicator Types
IOE
Related Threats
CTD-000139
Kerberos Constrained Delegation: krbtgt Risks
Critical
CTD-000122
Active Directory Schema Update Permission Risks
Critical