CTD-000043

Service Principal promoted a service principal to privileged role members

Critical
Entra ID
Defense Evasion Privilege Escalation
v52

Signature Identity

CTD-000043
Threat ID
52
Version
IOA-IOC
Indicator Type

Threat Description

A service principal is an identity that is used by applications or services to access resources in Microsoft Entra ID. Service principals are created with specific permissions, such as the ‘AppRoleAssignment.ReadWrite.All’ permission, which allows the service principal to manage role assignments in Microsoft Entra ID.
This can include promoting itself or other service principals to members of privileged roles, such as administrators or owners. This means that a threat actor who has gained access to a previously created service principal with the ‘AppRoleAssignment.ReadWrite.All’ permission could use it to persist in the environment and elevate their privileges when needed.

MITRE ATT&CK: Attack Tactics

Defense Evasion Privilege Escalation

D3FEND: Defend Tactics

Domain Account Monitoring

Remediation

  1. To remove unwanted role assignments using Microsoft Entra admin center:
    1. Sign in to the Microsoft Entra admin center as a Global Administrator or Privileged Role Administrator.
    2. Select Identity > Roles & Admins > Roles & Admins > All roles.
    3. Select the role which assignment you want to remove.
    4. Select Remove for all of the needed objects.
    5. When asked to confirm your action, select Yes.
  2. To undo unwanted role assignments using Cayosoft Guardian:
    1. Go to the Change Monitoring > Change History node.
    2. Find unwanted changes using filters.
    3. Select unwanted changes and press Rollback.
  3. To disable a compromised user account:
    1. Go to the Microsoft Entra admin center as a Global Administrator or User Administrator.
    2. Select Identity > Users > All users.
    3. Find the user and click the user’s name to open its properties.
    4. Click the Edit properties button.
    5. Locate Account enabled option in the Settings tab.
    6. Remove the checkmark and save.
  4. To review account’s activity, use Change History in Cayosoft Guardian.

Frequently Asked Questions

What does Service Principal promoted a service principal to privileged role members mean?

When a service principal is added as a member of a privileged role, such as an administrator or owner, it gains the ability to manage role assignments and elevate its privileges when needed. Specifically, this configuration allows the service principal to be part of the role's membership.

This issue is rated critical because it enables an attacker who has gained access to a previously created service principal with the 'AppRoleAssignment.ReadWrite.All' permission to persist in the environment and elevate their privileges when needed, potentially leading to significant operational impact. The mechanism behind this vulnerability lies in the role assignment's membership, which can be modified by the service principal.

An attacker can use a service principal that has been promoted to a privileged role member to maintain access to sensitive resources and perform malicious operations without being detected, as they gain the ability to manage role assignments and elevate their privileges. This allows them to persist in the environment and potentially lead to further attacks.

Cayosoft Guardian continuously monitors the membership of service principals in privileged roles and flags any instances where a service principal has been added as a member, alerting administrators to potential security risks. This is achieved through ongoing monitoring and analysis of role assignments.

Cayosoft Guardian helps reduce this risk by alerting administrators to unwanted role assignments, allowing them to review and remove these assignments. Additionally, Guardian supports ongoing monitoring to quickly detect if the role assignment is re-added later, providing visibility into potential security threats.

Stop AD Threats As They Happen

Cayosoft Protector provides continuous monitoring and real-time alerts across your entire Microsoft Identity stack

Classification
Systems
Entra ID
Themes
Privileged Access Management
Attack Tactics
Defense Evasion Privilege Escalation
Defend Tactics
Domain Account Monitoring
Indicator Types
IOA IOC
Related Threats
CTD-000139
Kerberos Constrained Delegation: krbtgt Risks
Critical
CTD-000122
Active Directory Schema Update Permission Risks
Critical