CTD-000188

Entra user account with compromised password

Medium
Entra ID
Credential Access Discovery Initial Access
v20

Signature Identity

CTD-000188
Threat ID
20
Version
IOC-IOE
Indicator Type

Threat Description

This detection identifies valid internal domain suffixes used in Entra user and tenant objects and checks whether any of these domains appear in known public breaches using the HaveIBeenPwned (HIBP) domain search API. Public email providers are excluded from the threat settings’ predefined list.

When a matching breach is found, Cayosoft Guardian evaluates only breaches that include compromised passwords, ensuring results are limited to cases where user credentials were actually exposed. For each affected user, Cayosoft Guardian compares the breach data with the date the user last changed their password. If the password has never been changed or was last changed before the breach date, an alert is triggered.

If internal domains are found in breach data containing compromised passwords, and affected users have not rotated their credentials since the breach, this represents a significant threat vector. Compromised credentials may be exploited for phishing, credential stuffing, or unauthorized access.

This detection enables organizations to proactively assess and mitigate domain-level exposure risks by identifying users whose passwords remain vulnerable after a known breach.

MITRE ATT&CK: Attack Tactics

Credential Access Discovery Initial Access

D3FEND: Defend Tactics

Domain Account Monitoring

Remediation

  1. Review breach metadata from HaveIBeenPwned.
  2. Contact impacted users and force a password change. Enforce multi-factor authentication (MFA), and if users are already registered, require them to re-register.
  3. Check Cayosoft Guardian Change History for any suspicious activity performed by the identified accounts.

Frequently Asked Questions

What does Entra user account with compromised password mean?

An Entra user's password has been exposed in a known public breach, allowing an attacker to use the credential for authentication attempts and potentially gaining access to sensitive resources.

Entra user account with compromised password is rated medium severity because it indicates a significant threat vector where exposed credentials can be exploited through brute-force attacks or phishing campaigns, potentially leading to unauthorized access and data breaches.

An attacker can use the exposed credential to attempt authentication, potentially leading to successful login and unauthorized access to the affected user's account, as well as gaining access to sensitive resources and data. This can also enable lateral movement within the domain.

Cayosoft Guardian continuously monitors public breaches for exposed credentials and compares them to valid Entra users' passwords, flagging matches as security issues for administrator review and providing visibility into potential attack paths.

Cayosoft Guardian alerts administrators to affected users, prompting them to enforce password changes, multi-factor authentication, and review breach metadata from HaveIBeenPwned, thereby mitigating domain-level exposure risks and supporting investigation and response efforts.

Stop AD Threats As They Happen

Cayosoft Protector provides continuous monitoring and real-time alerts across your entire Microsoft Identity stack

Classification
Systems
Entra ID
Themes
Account protection
Attack Tactics
Credential Access Discovery Initial Access
Defend Tactics
Domain Account Monitoring
Indicator Types
IOC IOE
Related Threats
CTD-000139
Kerberos Constrained Delegation: krbtgt Risks
Critical
CTD-000122
Active Directory Schema Update Permission Risks
Critical