CTD-000201

Microsoft Entra Organizational Messages Writer and Approver roles assigned to the same user or group

Medium
Entra ID
Defense Evasion Impact Privilege Escalation
v6

Signature Identity

CTD-000201
Threat ID
6
Version
IOE
Indicator Type

Threat Description

A user may be assigned both the Organizational Messages Writer and Organizational Messages Approver roles in Microsoft Entra ID. This removes dual control, a key security principle, and allows the same identity to both create and approve organizational messages without independent review.

An intentional or compromised account with both roles could publish misleading or malicious organizational messages to users without oversight.

MITRE ATT&CK: Attack Tactics

Defense Evasion Impact Privilege Escalation

D3FEND: Defend Tactics

Application Configuration Hardening

Remediation

  1. Sign in to the Microsoft Entra admin center.
  2. Open the affected user or the relevant role assignment.
  3. Review the roles assigned to the user.
  4. Remove either the Organizational Messages Writer role or the Organizational Messages Approver role so that the same identity no longer holds both roles.
  5. Verify that the change is reflected in the user’s role assignments.

Frequently Asked Questions

What does Microsoft Entra Organizational Messages Writer and Approver roles assigned to the same user or group mean?

When a single identity is granted both the Organizational Messages Writer and Organizational Messages Approver roles in Microsoft Entra ID, it removes dual control. This configuration allows the same identity to create and approve organizational messages without independent review.

This configuration enables an attacker to publish malicious or misleading content by exploiting the lack of dual control, which can lead to unauthorized access, data exposure, or reputational damage.

An attacker can use this configuration to publish malicious or misleading organizational messages by creating and approving them without oversight. This can lead to unauthorized access, data exposure, or reputational damage.

Cayosoft Guardian continuously monitors role assignments in Microsoft Entra ID to identify when a single identity has both the Organizational Messages Writer and Organizational Messages Approver roles. When this is detected, Guardian alerts administrators.

Cayosoft Guardian provides visibility into role assignments in Microsoft Entra ID, allowing administrators to review and remove either the Organizational Messages Writer or Organizational Messages Approver role from the affected user.

Stop AD Threats As They Happen

Cayosoft Protector provides continuous monitoring and real-time alerts across your entire Microsoft Identity stack

Classification
Systems
Entra ID
Themes
Account protection Privileged Access Management Tenant-wide
Attack Tactics
Defense Evasion Impact Privilege Escalation
Defend Tactics
Application Configuration Hardening
Indicator Types
IOE
Related Threats
CTD-000139
Kerberos Constrained Delegation: krbtgt Risks
Critical
CTD-000122
Active Directory Schema Update Permission Risks
Critical