CTD-000161

Entra ID application owner attribute populated with a hybrid user account

Medium
Entra ID
Lateral Movement Persistence Privilege Escalation
v23

Signature Identity

CTD-000161
Threat ID
23
Version
IOE
Indicator Type

Threat Description

The Application Owner attribute in Entra ID specifies the account responsible for managing an application's lifecycle. When this attribute is set to a hybrid user account synchronized from the on-premises Active Directory, it introduces significant risks. These hybrid accounts are typically subject to legacy authentication protocols, shared account usage, or administrative roles not intended for cloud application management. A compromise of this account provides attackers a persistent foothold in your environment, with the ability to reconfigure or exploit applications in Entra ID for malicious purposes.

MITRE ATT&CK: Attack Tactics

Lateral Movement Persistence Privilege Escalation

D3FEND: Defend Tactics

D3-ACH (Application Configuration Hardening)

Remediation

  1. In Entra ID, navigate to Enterprise Applications and select the application.
  2. Check the Owners tab to confirm the hybrid account is assigned as an owner.
  3. Contact the application stakeholders or IT team to validate whether the hybrid account was intentionally assigned.
  4. Document the purpose, usage, and access level requirements of the account.
  5. Replace Hybrid Account with Secure Owner.
  6. Create a managed identity or a cloud-only account with strict access controls (e.g., a dedicated service account).
  7. Navigate to the OwnEntra IDers tab in the application and assign the new secure account as the owner.
  8. Remove the hybrid account from ownership.
  9. Ensure only secure, cloud-only accounts are listed under Owners.

Frequently Asked Questions

What does Entra ID application owner attribute populated with a hybrid user account mean?

The Application Owner attribute in Entra ID is set to a hybrid user account synchronized from on-premises Active Directory. This can introduce risks due to potential legacy authentication protocols, shared account usage, or administrative roles not intended for cloud application management.

This setting provides attackers with a persistent foothold in the environment, enabling them to reconfigure or exploit applications in Entra ID. This can be achieved through compromising the hybrid account's credentials or exploiting its permissions.

Attackers can compromise the hybrid account and use it to reconfigure or exploit applications in Entra ID. This allows them to maintain access and manipulate application settings for malicious purposes, such as unauthorized data access or privilege escalation.

Cayosoft Guardian continuously monitors the Application Owner attribute in Entra ID and identifies when it is set to a hybrid user account. This provides visibility into potential security risks and enables proactive measures.

Cayosoft Guardian alerts administrators to the presence of a hybrid account as an application owner, enabling them to review and correct the setting. This supports ongoing monitoring to ensure only secure accounts are assigned as owners, reducing the risk of unauthorized access and privilege escalation.

Stop AD Threats As They Happen

Cayosoft Protector provides continuous monitoring and real-time alerts across your entire Microsoft Identity stack

Classification
Systems
Entra ID
Themes
Account protection Privileged Access Management
Attack Tactics
Lateral Movement Persistence Privilege Escalation
Defend Tactics
D3-ACH (Application Configuration Hardening)
Indicator Types
IOE
Related Threats
CTD-000139
Kerberos Constrained Delegation: krbtgt Risks
Critical
CTD-000122
Active Directory Schema Update Permission Risks
Critical