CTD-000149

Entra user added to a privileged role

High
Entra ID
Privilege Escalation
v33

Signature Identity

CTD-000149
Threat ID
33
Version
IOA-IOC-IOE
Indicator Type

Threat Description

A user added to a privileged role can indicate unauthorized or suspicious activity. This includes direct membership changes, membership granted through nested groups, and membership granted through role-assignable groups. Such changes may be used to escalate privileges, establish persistence, or gain access to sensitive systems and data.

NOTE: This threat rule includes a built-in lookback parameter set to 48 hours. Only events that occurred within this timeframe are processed by the rule.

MITRE ATT&CK: Attack Tactics

Privilege Escalation

D3FEND: Defend Tactics

Restore Configuration

Remediation

Use Change History in Cayosoft Guardian to review modifications and rollback unwanted changes. For more information on how to do that, see Rolling back the changes.

Frequently Asked Questions

What does Entra user added to a privileged role mean?

Entra user added to a privileged role means that a user has been directly assigned or indirectly granted membership in a privileged role within your Entra ID environment. This can indicate unauthorized access control changes, as it may be used to modify access controls and escalate privileges.

The addition of a user to a privileged role directly enables privilege escalation, allowing an attacker to access sensitive systems and data with elevated permissions. This can be used as a foothold for further malicious activity.

An attacker can use the elevated privileges to modify access controls, escalate their access, or gain unauthorized access to sensitive systems and data. This can be used as a foothold for further malicious activity.

Cayosoft Guardian detects Entra user added to a privileged role by continuously monitoring changes to role assignments and memberships within your Entra ID environment, specifically looking for unauthorized additions of users to privileged roles.

Cayosoft Guardian provides visibility into changes made to role assignments and memberships, allowing administrators to review modifications using Change History in Cayosoft Guardian and maintain the integrity of their environment.

Stop AD Threats As They Happen

Cayosoft Protector provides continuous monitoring and real-time alerts across your entire Microsoft Identity stack

Classification
Systems
Entra ID
Themes
Privileged Access Management
Attack Tactics
Privilege Escalation
Defend Tactics
Restore Configuration
Indicator Types
IOA IOC IOE
Related Threats
CTD-000139
Kerberos Constrained Delegation: krbtgt Risks
Critical
CTD-000122
Active Directory Schema Update Permission Risks
Critical