CTD-000032

Guest account with Microsoft Entra role membership

High
Entra ID
Privilege Escalation
v40

Signature Identity

CTD-000032
Threat ID
40
Version
IOC-IOE
Indicator Type

Threat Description

A guest user account with membership in Microsoft Entra role poses a threat to your environment. This guest user has an account in an external Microsoft Entra tenant or an external identity provider. If a guest user account in that external organization is compromised, a threat actor might access resources in your tenant.

MITRE ATT&CK: Attack Tactics

Privilege Escalation

D3FEND: Defend Tactics

Credential Transmission Scoping User Account Permissions

Remediation

  1. Review this guest user account and her activity.
  2. Remove role assignments from the guest user account.
  3. If a guest user requires administrative access to your tenant, consider creation of an account in your tenant for this user.

Frequently Asked Questions

What does Guest account with Microsoft Entra role membership mean?

A user account in the environment that has been granted membership in a Microsoft Entra role, typically from an external organization, with an account in an external Microsoft Entra tenant or identity provider.

It allows an attacker to access resources in the tenant through unmanaged identities, potentially leading to privilege escalation and unauthorized access. This is because guest accounts can be compromised by attackers who have control over the external organization's identity provider or tenant.

Attackers can exploit a guest account with Microsoft Entra role membership by compromising the guest user account in the external organization, granting them access to resources in the tenant through unmanaged identities and potentially leading to privilege escalation. This can also enable lateral movement within the environment.

Cayosoft Guardian continuously monitors the membership of user accounts in the environment, including those from external organizations, detecting guest accounts with Microsoft Entra role membership and flagging them as security issues for administrators to review.

Cayosoft Guardian alerts administrators to remove role assignments from guest user accounts, preventing unauthorized access and privilege escalation. It also provides visibility into unmanaged identities and recommends creating new accounts in the tenant for users requiring administrative access.

Stop AD Threats As They Happen

Cayosoft Protector provides continuous monitoring and real-time alerts across your entire Microsoft Identity stack

Classification
Systems
Entra ID
Themes
Account protection Guest management
Attack Tactics
Privilege Escalation
Defend Tactics
Credential Transmission Scoping User Account Permissions
Indicator Types
IOC IOE
Related Threats
CTD-000139
Kerberos Constrained Delegation: krbtgt Risks
Critical
CTD-000122
Active Directory Schema Update Permission Risks
Critical