CTD-000013

Microsoft Entra Global Administrator with elevated access to Azure Resources

Critical
Azure resources Entra ID
Lateral Movement Privilege Escalation
v55

Signature Identity

CTD-000013
Threat ID
55
Version
IOA-IOC-IOE
Indicator Type

Threat Description

A Global Administrator elevating access to Azure resources creates a cross-boundary privilege pivot between Microsoft Entra ID and Azure Resource Manager. By assigning themselves access at the root scope, an attacker can gain control over all subscriptions and management groups, enabling lateral movement from identity control into resource control. This allows the attacker to establish persistent access by creating or modifying Azure RBAC assignments, deploy resources, and maintain backdoor permissions even if the original Entra ID role is remediated.

MITRE ATT&CK: Attack Tactics

Lateral Movement Privilege Escalation

D3FEND: Defend Tactics

User Account Permissions

Remediation

  1. Remove elevated access as Global Admins should not have access to Azure resources.
    User Access Administrator role assignments can be removed using Azure PowerShell, Azure CLI, or the REST API.
  2. Investigate the activities of an administrator in the Activity Log.

Frequently Asked Questions

What does Microsoft Entra Global Administrator with elevated access to Azure Resources mean?

A user in the Global Admin role has been granted increased permissions to access Azure resources, allowing them to view or modify resource configurations.

This elevation of privileges allows an attacker to gain direct and unfiltered access to sensitive Azure resources, enabling modification of storage accounts, virtual machines, or network settings, which can lead to data breaches or security incidents.

Attackers can exploit the elevated permissions to view or modify Azure resource configurations, gaining unauthorized access to sensitive data or disrupting services. This can also support later attacker activity, such as lateral movement or privilege escalation.

Cayosoft Guardian monitors role assignments and permissions in both Entra ID and Azure, alerting administrators when an unexpected change is detected, such as a user being added to the Global Admin role or having their permissions increased.

Cayosoft Guardian provides visibility into role assignments and permissions, allowing administrators to quickly identify and correct any unexpected changes, preventing attackers from gaining unauthorized access to sensitive resources. This helps support investigation and response efforts by providing a clear audit trail of changes.

Stop AD Threats As They Happen

Cayosoft Protector provides continuous monitoring and real-time alerts across your entire Microsoft Identity stack

Classification
Systems
Azure resources Entra ID
Themes
Account protection
Attack Tactics
Lateral Movement Privilege Escalation
Defend Tactics
User Account Permissions
Indicator Types
IOA IOC IOE
Related Threats
CTD-000139
Kerberos Constrained Delegation: krbtgt Risks
Critical
CTD-000122
Active Directory Schema Update Permission Risks
Critical