CTD-000016

Microsoft Entra role with permanent active members

High
Entra ID
Defense Evasion Persistence Privilege Escalation
v55

Signature Identity

CTD-000016
Threat ID
55
Version
IOE
Indicator Type

Threat Description

Permanent active role assignments might be an indication of threat activities. If an account with permanent active role membership is compromised, threat actor immediately gets access to administrative privileges. Using only time-limited role assignments for administrators increases security posture in your tenant as role activation might be protected with MFA on activation or approval.

MITRE ATT&CK: Attack Tactics

Defense Evasion Persistence Privilege Escalation

D3FEND: Defend Tactics

User Account Permissions

Remediation

To review or modify permanent active role membership:

  1. Sign in to Microsoft Entra admin center with a user that is a member of the Privileged role administrator role.
  2. Open Microsoft Entra Privileged Identity Management.
  3. Select Microsoft Entra roles.
  4. Select Roles to see the list of roles for Microsoft Entra permissions.
  5. Select a role.
  6. Switch to the Active assignments tab.
  7. To remove assignment click on Remove.

Frequently Asked Questions

What does Microsoft Entra role with permanent active members mean?

In Microsoft Entra, a user or service has been assigned to a role with ongoing, permanent access. This type of membership grants continuous access without the need for re-approval or multi-factor authentication (MFA).

A compromised account with permanent active role membership in Microsoft Entra allows an attacker to gain immediate administrative privileges, enabling rapid escalation of privileges and significant operational impact. This is because the role's permissions grant direct access to sensitive areas, allowing attackers to persist and conduct reconnaissance.

When a user or service has permanent active role membership in Microsoft Entra, an attacker who compromises the account gains direct access to administrative capabilities through the role's permissions. This enables privilege escalation and operational impact, allowing attackers to show change history and assist response efforts.

Cayosoft Guardian continuously monitors membership assignments in Microsoft Entra, identifying users or services with ongoing, permanent access to roles. When detected, Guardian flags the issue for administrators to review and address.

Cayosoft Guardian alerts administrators to review and modify permanent active role membership, enabling teams to limit unnecessary access and prevent privilege escalation through targeted security measures. This helps provide visibility into administrative scope and credentials, supporting investigation and response efforts.

Stop AD Threats As They Happen

Cayosoft Protector provides continuous monitoring and real-time alerts across your entire Microsoft Identity stack

Classification
Systems
Entra ID
Themes
Privileged Access Management
Attack Tactics
Defense Evasion Persistence Privilege Escalation
Defend Tactics
User Account Permissions
Indicator Types
IOE
Related Threats
CTD-000139
Kerberos Constrained Delegation: krbtgt Risks
Critical
CTD-000122
Active Directory Schema Update Permission Risks
Critical