CTD-000017

Microsoft Entra role with permanent eligible members

High
Entra ID
Defense Evasion Persistence Privilege Escalation
v41

Signature Identity

CTD-000017
Threat ID
41
Version
IOE
Indicator Type

Threat Description

Permanent eligible role assignments might be an indication of threat activities or misconfiguration. If an account with permanent eligible role membership is compromised, a threat actor might immediately get access to administrative privileges if role activation is not properly protected. Using only time-limited role assignments for administrators increases security posture in your tenant.

MITRE ATT&CK: Attack Tactics

Defense Evasion Persistence Privilege Escalation

D3FEND: Defend Tactics

User Account Permissions

Remediation

To review or modify permanent eligible role membership:

  1. Sign in to Microsoft Entra admin center with a user that is a member of the Privileged role administrator role.
  2. Open Microsoft Entra Privileged Identity Management.
  3. Select Microsoft Entra roles.
  4. Select Roles to see the list of roles for Microsoft Entra permissions.
  5. Select a role.
  6. Switch to the Eligible assignments tab.
  7. To remove assignment click on Remove.

Frequently Asked Questions

What does Microsoft Entra role with permanent eligible members mean?

In a Microsoft Entra environment, a role with permanent eligible members has been assigned to accounts that can access administrative privileges without time limits. This setting enables immediate access to sensitive permissions if an account is compromised.

The presence of a Microsoft Entra role with permanent eligible members allows a threat actor to gain direct access to administrative privileges upon compromising an account, justifying the high severity rating due to increased risk of privilege escalation and persistence.

A threat actor who compromises an account with permanent eligibility in a Microsoft Entra environment can immediately gain administrative privileges, enabling them to escalate their access and persist in the environment through unauthorized access to sensitive permissions. This allows for reconnaissance of administrative scope and exploitation of credentials.

Cayosoft Guardian continuously monitors role assignments and eligibility settings within your Microsoft Entra environment, detecting roles with permanent eligible members and flagging the issue for administrators to review and adjust.

Cayosoft Guardian alerts administrators when it detects a role with permanent eligible members, enabling them to review and modify the settings to ensure only time-limited roles are used for administrators, thereby reducing the risk of privilege escalation and persistence.

Stop AD Threats As They Happen

Cayosoft Protector provides continuous monitoring and real-time alerts across your entire Microsoft Identity stack

Classification
Systems
Entra ID
Themes
Privileged Access Management
Attack Tactics
Defense Evasion Persistence Privilege Escalation
Defend Tactics
User Account Permissions
Indicator Types
IOE
Related Threats
CTD-000139
Kerberos Constrained Delegation: krbtgt Risks
Critical
CTD-000122
Active Directory Schema Update Permission Risks
Critical