CTD-000041

Microsoft Entra tenant allowing unsecure token persistence

Medium
Entra ID
Credential Access
v37

Signature Identity

CTD-000041
Threat ID
37
Version
IOE
Indicator Type

Threat Description

A Primary Refresh Token (PRT) is a key artifact of Microsoft Entra authentication on Windows 10 or newer, Windows Server 2016 and later versions, iOS, and Android devices. It is a JSON Web Token (JWT) specially issued to Microsoft first party token brokers to enable single sign-on (SSO) across the applications used on those devices. After an administrator logs in on a device, PRT is cached on the client. If a device used by the administrator is left unattended or compromised, a threat actor might be able to extract PRT and use it to access your tenant bypassing MFA.

MITRE ATT&CK: Attack Tactics

Credential Access

D3FEND: Defend Tactics

Application Configuration Hardening Credential Transmission Scoping

Remediation

To change sign-in frequency control and browser session persistence for users with administrative permissions:

  1. Sign in to the Microsoft Entra admin center as a Global Administrator, Security Administrator, or Conditional Access Administrator.
  2. Browse to Protection > Conditional Access.
  3. Select Create new policy.
  4. Give your policy a name. 
  5. In Target resources choose Cloud apps > All cloud apps.
  6. In Users choose Select users and groups in Include section.
  7. Select Directory roles.
  8. Add all administrative roles.
  9. Go to Access controls > Session.
  10. Select Sign-in frequency.
  11. Select Periodic reauthentication.
  12. Enter a value of hours, or select Every time.
  13. Under Access controls > Session select Persistent browser session.
  14. Choose Never persistent.
  15. Select On in Enable policy section.
  16. Save your policy.

Frequently Asked Questions

What does Microsoft Entra tenant allowing unsecure token persistence mean?

Microsoft Entra tenant allowing unsecure token persistence occurs when a Primary Refresh Token (PRT) is cached on client devices without proper security or deletion, enabling potential attackers to extract the PRT and access the tenant.

This issue is rated medium severity because it creates a risk of unauthorized access when an administrator's device is left unattended or compromised, allowing attackers to extract the cached PRT and use it to bypass MFA.

Attackers exploit this issue by extracting the cached Primary Refresh Token (PRT) from an administrator's device, which they can then use to access the tenant without MFA and gain unauthorized access to sensitive resources. This allows them to maintain persistence in the environment.

Cayosoft Guardian detects this issue by continuously monitoring the state of Primary Refresh Tokens (PRTs) on client devices, flagging any unsecured PRTs as a security issue and providing administrators with clear visibility into potential exposure.

Cayosoft Guardian helps reduce the risk by alerting administrators to properly secure or disable Primary Refresh Tokens (PRTs) on client devices, limiting the potential for attackers to extract and use PRTs to access the tenant and reducing exposure to unauthorized access.

Stop AD Threats As They Happen

Cayosoft Protector provides continuous monitoring and real-time alerts across your entire Microsoft Identity stack

Classification
Systems
Entra ID
Themes
Account protection Privileged Access Management Tenant-wide
Attack Tactics
Credential Access
Defend Tactics
Application Configuration Hardening Credential Transmission Scoping
Indicator Types
IOE
Related Threats
CTD-000139
Kerberos Constrained Delegation: krbtgt Risks
Critical
CTD-000122
Active Directory Schema Update Permission Risks
Critical