CTD-000018

Microsoft Entra tenant with auditing disabled

Critical
Entra ID
Defense Evasion
v37

Signature Identity

CTD-000018
Threat ID
37
Version
IOA-IOC
Indicator Type

Threat Description

In Microsoft Entra tenant with auditing disabled, user activities are not recorded in the auditing log. Without data from auditing log investigation of security issues might be difficult or impossible in some cases. A threat actor might disable auditing to perform some changes in your environment.

MITRE ATT&CK: Attack Tactics

Defense Evasion

D3FEND: Defend Tactics

Application Configuration Hardening

Remediation

To enable Microsoft 365 audit log search:

  1. Log in to Microsoft Purview compliance portal.
  2. Under Solutions, select Audit.
  3. Click Start recording user and admin activity.
  4. Click Yes to confirm.

Frequently Asked Questions

What does Microsoft Entra tenant with auditing disabled mean?

Microsoft Entra tenant with auditing disabled means that user activities are not recorded in the auditing log within your Microsoft Entra environment. This lack of logging makes it difficult to investigate security issues, as there is no data available for analysis.

Microsoft Entra tenant with auditing disabled is rated critical because the absence of auditing log data severely hampers incident response and threat hunting efforts. Without this crucial information, security teams are left without a clear audit trail, making it challenging to identify and respond to potential threats.

Attackers might exploit the lack of auditing by disabling it themselves to cover their tracks or perform malicious activities without being detected. This allows them to evade detection, making it challenging for security teams to identify and respond to potential threats.

Cayosoft Guardian detects Microsoft Entra tenant with auditing disabled by continuously monitoring the configuration of your Microsoft Entra environment. When it finds that auditing is disabled, Guardian flags this as a critical security issue, providing administrators with clear visibility into the potential threat.

Cayosoft Guardian helps reduce the risk by alerting administrators to enable auditing in your Microsoft Entra environment. This ensures that user activities are properly logged, enabling security teams to detect and respond to potential threats more effectively.

Stop AD Threats As They Happen

Cayosoft Protector provides continuous monitoring and real-time alerts across your entire Microsoft Identity stack

Classification
Systems
Entra ID
Themes
Infrastructure Tenant-wide
Attack Tactics
Defense Evasion
Defend Tactics
Application Configuration Hardening
Indicator Types
IOA IOC
Related Threats
CTD-000139
Kerberos Constrained Delegation: krbtgt Risks
Critical
CTD-000122
Active Directory Schema Update Permission Risks
Critical