CTD-000042

Microsoft Entra tenant with Certificate-Based Authentication enabled for all users

High
Entra ID
Defense Evasion Persistence
v27

Signature Identity

CTD-000042
Threat ID
27
Version
IOE
Indicator Type

Threat Description

  1. If a treat actor gains control of a root CA trusted by Microsoft Entra ID, the threat actor can impersonate any user without knowing their password.
  2. Configuring Certificate-Based Authentication and impersonating a Global Admin doesn’t require Global Admin rights. The threat actor might use this technique to elevate his privileges without being noticed.

MITRE ATT&CK: Attack Tactics

Defense Evasion Persistence

D3FEND: Defend Tactics

Application Configuration Hardening

Remediation

To delete a CA certificate:

  1. Sign in to the Microsoft Entra admin center as a Global Administrator.
  2. Browse to Protection > Security Center > Certificate authorities.
  3. Select the certificate.
  4. Click Delete.

To specify groups that can use the certificate-based authentication in the Microsoft Entra admin center:

  1. Sign in to the Microsoft Entra admin center as an Authentication Policy Administrator.
  2. Browse to Protection > Authentication methods > Certificate-based Authentication.
  3. Under Enable and Target select Enable.
  4. Select All users, or select Add groups to select specific groups.

Frequently Asked Questions

What does Microsoft Entra tenant with Certificate-Based Authentication enabled for all users mean?

Certificate-Based Authentication is configured to allow all users in the tenant to use certificate-based authentication. This allows an attacker who gains control of a root CA trusted by Microsoft Entra ID to issue unauthorized certificates, enabling them to impersonate any user without knowing their password.

This configuration enables an attacker who gains control of a root CA trusted by Microsoft Entra ID to issue unauthorized certificates, allowing them to bypass multi-factor authentication and access sensitive resources. This can lead to privilege elevation and other malicious activities.

An attacker who gains control of a root CA trusted by Microsoft Entra ID can use certificate-based authentication to issue unauthorized certificates, enabling them to impersonate any user without knowing their password. This allows the attacker to elevate privileges and perform other malicious activities undetected.

Cayosoft Guardian continuously monitors the configuration of Certificate-Based Authentication in the Microsoft Entra admin center. When it finds that Certificate-Based Authentication is enabled for all users, Guardian flags it as a security issue so administrators are aware of the potential risk.

Cayosoft Guardian alerts administrators to disable Certificate-Based Authentication for all users in the Microsoft Entra admin center, limiting the potential for an attacker to impersonate any user without knowing their password and reducing the risk of privilege elevation and other malicious activities.

Stop AD Threats As They Happen

Cayosoft Protector provides continuous monitoring and real-time alerts across your entire Microsoft Identity stack

Classification
Systems
Entra ID
Themes
Tenant-wide
Attack Tactics
Defense Evasion Persistence
Defend Tactics
Application Configuration Hardening
Indicator Types
IOE
Related Threats
CTD-000139
Kerberos Constrained Delegation: krbtgt Risks
Critical
CTD-000122
Active Directory Schema Update Permission Risks
Critical