CTD-000096

Microsoft Entra tenant with device settings allowing brute force attacks

Medium
Entra ID Intune
Initial Access
v21

Signature Identity

CTD-000096
Threat ID
21
Version
IOE
Indicator Type

Threat Description

If a Windows device does not restrict password attempts, a threat actor may be able to repeatedly guess the password and gain access to the device. This can lead to compromised credentials or data or to the installation of malicious software.

MITRE ATT&CK: Attack Tactics

Initial Access

D3FEND: Defend Tactics

Application Configuration Hardening

Remediation

To configure this setting, use the Microsoft Intune admin center:

  1. Go to Devices > Configuration profiles.
  2. Select Create > New policy.
  3. Choose Windows 8.1 and later as the Platform.
  4. Select Device restrictions as the Profile type.
  5. Select Create.
  6. Enter a name for the policy, then select Next.
  7. In the Password section, review Number of sign-in failures before wiping device and set it according to your organization’s security policy.
  8. Complete the policy configuration.
  9. Assign the policy only to the intended device groups.
  10. Test the policy on a limited set of devices before broader deployment.

Warning: Setting Number of sign-in failures before wiping device to a value greater than 0 can cause devices to be wiped after repeated failed sign-in attempts. Before enabling this setting, make sure the policy is reviewed, tested, and assigned only to the correct devices.

Frequently Asked Questions

What does Microsoft Entra tenant with device settings allowing brute force attacks mean?

When password attempt restrictions are disabled on Windows devices in your Intune-managed environment, an attacker can make multiple consecutive login attempts to guess the password. This increases the likelihood of successful guessing and subsequent access to the device.

Disabling password attempt restrictions allows attackers to repeatedly try passwords, increasing the risk of successful login attempts. This can lead to compromised credentials or data, making it a meaningful concern for organizations.

An attacker can exploit the disabled password attempt restrictions on Windows devices in your Intune-managed environment by repeatedly guessing passwords. This can lead to successful login attempts, compromised credentials or data, and potential installation of malicious software.

Cayosoft Guardian continuously monitors the password attempt restrictions setting across your Intune-managed environment. When it detects that the setting is disabled, Guardian flags it as a security issue to alert administrators and provide visibility into potential attack paths.

Cayosoft Guardian alerts administrators to enable password attempt restrictions in the Intune admin center, limiting the potential for successful guessing and subsequent access to devices. This helps protect against compromised credentials or data by supporting investigation and response efforts.

Stop AD Threats As They Happen

Cayosoft Protector provides continuous monitoring and real-time alerts across your entire Microsoft Identity stack

Classification
Systems
Entra ID Intune
Themes
Devices protection Tenant-wide
Attack Tactics
Initial Access
Defend Tactics
Application Configuration Hardening
Indicator Types
IOE
Related Threats
CTD-000139
Kerberos Constrained Delegation: krbtgt Risks
Critical
CTD-000122
Active Directory Schema Update Permission Risks
Critical