CTD-000019

Microsoft Entra tenant with Microsoft 365 groups exposed to the whole organization

Low
Entra ID
Discovery
v33

Signature Identity

CTD-000019
Threat ID
33
Version
IOE
Indicator Type

Threat Description

A public group might pose a threat as all users in the organization might have access to the group’s content. A threat actor can add herself to any public group using the Microsoft Entra admin center and access resources such as SharePoint documents or Teams chats.

MITRE ATT&CK: Attack Tactics

Discovery

D3FEND: Defend Tactics

Application Configuration Hardening

Remediation

  1. To review public groups using the Microsoft 365 Administration portal:
    1. Open Microsoft 365 Administration portal.
    2. Open Teams & groups.
    3. Open Active teams & groups.
    4. Review groups with Public in the Privacy column.
  2. To change group’s privacy using the Microsoft 365 Administration portal:
    1. Open Microsoft 365 Administration portal.
    2. Open Teams & groups.
    3. Open Active teams & groups.
    4. Select group with double-click.
    5. Go to the Settings tab.
    6. Change Privacy.
    7. Press Save.

Frequently Asked Questions

What does Microsoft Entra tenant with Microsoft 365 groups exposed to the whole organization mean?

When a Microsoft 365 group's privacy setting is set to 'Public', its content becomes visible and accessible to all users in the organization, allowing unauthorized access to sensitive resources.

This issue is rated low severity because an attacker would need to add themselves to the public group using the Microsoft Entra admin center, which requires some level of effort and context. However, it's essential to note that this vulnerability can be exploited by attackers with minimal privileges.

A threat actor can add themselves to a public group using the Microsoft Entra admin center, granting access to resources like SharePoint documents or Teams chats without explicit permissions. They can then use this access for reconnaissance, data exfiltration, or other malicious activities, ultimately enabling persistence and lateral movement within the organization.

Cayosoft Guardian continuously monitors group privacy settings across your Microsoft 365 environment and flags public groups as security issues, alerting administrators to potential exposure.

Cayosoft Guardian alerts administrators to review and adjust group privacy settings, supporting ongoing monitoring to catch any changes that re-enable public groups, limiting exposure and potential attacker access. Additionally, Cayosoft Guardian provides visibility into group membership and resource access, enabling swift response and mitigation of the vulnerability.

Stop AD Threats As They Happen

Cayosoft Protector provides continuous monitoring and real-time alerts across your entire Microsoft Identity stack

Classification
Systems
Entra ID
Themes
Groups protection Tenant-wide
Attack Tactics
Discovery
Defend Tactics
Application Configuration Hardening
Indicator Types
IOE
Related Threats
CTD-000139
Kerberos Constrained Delegation: krbtgt Risks
Critical
CTD-000122
Active Directory Schema Update Permission Risks
Critical