CTD-000117

Microsoft Entra tenant with partner access via Delegated Administrative Privileges

High
Entra ID
Defense Evasion Initial Access Persistence Privilege Escalation
v7

Signature Identity

CTD-000117
Threat ID
7
Version
IOE
Indicator Type

Threat Description

A Microsoft Entra tenant configured to allow partner access through Delegated Administrative Privileges (DAP) poses a high-severity threat if not tightly monitored and restricted. This access model grants external partners elevated rights within the tenant, potentially including Global Administrator or other privileged roles.

The existence of DAP allows a partner organization to act on behalf of your tenant without needing per-activity approval or just-in-time access, which increases the attack surface. If a partner organization is compromised or acts maliciously, the threat actor could gain control over sensitive resources within your environment, bypass Conditional Access policies, or disable security configurations.

Furthermore, partner access may not show up in standard user audit logs, complicating the detection of misuse. If DAP accounts are unnecessary, it is highly recommended to eliminate them and implement Least Privilege Access, opting for more secure alternatives like Granular Delegated Admin Privileges (GDAP) instead.

MITRE ATT&CK: Attack Tactics

Defense Evasion Initial Access Persistence Privilege Escalation

D3FEND: Defend Tactics

D3-ACH (Application Configuration Hardening)

Remediation

  1. Sign in to Microsoft 365 Admin Center using Global Administrator credentials for your tenant.
  2. In the left navigation panel, click Settings > Partner relationships.
  3. Review the list of delegated admin partners. Each partner listed has administrative access to your tenant via DAP.
  4. For each partner you want to remove:
    1. Click the partner name.
    2. Choose Remove delegated admin or Delete relationship.
    3. Confirm removal when prompted.
  5. (Optional) Replace with Granular Delegated Admin Privileges (GDAP).
    1. If the partner still needs access but with tighter controls, instruct the partner to configure GDAP instead.
    2. Manage GDAP relationships via Microsoft Partner Center – GDAP Management.

Frequently Asked Questions

What does Microsoft Entra tenant with partner access via Delegated Administrative Privileges mean?

A Microsoft Entra tenant configured for partner access through Delegated Administrative Privileges grants external partners elevated rights within the tenant, including the ability to act on behalf of the tenant without needing per-activity approval or just-in-time access. This configuration allows partners to manage resources and make changes on behalf of the tenant.

This configuration increases the attack surface by granting external partners elevated rights, allowing them to potentially exploit vulnerabilities in Conditional Access policies and security configurations. The attacker gains the ability to bypass security controls and gain unauthorized access to sensitive resources.

Attackers could exploit the elevated rights granted to external partners by bypassing Conditional Access policies, disabling security configurations, or gaining unauthorized access to sensitive resources within the environment. This allows attackers to move laterally and escalate privileges.

Cayosoft Guardian continuously monitors delegated administrative privileges across your Microsoft Entra tenant and flags unnecessary or unmonitored DAP relationships as security issues, alerting administrators to take action. This provides visibility into potential security risks.

Cayosoft Guardian alerts administrators to remove unnecessary or unmonitored DAP relationships, limiting the attack surface and preventing external partners from gaining elevated rights within the tenant. This helps support investigation and response efforts by providing a clear audit trail.

Stop AD Threats As They Happen

Cayosoft Protector provides continuous monitoring and real-time alerts across your entire Microsoft Identity stack

Classification
Systems
Entra ID
Themes
Tenant-wide
Attack Tactics
Defense Evasion Initial Access Persistence Privilege Escalation
Defend Tactics
D3-ACH (Application Configuration Hardening)
Indicator Types
IOE
Related Threats
CTD-000139
Kerberos Constrained Delegation: krbtgt Risks
Critical
CTD-000122
Active Directory Schema Update Permission Risks
Critical