CTD-000083

Microsoft Entra tenant with recent changes in Cross Tenant Access configuration

High
Entra ID
Defense Evasion Persistence Privilege Escalation
v35

Signature Identity

CTD-000083
Threat ID
35
Version
IOC
Indicator Type

Threat Description

When a cross-tenant synchronization is configured, a trust relationship between a source tenant and a target tenant is established. By modifying existing or creating a cross tenant access configuration, a threat actor who has access to the source tenant might obtain a long-term persistence in the target tenant or elevate their permissions in the target tenant by including synced accounts into privileged groups.

MITRE ATT&CK: Attack Tactics

Defense Evasion Persistence Privilege Escalation

D3FEND: Defend Tactics

Platform Monitoring

Remediation

Review changes in the configuration of cross-tenant synchronization.

To delete unwanted configurations:
  1. Sign in to the Microsoft Entra admin center as a Security Administrator or Global Administrator.
  2. Select Identity > External Identities > Cross-tenant synchronization.
  3. On the Configurations page, add a checkmark next to the configuration you want to delete.
  4. Select Delete.
  5. Select OK.

Frequently Asked Questions

What does Microsoft Entra tenant with recent changes in Cross Tenant Access configuration mean?

When a threat actor modifies existing or creates a new cross-tenant access configuration, it can allow them to maintain unauthorized access or elevate privileges in the target tenant. This change may occur during account synchronization and might not be immediately apparent.

This threat is rated high severity because it enables an attacker to maintain unauthorized access or elevate privileges in the target tenant, providing them with significant control and flexibility. This can be particularly concerning if synced accounts are involved.

An attacker can exploit a misconfigured cross-tenant synchronization by maintaining unauthorized access or elevating their privileges in the target tenant. This allows them to include synced accounts in privileged groups, granting them control and flexibility within the target environment.

Cayosoft Guardian continuously monitors cross-tenant access configurations across the Entra ID platform. When a change is detected, Guardian flags it as a security issue so administrators can review and address the potential threat.

Cayosoft Guardian helps mitigate this risk by providing visibility into cross-tenant access configurations, allowing administrators to identify and delete unwanted configurations. This limits the potential for attackers to maintain unauthorized access or elevate privileges in the target tenant.

Stop AD Threats As They Happen

Cayosoft Protector provides continuous monitoring and real-time alerts across your entire Microsoft Identity stack

Classification
Systems
Entra ID
Themes
Cross-tenant
Attack Tactics
Defense Evasion Persistence Privilege Escalation
Defend Tactics
Platform Monitoring
Indicator Types
IOC
Related Threats
CTD-000139
Kerberos Constrained Delegation: krbtgt Risks
Critical
CTD-000122
Active Directory Schema Update Permission Risks
Critical