CTD-000023

Microsoft Entra tenant with unsecure delegation of Global Admin role

Low
Entra ID
Persistence
v31

Signature Identity

CTD-000023
Threat ID
31
Version
IOE
Indicator Type

Threat Description

Having only one global administrator account is a potential threat to your environment. There should be at least two accounts for redundancy and audit purposes. With only one global administrator a threat actor can perform malicious activities and she will not be discovered by another administrator. However, too many global administrator accounts increase the possibility that one of the accounts will be breached by a threat actor.

MITRE ATT&CK: Attack Tactics

Persistence

D3FEND: Defend Tactics

User Account Permissions

Remediation

  1. To review accounts with Global Admin role:
    1. Log in to Microsoft 365 admin center as a Global Administrator.
    2. Select Users.
    3. Select Active Users.
    4. Select Filter then select Global Admins.
    5. Review the list of Global Admins.
  2. To assign or de-assign Global Administrator role using the Microsoft Entra admin center follow the instructions.

Frequently Asked Questions

What does Microsoft Entra tenant with unsecure delegation of Global Admin role mean?

In a Microsoft Entra tenant, an unsecure delegation of the Global Admin role occurs when there is only one global administrator account. This configuration allows unauthorized access to sensitive administrative functions and increases the risk of malicious activities.

This issue is rated low severity because an attacker would still need additional steps or context to exploit the vulnerability. However, having only one global administrator account increases the risk of malicious activities and makes detection more difficult.

An attacker who gains access to a single global administrator account in a Microsoft Entra tenant can use that account to perform unauthorized administrative actions, such as creating new users or modifying group memberships. This allows the attacker to persist and evade detection.

Cayosoft Guardian detects this issue by continuously monitoring the number of global administrator accounts in your Microsoft Entra tenant. When only one account is found, Guardian flags it as a security issue so administrators are aware of the potential threat.

Cayosoft Guardian helps reduce this risk by alerting administrators to review and adjust their global administrator accounts. This ensures that there are at least two accounts for redundancy and audit purposes, reducing the risk of unauthorized access to sensitive administrative functions.

Stop AD Threats As They Happen

Cayosoft Protector provides continuous monitoring and real-time alerts across your entire Microsoft Identity stack

Classification
Systems
Entra ID
Themes
Delegation Tenant-wide
Attack Tactics
Persistence
Defend Tactics
User Account Permissions
Indicator Types
IOE
Related Threats
CTD-000139
Kerberos Constrained Delegation: krbtgt Risks
Critical
CTD-000122
Active Directory Schema Update Permission Risks
Critical