CTD-000068

Microsoft Entra user retrieving Bitlocker keys

Medium
Entra ID
Credential Access
v30

Signature Identity

CTD-000068
Threat ID
30
Version
IOC
Indicator Type

Threat Description

Intune enables BitLocker Drive Encryption on devices that run Windows 10/11 and stores recovery keys in the Microsoft Entra ID. A threat actor can misuse the recovery keys to decrypt drives and get access to data.

MITRE ATT&CK: Attack Tactics

Credential Access

D3FEND: Defend Tactics

Credential Revoking

Remediation

Investigate user’s activity. Note: To use the key a threat actor requires a physical access to the device.

Frequently Asked Questions

What does Microsoft Entra user retrieving Bitlocker keys mean?

When a Microsoft Entra user accesses the recovery keys for BitLocker Drive Encryption stored in the Microsoft Entra ID tenant, it allows an attacker to decrypt devices running Windows 10/11 using those keys. This enables unauthorized access to data on those drives.

This vulnerability allows an attacker to bypass security controls and gain unauthorized access to sensitive information, but does not grant administrative control or escalate privileges. The exposure requires physical access to the device.

An attacker can use the retrieved BitLocker recovery keys to decrypt devices and gain unauthorized access to data on those drives, potentially exfiltrating sensitive information. This capability enables attackers to bypass security controls and maintain persistence.

Cayosoft Guardian detects Microsoft Entra user retrieving Bitlocker keys by monitoring access to recovery keys in the Microsoft Entra ID tenant. When an unauthorized user accesses these keys, Guardian flags it as a security issue and provides visibility into the attack path.

Cayosoft Guardian helps reduce the risk by alerting administrators to investigate user activity, enabling teams to quickly identify and address potential security incidents. This support investigation and response enables administrators to show change history and assist in reviewing user access.

Stop AD Threats As They Happen

Cayosoft Protector provides continuous monitoring and real-time alerts across your entire Microsoft Identity stack

Classification
Systems
Entra ID
Themes
Account protection Data protection
Attack Tactics
Credential Access
Defend Tactics
Credential Revoking
Indicator Types
IOC
Related Threats
CTD-000139
Kerberos Constrained Delegation: krbtgt Risks
Critical
CTD-000122
Active Directory Schema Update Permission Risks
Critical