CTD-000097

Microsoft Entra user with authentication phone details modified by another user

Medium
Entra ID
Defense Evasion
v27

Signature Identity

CTD-000097
Threat ID
27
Version
IOA-IOC
Indicator Type

Threat Description

A Microsoft Entra user whose authentication details were modified by another user might be an indication of threat activities. A threat actor might perform such a change to receive multifactor authentication messages for a compromised account and get access to the resources.

MITRE ATT&CK: Attack Tactics

Defense Evasion

D3FEND: Defend Tactics

Application Configuration Hardening

Remediation

  1. Contact the initiator to check if the phone number change is valid.
  2. Review the activity of the user.

Frequently Asked Questions

What does Microsoft Entra user with authentication phone details modified by another user mean?

A Microsoft Entra user's multifactor authentication settings have been altered by someone other than the user themselves, potentially indicating unauthorized access or compromise. This change allows an attacker to receive multifactor authentication messages for a compromised account.

This issue is rated medium severity because it indicates a potential security vulnerability that could be exploited by attackers. The modification of authentication phone details enables an attacker to receive multifactor authentication messages for a compromised account, which can support later attacker activity such as persistence and reconnaissance.

Attackers could use this vulnerability to gain unauthorized access to a Microsoft Entra user's account. By modifying the user's authentication phone details, an attacker may receive multifactor authentication messages for a compromised account, which enables them to bypass security controls and maintain persistence.

Cayosoft Guardian continuously monitors changes to Microsoft Entra user settings, including multifactor authentication configurations. When an unauthorized change is detected, Guardian flags it as a security issue and provides visibility into the activity of the user who made the change.

Cayosoft Guardian alerts administrators to potential security issues, enabling them to investigate and take corrective action. This includes reviewing the activity of the user who made the change and verifying its legitimacy, as well as showing change history and supporting investigation.

Stop AD Threats As They Happen

Cayosoft Protector provides continuous monitoring and real-time alerts across your entire Microsoft Identity stack

Classification
Systems
Entra ID
Themes
Account protection MFA
Attack Tactics
Defense Evasion
Defend Tactics
Application Configuration Hardening
Indicator Types
IOA IOC
Related Threats
CTD-000139
Kerberos Constrained Delegation: krbtgt Risks
Critical
CTD-000122
Active Directory Schema Update Permission Risks
Critical