CTD-000203

Microsoft Intune Multi Admin Approval access policies not configured

High
Entra ID Intune
Defense Evasion Impact Privilege Escalation
v3

Signature Identity

CTD-000203
Threat ID
3
Version
IOE
Indicator Type

Threat Description

This threat identifies an Intune tenant where no Multi Admin Approval access policies are configured.

Without Multi Admin Approval access policies, a compromised or malicious administrator account can perform sensitive actions without independent validation.

For example, if a threat actor compromises an Intune administrator account and no Multi Admin Approval access policies exist, the attacker could deploy a malicious line-of-business app, weaken compliance requirements, or initiate device wipe actions without approval from another administrator.

MITRE ATT&CK: Attack Tactics

Defense Evasion Impact Privilege Escalation

D3FEND: Defend Tactics

Application Configuration Hardening

Remediation

Configure Multi Admin Approval access policies in Microsoft Intune to require independent approval for sensitive administrative actions.

  1. Go to the Microsoft Intune admin center.
  2. Select Tenant administration > Multi Admin Approval > Access policies.
  3. Select Create.
  4. Create access policies for high-risk resource types. Configure policies for as many supported resource types as possible, including:
    • Apps
    • Scripts
    • Device actions, such as wipe, retire, and delete actions
    • Device configuration policies, such as Settings catalog policies
    • Device compliance policies
    • Access policies, to protect Multi Admin Approval policy changes
  5. For each access policy:
    1. Enter a clear Name and, optionally, a Description.
    2. Select the required Profile type. Each access policy supports only one profile type.
    3. On the Approvers tab, select Add groups.
    4. Select one or more Microsoft Entra security groups that contain trusted approvers.
  6. Review the policy settings, and then create the policy.

Important: Approver groups should include at least two or three trusted members. Approvers must have the required Intune permissions, such as an Intune license or assignment to an appropriate Intune role. To prevent self-approval, do not include the same administrators in both the requester and approver groups for the same policy.

Note: The first access policy might require approval from another administrator before it becomes active.

Frequently Asked Questions

What does Microsoft Intune Multi Admin Approval access policies not configured mean?

Microsoft Intune Multi Admin Approval access policies not configured means that no Multi Admin Approval access policies are set up in your Intune tenant. This allows a compromised or malicious administrator account to perform sensitive actions without independent validation, such as deploying apps or initiating device wipe actions.

This configuration is rated high severity because it enables an attacker to gain elevated privileges and perform unauthorized actions, which can lead to data breaches and security incidents. The lack of approval requirements allows a compromised administrator account to bypass validation checks, making it easier for attackers to exploit vulnerabilities.

Attackers can exploit the lack of Multi Admin Approval access policies in an Intune tenant by compromising an administrator account and performing sensitive actions without independent validation, such as deploying malicious apps or initiating device wipe actions. This enables them to gain unauthorized access to sensitive data and disrupt business operations.

Cayosoft Guardian detects Microsoft Intune Multi Admin Approval access policies not configured by continuously monitoring the configuration of Multi Admin Approval access policies in your Intune tenant and flagging any missing or incomplete configurations, ensuring that approval requirements are properly set up.

Cayosoft Guardian helps reduce the risk by alerting administrators to set up and configure Multi Admin Approval access policies, which requires independent validation for sensitive actions. This limits the potential impact of a compromised administrator account and prevents unauthorized data access.

Stop AD Threats As They Happen

Cayosoft Protector provides continuous monitoring and real-time alerts across your entire Microsoft Identity stack

Classification
Systems
Entra ID Intune
Themes
Account protection Privileged Access Management Tenant-wide
Attack Tactics
Defense Evasion Impact Privilege Escalation
Defend Tactics
Application Configuration Hardening
Indicator Types
IOE
Related Threats
CTD-000139
Kerberos Constrained Delegation: krbtgt Risks
Critical
CTD-000122
Active Directory Schema Update Permission Risks
Critical