CTD-000061

Stale Microsoft Entra device

Low
Entra ID Intune
Credential Access
v32

Signature Identity

CTD-000061
Threat ID
32
Version
IOE
Indicator Type

Threat Description

Stale devices include devices that haven’t signed in for a specified time period. Devices can become stale when a user gets a new device or loses a device, or when a Microsoft Entra joined device is wiped or reprovisioned. Devices might also remain registered or joined when the user is no longer associated with the tenant. Stale devices should be removed so the primary refresh tokens (PRTs) cannot be used by a threat actor.

MITRE ATT&CK: Attack Tactics

Credential Access

D3FEND: Defend Tactics

Authentication Cache Invalidation

Remediation

To remove a device:

  1. In the Microsoft Intune admin center, select Devices in the left navigation pane.
  2. Click on All devices.
  3. Click on device you want to delete.
  4. Click Delete which opens a fly-in to remove the device.
  5. In the fly-in, review the selected device.
  6. Select Yes. Device removal can take a few minutes to complete.

Important: Removing the objects related to a device from Microsoft Entra ID and Microsoft Intune is permanent. If you remove the objects, you won’t be able to view or manage the devices from the Intune and Microsoft Entra admin centers. The devices won’t be able to access their company’s corporate resources. Company data might be deleted from them if the devices try to sign in after they’re deleted.

Frequently Asked Questions

What does Stale Microsoft Entra device mean?

A stale Microsoft Entra device refers to a device that has not signed in for a specified time period, causing primary refresh tokens (PRTs) to remain active. This can occur when a user gets a new device or loses a device, or when a Microsoft Entra joined device is wiped or reprovisioned.

Stale Microsoft Entra devices are rated low severity because they do not directly grant administrative control. However, they expose credentials and increase the attack surface for attackers, allowing them to access company resources through primary refresh tokens (PRTs).

Attackers can use stale Microsoft Entra devices by signing in with primary refresh tokens (PRTs), which remain active due to the device's inactive state. This allows them to access company resources, but their privileges are limited to those of the original user.

Cayosoft Guardian detects stale Microsoft Entra devices by continuously monitoring the state of devices in Microsoft Intune. When a device is found to be stale, Guardian flags it as a security issue so administrators are aware of the potential exposure.

Cayosoft Guardian helps reduce the risk of stale Microsoft Entra devices by alerting administrators to remove the devices from Microsoft Intune, revoking primary refresh tokens (PRTs) and preventing unauthorized access.

Stop AD Threats As They Happen

Cayosoft Protector provides continuous monitoring and real-time alerts across your entire Microsoft Identity stack

Classification
Systems
Entra ID Intune
Themes
Account protection
Attack Tactics
Credential Access
Defend Tactics
Authentication Cache Invalidation
Indicator Types
IOE
Related Threats
CTD-000139
Kerberos Constrained Delegation: krbtgt Risks
Critical
CTD-000122
Active Directory Schema Update Permission Risks
Critical