CTD-000156

Unauthorized changes to compliance policies

High
Entra ID Intune
Defense Evasion Impair Defenses (T1562) Persistence Privilege Escalation
v17

Signature Identity

CTD-000156
Threat ID
17
Version
IOC
Indicator Type

Threat Description

Unauthorized changes to compliance policies weaken your organization's security by potentially allowing non-compliant or compromised devices to access corporate resources. Such changes may indicate that a threat actor has gained administrative access and is attempting to bypass security controls. Monitoring compliance policy changes ensures that the integrity of your device management environment remains intact.

A threat actor who gains administrative access could alter compliance policies to reduce security requirements, allowing non-compliant devices (such as those lacking encryption or updated software) to access critical systems. By detecting these unauthorized changes, the organization can quickly respond and restore secure policies, mitigating the risk of compromised devices accessing sensitive resources.

MITRE ATT&CK: Attack Tactics

Defense Evasion Impair Defenses (T1562) Persistence Privilege Escalation

D3FEND: Defend Tactics

D3-RC Restore Configuration D3-SCP System Configuration Permissions

Remediation

  1. Review Intune audit logs to identify the user or account responsible for the compliance policy changes.
  2. Verify whether the changes align with the organization's policy change schedule and confirm that the account used was authorized to make such modifications.
  3. If the change was unauthorized, revert the compliance policy to its last known secure configuration using compliance policy versioning or configuration backups to restore the correct policy.
  4. Temporarily suspend the user account or administrative role that made the change if it appears suspicious.
  5. Validate this action by checking Sign-In Logs and Conditional Access Logs in Entra ID for any signs of suspicious activity or credential misuse.
  6. Conduct a thorough review of access permissions to ensure that only authorized administrators can modify compliance policies.
  7. Enforce proper Role-Based Access Control (RBAC) by reviewing role assignments in Intune.

Frequently Asked Questions

What does Unauthorized changes to compliance policies mean?

Unauthorized changes to compliance policies refer to modifications made to the organization's compliance policies without proper authorization, potentially altering security settings and configurations.

This is because unauthorized changes indicate a potential security breach, allowing an attacker with administrative access to modify policy settings and reduce security requirements. The modified configuration settings can then be exploited by attackers to bypass security controls.

Attackers can exploit unauthorized changes to compliance policies by altering the policies to allow non-compliant or compromised devices to access corporate resources, potentially bypassing security controls through modified configuration settings. This allows attackers to gain persistence and reconnaissance capabilities within the organization's network.

Cayosoft Guardian detects unauthorized changes to compliance policies by continuously monitoring the organization's Intune audit logs for suspicious activity, such as policy modifications or deletions, and flags them as security issues. This provides visibility into potential security threats and supports investigation and response efforts.

Cayosoft Guardian helps reduce the risk by alerting administrators to review Intune audit logs, verify policy changes, and revert to secure configurations if necessary. This ensures that only authorized administrators can modify compliance policies, providing a more secure administrative scope.

Stop AD Threats As They Happen

Cayosoft Protector provides continuous monitoring and real-time alerts across your entire Microsoft Identity stack

Classification
Systems
Entra ID Intune
Themes
Policy Configuration Management
Attack Tactics
Defense Evasion Impair Defenses (T1562) Persistence Privilege Escalation
Defend Tactics
D3-RC Restore Configuration D3-SCP System Configuration Permissions
Indicator Types
IOC
Related Threats
CTD-000139
Kerberos Constrained Delegation: krbtgt Risks
Critical
CTD-000122
Active Directory Schema Update Permission Risks
Critical