Skip to content
Threat Feed

Tag

Entra Id

27 briefs RSS
high advisory

Microsoft Entra ID Temporary Access Pass (TAP) Abuse for MFA Bypass and Persistence

An attacker with elevated privileges abuses the Microsoft Entra ID Temporary Access Pass (TAP) feature to bypass multi-factor authentication (MFA), gain unauthorized access to target user accounts, and establish persistence by registering new authentication methods.

Microsoft Entra ID cloud identity azure entra-id mfa-bypass persistence lateral-movement initial-access
3r 2t
high advisory

M365 or Entra ID Identity Sign-in from a Suspicious Source

This rule correlates Entra-ID or Microsoft 365 mail successful sign-in events with network security alerts by source address, indicating potential initial access via compromised credentials.

Entra ID +1 initial-access cloud entra-id m365
2r 1t
medium advisory

Entra ID OAuth User Impersonation to Microsoft Graph

This rule detects potential session hijacking or token replay in Microsoft Entra ID, identifying cases where a user signs in and subsequently accesses Microsoft Graph from a different IP address using the same session ID, which may indicate a successful OAuth phishing attack, session hijacking, or token replay attack.

Entra ID +1 cloud identity api azure oauth session hijacking
2r 2t
medium advisory

Entra ID Sign-in Brute Force Attempt Against Microsoft 365

A high volume of failed Microsoft Entra ID sign-in attempts against Microsoft 365 services within a short time period indicates a potential brute-force attack, which could lead to unauthorized access to Microsoft 365 services.

Microsoft 365 +4 azure entra-id microsoft-365 brute-force credential-access
2r 1t
medium advisory

Entra ID Device Code Authentication Abuse via Malicious Broker Client

Adversaries are abusing Entra ID device code authentication using a malicious broker client to bypass MFA and gain unauthorized access to Azure resources by compromising Primary Refresh Tokens (PRTs).

Azure +1 entra-id device-code-authentication prt
2r 2t 4i
medium advisory

Entra ID OAuth Device Code Grant by Unusual User

An attacker uses device code authentication in Entra ID to phish users and steal access tokens, leading to unauthorized access and potential defense evasion.

Entra ID azure entra-id device-code phishing
2r 3t
high advisory

Entra ID OAuth Phishing via Auth Broker to DRS

Detection of OAuth phishing in Microsoft Entra ID through Microsoft Authentication Broker (MAB) and Device Registration Service (DRS) indicated by the same user principal and session ID originating from multiple IP addresses within a short timeframe, indicative of unauthorized token acquisition.

Microsoft Entra ID +3 entra-id oauth-phishing initial-access
2r 1t 2i
high advisory

Entra ID Concurrent Sign-in with Suspicious Properties

This rule identifies concurrent Azure sign-in events for the same user from multiple sources, where at least one authentication event exhibits suspicious properties associated with DeviceCode and OAuth phishing, potentially indicating refresh token theft.

Azure Entra ID +2 azure entra-id credential-access phishing
2r 4t
medium advisory

EntraFalcon Security Posture Assessment Tool

EntraFalcon is a security tool designed to enumerate and assess the security posture of Entra ID tenants, identifying misconfigurations and vulnerabilities related to users, groups, applications, roles, PIM settings, and Conditional Access policies.

Entra ID entra-id azure-ad security-assessment misconfiguration cloud-security
2r 3t 2i
high advisory

Entra ID OAuth Device Code Flow Phishing

Attackers are leveraging device code phishing to steal application access tokens from users of Entra ID OAuth applications, by tricking users into entering codes into attacker-controlled polling clients, leading to unauthorized access to cloud resources.

Microsoft Entra ID +2 entra-id oauth device-code-phishing credential-access
2r 3t
medium threat

Entra ID Unusual ROPC Login Attempt

Detects unusual resource owner password credential (ROPC) login attempts by a user principal in Microsoft Entra ID, potentially indicating account compromise or password spraying.

exploited Microsoft Entra ID azure entra-id ropc initial-access
2r 2t
high advisory

Entra ID Protection Detects User Risk

Entra ID Protection detects user risk activity such as anonymized IP addresses, unlikely travel, password spray, and other suspicious behaviors indicating potential initial access attempts and compromised accounts within cloud environments.

Entra ID azure entra-id risk-detection initial-access
3r 4t
medium advisory

Entra ID Service Principal Federated Credential Authentication by Unusual Client

Detection of initial Entra ID service principal authentication using a federated identity credential, potentially indicating a rogue identity provider abusing compromised applications.

Entra ID entra-id federated-credentials byoidp initial-access
2r 3t
medium advisory

Entra ID Service Principal Sign-in from Unusual ASN

Detection of Entra ID service principal sign-ins originating from a previously unseen combination of workload identity and source autonomous system number (ASN), potentially indicating compromised credentials or malicious activity.

Entra ID azure entra-id service-principal initial-access
2r 2t
medium advisory

Entra ID Illicit Consent Grant via Registered Application

Attackers register malicious applications within Entra ID and deceive users into granting extensive permissions through OAuth consent, enabling unauthorized access to sensitive data like emails and files.

Microsoft Entra ID azure entra-id oauth illicit-consent
2r 3t
high advisory

M365 or Entra ID Identity Sign-in from a Suspicious Source

Correlates successful Entra ID or Microsoft 365 sign-in events with network security alerts based on the source IP address, indicating potential initial access from suspicious sources.

Microsoft 365 +1 cloud azure m365 entra-id initial-access
2r 1t
medium advisory

Entra ID User Sign-in with Unusual Client Application

Adversaries with stolen credentials or OAuth tokens may abuse Entra ID-managed or first-party client IDs to perform on-behalf-of (OBO) authentication, blending into legitimate cloud traffic and evading detection by using a rare application ID for principal authentication.

Entra ID +1 azure entra-id initial-access oauth
2r 3t
medium advisory

Detect Windows Entra User Management Via Azure CLI

This analytic detects the usage of the Azure CLI to interact with user accounts, such as creating or deleting a user, potentially indicating malicious activity aimed at maintaining persistence and evading detection within an Entra ID environment.

Azure CLI +3 azure entra-id user-management persistence windows
2r 3t
medium advisory

Entra ID User Reported Suspicious Activity

This rule detects suspicious activity reported by users in Microsoft Entra ID, indicating potential account compromise or unauthorized access attempts via social engineering during authentication.

Entra ID +1 entra-id suspicious-activity initial-access credential-access
2r 2t
high advisory

Entra ID Protection - Sign-in Risk Detection

This brief covers detection of sign-in risk events identified by Microsoft Entra ID Protection, including anonymized IP addresses, unlikely travel, and password spray attacks, which can indicate compromised accounts or malicious activity.

Microsoft Entra ID +1 azure entra-id identity-protection sign-in-risk initial-access
3r 4t
low advisory

Entra ID PowerShell Sign-in

Detection of successful sign-ins using the Azure Active Directory PowerShell module to identify potentially unauthorized administrative actions in Entra ID.

Entra ID +1 azure entra-id powershell initial-access
2r 2t
medium advisory

Entra ID OAuth Authorization Code Grant for Unusual User, App, and Resource

Detects the first-time use of an OAuth 2.0 authorization code grant flow for a specific combination of user, application, and resource in Microsoft Entra ID, potentially indicating OAuth phishing attacks like ConsentFix, where attackers steal authorization codes.

Microsoft Entra ID +2 entra-id oauth phishing initial-access
2r 3t
medium advisory

Entra ID External Authentication Methods (EAM) Modified

Modification of Entra ID external authentication methods (EAM) via the Microsoft Graph API can allow attackers to bypass multi-factor authentication (MFA) and establish persistence or gain unauthorized access via bring-your-own IdP (BYOIDP) methods.

Entra ID azure entra-id persistence authentication
2r 2t
high advisory

Entra ID Excessive Account Lockouts Detected

Adversaries may attempt to brute-force user accounts using password spraying or credential stuffing, leading to account lockouts by Entra ID Smart Lockout policies, which this rule detects by identifying a high count of failed Microsoft Entra ID sign-in attempts due to account lockouts (error code 50053).

Entra ID cloud credential-access azure entra-id
2r 3t
high advisory

Entra ID Domain Federation Configuration Change

Adversaries with Global Administrator or Domain Administrator privileges may add a custom domain, verify ownership, and configure it to federate authentication with an attacker-controlled identity provider, allowing token forgery and bypassing MFA and conditional access policies for persistent, stealthy access to victim tenants.

Entra ID azure entra-id domain-federation privilege-escalation
3r 4t
low advisory

Entra ID Custom Domain Added or Verified

Detection of custom domain additions or verifications in Entra ID, a precursor to potentially malicious domain federation for Golden SAML attacks.

Microsoft Entra ID azure entra-id domain-federation golden-saml
2r 1t
low advisory

Entra ID User Sign-in with Unusual Non-Managed Device

Detects Microsoft Entra ID user sign-ins from devices not typically used or managed, indicating potential account compromise or unauthorized access via device registration for persistence.

Microsoft Entra ID azure entra-id persistence device-registration
2r 2t