logo

Hidden in Plain Sight: Abusing Entra ID Administrative Units for Sticky Persistence

ID: 22ff7620-2754-5159-9870-09d3af2c5eaf

STIX ID: report--22ff7620-2754-5159-9870-09d3af2c5eaf

Feed Name: Datadog Security Labs

Threat Score
60/100

Date Published: 2024-09-16

Date Updated: 2026-04-27

...
...

This Datadog SecurityLabs report analyzes how Microsoft Entra ID Administrative Units (AUs) can be legitimately used for least-privilege management but also abused by attackers with Global Administrator or Privileged Role Administrator privileges: restricted management AUs can make backdoor accounts difficult for tenant-wide admins to modify or remove, while hidden membership AUs can conceal which users are in scope for scoped role assignments; the report includes reproduction steps, Stratus Red Team emulations, detection recommendations using Entra audit logs, and remediation/playbook guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.