Hidden in Plain Sight: Abusing Entra ID Administrative Units for Sticky Persistence
ID: 22ff7620-2754-5159-9870-09d3af2c5eaf
STIX ID: report--22ff7620-2754-5159-9870-09d3af2c5eaf
Feed Name: Datadog Security Labs
This Datadog SecurityLabs report analyzes how Microsoft Entra ID Administrative Units (AUs) can be legitimately used for least-privilege management but also abused by attackers with Global Administrator or Privileged Role Administrator privileges: restricted management AUs can make backdoor accounts difficult for tenant-wide admins to modify or remove, while hidden membership AUs can conceal which users are in scope for scoped role assignments; the report includes reproduction steps, Stratus Red Team emulations, detection recommendations using Entra audit logs, and remediation/playbook guidance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
