Microsoft Incident Response lessons on preventing cloud identity compromise
ID: 1f407174-b332-512d-a9ae-c0a3b9493412
STIX ID: report--1f407174-b332-512d-a9ae-c0a3b9493412
Feed Name: Microsoft Security
Microsoft IR details a surge in identity-focused attacks and the most common Microsoft Entra ID/hybrid identity weaknesses that enable tenant compromise—such as compromised AD FS, token theft via AiTM and malware, excessive user/workload privileges, Conditional Access gaps, device and application access misconfigurations, risky partner (DAP) rights, OAuth consent phishing, and SSPR/MFA social engineering—and provides prioritized mitigations including adopting native Entra authentication, least privilege and PIM, phishing-resistant MFA, hardened admin workstations, strong logging and monitoring, Conditional Access simplification and enforcement, granular partner access (GDAP), and token protection to reduce paths to tenant takeover.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
