(In)tuned to Takeovers: Abusing Intune Permissions for Lateral Movement and Privilege Escalation in Entra ID Native Environments
ID: 6470413d-f306-5e07-a95d-5fb7212d8ffd
STIX ID: report--6470413d-f306-5e07-a95d-5fb7212d8ffd
Feed Name: Google Cloud Threat Intelligence
Mandiant's red team demonstrated a novel attack path where, after gaining initial access to an Entra ID tenant, they abused the DeviceManagementConfiguration.ReadWrite.All permission granted to a service principal to compromise Intune-managed Privileged Access Workstations (PAWs) and escalate to Global Administrator by adding credentials to existing service principals; the report outlines the pretext, attack path, and recommends mitigations and detection strategies.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
