logo

(In)tuned to Takeovers: Abusing Intune Permissions for Lateral Movement and Privilege Escalation in Entra ID Native Environments

ID: 6470413d-f306-5e07-a95d-5fb7212d8ffd

STIX ID: report--6470413d-f306-5e07-a95d-5fb7212d8ffd

Feed Name: Google Cloud Threat Intelligence

Threat Score
75/100

Date Published: 2024-11-06

Date Updated: 2026-04-27

Author: Mandiant

...
...

Mandiant's red team demonstrated a novel attack path where, after gaining initial access to an Entra ID tenant, they abused the DeviceManagementConfiguration.ReadWrite.All permission granted to a service principal to compromise Intune-managed Privileged Access Workstations (PAWs) and escalate to Global Administrator by adding credentials to existing service principals; the report outlines the pretext, attack path, and recommends mitigations and detection strategies.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.