Azure / Entra ID Management Plane Compromise — Application Persistence, Role Takeover, and Golden SAML
Evidence-driven containment, persistence removal, and tenant recovery for scenarios where the Entra ID management plane is compromised via application secret/certificate addition, privileged role assignment, Golden SAML exploitation, or federated domain abuse.
Prepare
6 steps- Log sources active and routed
Entra ID `SigninLogs`, `AuditLogs`, `AADNonInteractiveUserSignInLogs` must be streaming to Sentinel and retained for at least 90 days; persistence detection requires long-term log retention
- Detection rules live
App secret/cert addition (DR-AE-3), admin role assignment (DR-AE-4), unauthorized consent (DR-AE-2), Golden SAML indicator (DR-AE-9), honey-admin alert (DR-AE-11) must be tuned and active in production
- Configuration baseline ready
A current snapshot of application registrations, service principals, all role assignments, CA policies, and federation trusts is required; mandatory for delta analysis at incident time
- AAD Connect / Entra Connect inventory completed
Inventory of AD DS Connector, ADSync, and Entra Connector accounts must be complete; compromise of these accounts puts the entire hybrid environment at risk
- RACI and approval chain defined
Bulk token revocation (tenant-wide), federation trust changes, and ADFS certificate rotation are destructive actions; Entra/M365 Admin + CISO + change board sign-off is mandatory
- Escalation chain