Skip to content
BreachPathAttack Path LibraryStart
IntermediateAccount takeoverData theft

Entra ID guest account to privileged access

An over-permissioned external guest identity is used to enumerate the tenant, abuse excessive directory rights and escalate toward privileged roles and the resources they unlock.

Technologies
Microsoft 365, Azure
Entry points
Stolen credentials, Supplier compromise
Sectors
SaaS & technology, Professional services, Financial services
Stages
3
01

An external guest identity is controlled

The attacker gains control of a guest account — through a compromised partner or reused credentials — that was invited for collaboration but retains broad default directory visibility.

Attacker objective

Operate as a legitimate external collaborator invited into the tenant.

Controls that should stop this
  • Restrict guest permissions to the most limited directory role
  • Conditional Access and MFA applied to guest identities
  • Regular review and expiry of external guest access
What defenders should see
  • Guest sign-ins from new locations or devices
  • Guest accounts accessing resources beyond their invited scope
  • Dormant guest accounts becoming active
What a pentest validates
  • Review default guest permissions and what they can enumerate
  • Test Conditional Access coverage for external identities
  • Audit stale and over-scoped guest accounts
Business impact

An external identity is now operating inside the tenant with more visibility than intended.

02

The directory is enumerated for escalation opportunities

Using default directory read access, the attacker enumerates role assignments, group memberships and application permissions, searching for misconfigurations — such as groups that grant privileged roles or apps with excessive permissions.

Attacker objective

Map users, groups, roles and applications to find a way to greater privilege.

Controls that should stop this
  • Restrict directory read access for guests and standard users
  • Remove dynamic or self-service groups that confer privileged roles
  • Least-privilege application permissions with regular review
What defenders should see
  • Heavy directory-read and role-enumeration activity by a guest
  • Access to role and group configuration objects
  • First-seen enumeration patterns for the identity
What a pentest validates
  • Enumerate what a guest can discover about roles and groups
  • Identify groups or apps that provide a privilege-escalation path
  • Review application permission grants for over-privilege
Business impact

The attacker identifies a concrete route from guest access toward privileged control.

03

Privileged role or resource access is obtained

The attacker abuses the identified path — for example self-adding to a group that grants a privileged role, or leveraging an over-permissioned application — to gain access to administrative capability or the underlying subscriptions and data.

Attacker objective

Turn a discovered misconfiguration into privileged role membership or direct resource access.

Controls that should stop this
  • Privileged Identity Management with approval and time-bound elevation
  • Alerting on privileged role assignment and group changes
  • Separation of the identity plane from sensitive resource access
What defenders should see
  • Role assignment or activation events for the identity
  • Group-membership changes that confer privilege
  • Privileged actions from an account that was recently a guest
What a pentest validates
  • Attempt the identified escalation in an authorised test
  • Validate PIM approval and alerting on privileged elevation
  • Confirm sensitive resources are not reachable from the escalated role
Business impact

An external guest now holds privilege that exposes tenant-wide data and administration.

ATT&CK techniques in this chain

If this chain completes

A guest identity intended for limited collaboration becomes a foothold for tenant-wide access, exposing data and administrative capability that should never have been reachable externally.

Should you test this against your environment?

Turn this chain into a scoped red-team brief — objective, systems and identities in scope, testing assumptions and the questions to answer before commissioning.