"Iβ―SPy" Entraβ―ID Global Admin Escalation Technique
Datadog's Security Labs identified an abuse of Office 365 Exchange Online service principal (SP) allowing escalation to Global Admin. MSRC considers it "expected misconfiguration" so don't expect a fix.
π¨ Alert on new credentials added to SPs.
π₯ Monitor changes to federated domains (federationConfiguration).
π΅πΌββοΈ Hunt unusual Graph API calls to /domains, /credentials, and /federationConfiguration.
π https://securitylabs.datadoghq.com/articles/i-spy-escalating-to-entra-id-global-admin/
#DFIR #ThreatHunting #EntraID #CloudForensics #M365 #ThreatDetection
