// BRIEFING

Entra ID. The keys to Microsoft 365. Entra ID. De sleutels van Microsoft 365.

Every mailbox, every file in SharePoint, every Teams chat and every admin right lives behind one identity system: Entra ID. Four ways the tenant gets taken over — with real examples — and the one setting that stops each. Elke mailbox, elk bestand in SharePoint, elke Teams-chat en elk beheerrecht zit achter één identiteitssysteem: Entra ID. Vier manieren waarop de tenant wordt overgenomen — met echte voorbeelden — en de ene instelling die elk ervan stopt.

// RISK 01RISICO 01

Too many people own the tenant. Te veel mensen bezitten de tenant.

standing Global Administrator rights / no Privileged Identity Management permanente Global Administrator-rechten / geen Privileged Identity Management
ONE PHISHED ADMINÉÉN GEPHISHTE BEHEERDER
🎣
Phishing mailPhishingmail
☁️
Our tenantOnze tenant
👤
👤
👤
👤
👤
👤
👤
7 GLOBAL ADMINS · ALWAYS ON7 GLOBAL ADMINS · ALTIJD ACTIEF
🎣
👑

Global Administrator is the master key of Microsoft 365. It reads every mailbox, changes every password, adds new administrators and turns off the logging that would show it happened. Most tenants hand that key to far more people than they think: the IT team, the helpdesk lead, two consultants from the migration project, a service account from 2018. All of them hold it permanently, whether they are using it or not. Attackers know this, so they do not attack the tenant. They phish one of those people.

Example: a helpdesk employee with standing Global Administrator rights approves a fake “Microsoft security update” login on a Monday morning. By lunch the attacker has added their own administrator, set up mailbox forwarding on the CFO and finance team, and created an application that keeps access even after every password is reset. Business impact: total loss of confidentiality over the company's email and files, and a recovery that means rebuilding trust in the entire tenant, not just one account.

Global Administrator is de hoofdsleutel van Microsoft 365. Die leest elke mailbox, wijzigt elk wachtwoord, voegt nieuwe beheerders toe en zet de logging uit die zou laten zien dat het gebeurde. De meeste tenants geven die sleutel aan veel meer mensen dan ze denken: het IT-team, de teamleider van de helpdesk, twee consultants van het migratieproject, een serviceaccount uit 2018. Ze hebben hem allemaal permanent, of ze hem nu gebruiken of niet. Aanvallers weten dat, dus ze vallen de tenant niet aan. Ze phishen één van die mensen.

Voorbeeld: een helpdeskmedewerker met permanente Global Administrator-rechten keurt op maandagochtend een nep-inlog voor een “Microsoft-beveiligingsupdate” goed. Tegen de lunch heeft de aanvaller een eigen beheerder toegevoegd, doorsturen ingesteld op de mailboxen van de CFO en het financeteam, en een applicatie aangemaakt die toegang houdt nadat elk wachtwoord is gereset. Bedrijfsimpact: volledig verlies van vertrouwelijkheid over de e-mail en bestanden van het bedrijf, en een herstel dat neerkomt op het opnieuw opbouwen van vertrouwen in de hele tenant, niet in één account.

ONE CLICK · WHOLE TENANT · PERSISTENTÉÉN KLIK · HELE TENANT · BLIJVEND FIX: PIM WITH JUST-IN-TIME ACTIVATION + ≤ 5 ELIGIBLE ADMINSOPLOSSING: PIM MET JUST-IN-TIME-ACTIVERING + ≤ 5 BEHEERDERS
// RISK 02RISICO 02

The gate is there. It is open. De poort staat er. Hij staat open.

Conditional Access gaps / legacy authentication / unmanaged devices gaten in Conditional Access / verouderde authenticatie / onbeheerde apparaten
SIGN-INS TODAYAANMELDINGEN VANDAAG
🌍
AnywhereOveral
📧
Mail & SharePointMail & SharePoint
🚧CONDITIONAL ACCESSCONDITIONAL ACCESS
📟LEGACY AUTH · NO MFA POSSIBLEVEROUDERDE AUTH · MFA ONMOGELIJK
📱PERSONAL PHONE · UNMANAGEDPRIVÉTELEFOON · ONBEHEERD
👤ADMIN · PASSWORD ONLYBEHEERDER · ALLEEN WACHTWOORD

Conditional Access is the gate in front of Microsoft 365: it decides, per sign-in, who gets in from where, on which device, and with what proof. Most tenants have a gate. Few have closed it. Legacy authentication — the old protocols used by IMAP, POP and ancient Office clients — cannot do MFA at all, and if it is still allowed, a password is enough. Administrators who are “too busy for MFA prompts” are exempted. Personal phones and home laptops that nobody manages open corporate mail and download SharePoint libraries.

Example: an attacker takes a password leaked from a hobby forum and signs in over legacy IMAP from another continent. Because that protocol cannot ask for a second factor, Entra ID lets it through, and the attacker quietly syncs three years of the sales director's mail. Business impact: the company believes it “has MFA” while the doors that matter still take a password alone. The fix is configuration, not licences: a baseline of policies that block legacy authentication, require MFA for everyone and require a managed device for anything sensitive.

Conditional Access is de poort vóór Microsoft 365: het beslist per aanmelding wie binnenkomt, vanwaar, op welk apparaat en met welk bewijs. De meeste tenants hebben een poort. Weinig hebben hem dichtgedaan. Verouderde authenticatie — de oude protocollen van IMAP, POP en stokoude Office-clients — kan helemaal geen MFA, en als die nog is toegestaan, volstaat een wachtwoord. Beheerders die “te druk zijn voor MFA-prompts” krijgen een uitzondering. Privételefoons en thuislaptops die niemand beheert, openen bedrijfsmail en downloaden SharePoint-bibliotheken.

Voorbeeld: een aanvaller pakt een wachtwoord dat lekte bij een hobbyforum en meldt zich via verouderd IMAP aan vanaf een ander continent. Omdat dat protocol geen tweede factor kan vragen, laat Entra ID het door, en de aanvaller synchroniseert ongemerkt drie jaar mail van de salesdirecteur. Bedrijfsimpact: het bedrijf denkt dat het “MFA heeft”, terwijl de deuren die ertoe doen nog steeds op alleen een wachtwoord opengaan. De oplossing is configuratie, geen licenties: een basisset beleidsregels die verouderde authenticatie blokkeert, MFA voor iedereen eist en een beheerd apparaat vereist voor alles wat gevoelig is.

“WE HAVE MFA” · BUT NOT WHERE IT COUNTS“WE HEBBEN MFA” · MAAR NIET WAAR HET TELT FIX: BLOCK LEGACY AUTH + MFA FOR ALL + COMPLIANT DEVICE FOR SENSITIVE APPSOPLOSSING: BLOKKEER VEROUDERDE AUTH + MFA VOOR IEDEREEN + BEHEERD APPARAAT VOOR GEVOELIGE APPS
// RISK 03RISICO 03

The guests never left. De gasten zijn nooit vertrokken.

external identities / guest accounts without an expiry externe identiteiten / gastaccounts zonder einddatum
GUEST LISTGASTENLIJST
2019
Agency designerOntwerper bureau
j.doe@agency.example
2021
Auditor, ex-firmAuditor, oud-kantoor
audit-team@old-firm.example
2023
Consultant, leftConsultant, vertrokken
consultant@personal.example
📁
Teams & filesTeams & bestanden

Inviting an outsider into Teams or a SharePoint site takes one click and creates a guest account in Entra ID. Removing it takes a decision nobody is assigned to make. So the list grows: the design agency from the rebrand, the auditors from two firms ago, a consultant who now works for a competitor and still logs in with a personal address. Guests keep every Team, channel and folder they were ever added to, and their home organisation — not you — controls how well their account is protected.

Example: a tenant review finds 1,400 guest accounts, 600 of which have not signed in for over a year, and one that still sits in the “Board – Confidential” Team from the 2021 strategy project. Business impact: board material, contracts and personnel files readable by people you no longer have a contract with, through accounts whose passwords you cannot enforce. A guest lifecycle — invite with an owner and an expiry date, review every quarter, remove on silence — turns an unknown into a managed list.

Een buitenstaander uitnodigen in Teams of een SharePoint-site kost één klik en maakt een gastaccount aan in Entra ID. Het verwijderen kost een beslissing die aan niemand is toegewezen. Dus groeit de lijst: het ontwerpbureau van de rebranding, de auditors van twee kantoren geleden, een consultant die nu bij een concurrent werkt en nog inlogt met een privéadres. Gasten houden elk Team, kanaal en elke map waaraan ze ooit zijn toegevoegd, en hun eigen organisatie — niet u — bepaalt hoe goed hun account beschermd is.

Voorbeeld: een tenantreview vindt 1.400 gastaccounts, waarvan 600 al meer dan een jaar niet zijn ingelogd, en één die nog in het Team “Directie – Vertrouwelijk” zit van het strategieproject uit 2021. Bedrijfsimpact: bestuursstukken, contracten en personeelsdossiers leesbaar voor mensen met wie u geen contract meer hebt, via accounts waarvan u het wachtwoordbeleid niet kunt afdwingen. Een gastlevenscyclus — uitnodigen met een eigenaar en een einddatum, elk kwartaal beoordelen, verwijderen bij stilte — maakt van een onbekende een beheerde lijst.

UNKNOWN READERS · UNENFORCEABLE PASSWORDSONBEKENDE LEZERS · NIET AFDWINGBARE WACHTWOORDEN FIX: GUEST EXPIRY + QUARTERLY ACCESS REVIEWS + OWNER PER GUESTOPLOSSING: EINDDATUM VOOR GASTEN + KWARTAALREVIEWS + EIGENAAR PER GAST
// RISK 04RISICO 04

The back door between two worlds. De achterdeur tussen twee werelden.

hybrid identity / Entra Connect / on-premises Active Directory hybride identiteit / Entra Connect / on-premises Active Directory
THE SYNC SERVERDE SYNCSERVER
🏢
On-prem AD (breached)On-prem AD (gehackt)
☁️
Entra IDEntra ID
🔄
ENTRA CONNECT · HOLDS BOTH SETS OF KEYSENTRA CONNECT · HEEFT BEIDE SLEUTELBOSSEN
🔑

Most companies did not move to the cloud; they connected to it. Entra Connect synchronises the on-premises Active Directory with Entra ID, so one login works everywhere. That convenience has a price: the sync server holds credentials powerful enough to change cloud accounts, and it lives on the same network as every other server. Whoever owns the on-premises domain — the classic outcome of a ransomware intrusion — can use it to reset cloud passwords, take over synced administrators or push their own account into the tenant. The opposite direction works too.

Example: during a ransomware incident the responders find that the attackers reached the Entra Connect server on day two, extracted its credentials, and had been reading Microsoft 365 mail for a week before the encryption started. The company rebuilt its servers from backup and was still compromised, because the tenant was never treated as part of the breach. Business impact: a breach in either world becomes a breach of both. The sync server must be treated as a tier-0 asset: isolated, hardened, accessible to almost nobody, and its cloud accounts excluded from synchronisation so that no on-premises password ever unlocks a Global Administrator.

De meeste bedrijven zijn niet naar de cloud verhuisd; ze hebben zich ermee verbonden. Entra Connect synchroniseert de on-premises Active Directory met Entra ID, zodat één inlog overal werkt. Dat gemak heeft een prijs: de syncserver heeft inloggegevens die krachtig genoeg zijn om cloudaccounts te wijzigen, en hij staat in hetzelfde netwerk als elke andere server. Wie het on-premises domein bezit — de klassieke uitkomst van een ransomware-inbraak — kan daarmee cloudwachtwoorden resetten, gesynchroniseerde beheerders overnemen of een eigen account in de tenant duwen. De omgekeerde richting werkt ook.

Voorbeeld: tijdens een ransomware-incident ontdekken de hulpverleners dat de aanvallers op dag twee de Entra Connect-server bereikten, de inloggegevens eruit haalden en al een week Microsoft 365-mail meelazen voordat de versleuteling begon. Het bedrijf herstelde zijn servers vanaf back-up en was nog steeds gecompromitteerd, omdat de tenant nooit als onderdeel van de inbraak was behandeld. Bedrijfsimpact: een inbraak in de ene wereld wordt een inbraak in beide. De syncserver moet worden behandeld als tier-0-systeem: geïsoleerd, gehard, voor bijna niemand bereikbaar, en met cloudbeheerders die buiten de synchronisatie blijven zodat geen enkel on-premises wachtwoord ooit een Global Administrator ontsluit.

ONE BREACH · TWO WORLDS · REBUILT BUT STILL OWNEDÉÉN INBRAAK · TWEE WERELDEN · HERSTELD MAAR NOG BEZET FIX: TIER-0 SYNC SERVER + CLOUD-ONLY ADMINS + NO SYNCED PRIVILEGEOPLOSSING: TIER-0-SYNCSERVER + CLOUD-ONLY BEHEERDERS + GEEN GESYNCHRONISEERDE RECHTEN
// CONTROLSMAATREGELEN

What locks the tenant down. Wat de tenant afsluit.

settings in a licence you already pay for — the cost is engineering hours and a few difficult conversations instellingen in een licentie die u al betaalt — de kosten zijn engineeringuren en een paar lastige gesprekken
DEFENCE STACKVERDEDIGINGSLAGEN
PIM CONDITIONAL ACCESS PHISHING-RESISTANT MFAPHISHINGBESTENDIGE MFA GUEST REVIEWSGASTREVIEWS TIER-0 SYNC SERVERTIER-0-SYNCSERVER
ControlStopsIn one line
PIMAdmins (01)Privileged Identity Management: nobody is a Global Administrator by default. Rights are activated for a few hours, with a reason, approval and a log entry. Aim for five eligible people or fewer.
Break-glassAdmins (01)Two emergency accounts, cloud-only, long random passwords in a sealed envelope, excluded from Conditional Access, and an alert the moment either one signs in.
Separate admin accountsAdmins (01)The account that reads mail and browses is never the account that administers the tenant. Phishing the daily account then yields nothing.
CA baselineGate (02)A small set of Conditional Access policies: block legacy authentication, require MFA for every user, require a compliant device for finance, HR and admin portals, block sign-ins from countries you do not operate in.
Phishing-resistant MFAAdmins (01), Gate (02)Passkeys or hardware keys for every administrator. A push notification can be approved by mistake; a hardware key cannot be phished.
Guest lifecycleGuests (03)Every guest has an owner and an expiry. Access reviews every quarter ask the owner one question; no answer means removal. Guests never reach admin or finance sites.
Tier-0 syncHybrid (04)The Entra Connect server is treated like a domain controller: isolated, patched first, no browsing, no mail, reachable only from admin workstations. All cloud administrators are cloud-only accounts, never synced.
Logs & alertsAll fourSign-in and audit logs kept for at least a year, with alerts on new administrators, new mailbox forwarding rules, new application consents and break-glass use.
Secure ScoreAll fourMicrosoft's Identity Secure Score, reported to the board quarterly. Not a target in itself, but a number that only goes up when the settings above are actually switched on.
MaatregelStoptIn één zin
PIMBeheerders (01)Privileged Identity Management: niemand is standaard Global Administrator. Rechten worden voor een paar uur geactiveerd, met een reden, goedkeuring en een logregel. Streef naar vijf of minder in aanmerking komende personen.
Break-glassBeheerders (01)Twee noodaccounts, cloud-only, lange willekeurige wachtwoorden in een verzegelde envelop, uitgesloten van Conditional Access, en een alarm zodra een van beide inlogt.
Aparte beheeraccountsBeheerders (01)Het account dat mail leest en browst, is nooit het account dat de tenant beheert. Het phishen van het dagelijkse account levert dan niets op.
CA-basissetPoort (02)Een kleine set Conditional Access-regels: blokkeer verouderde authenticatie, eis MFA voor elke gebruiker, eis een beheerd apparaat voor finance, HR en beheerportalen, blokkeer inlogs uit landen waar u niet actief bent.
Phishingbestendige MFABeheerders (01), Poort (02)Passkeys of hardwaresleutels voor elke beheerder. Een pushmelding kan per ongeluk worden goedgekeurd; een hardwaresleutel is niet te phishen.
GastlevenscyclusGasten (03)Elke gast heeft een eigenaar en een einddatum. Toegangsreviews stellen de eigenaar elk kwartaal één vraag; geen antwoord betekent verwijderen. Gasten komen nooit bij beheer- of financesites.
Tier-0-syncHybride (04)De Entra Connect-server wordt behandeld als een domeincontroller: geïsoleerd, als eerste gepatcht, geen browsen, geen mail, alleen bereikbaar vanaf beheerwerkplekken. Alle cloudbeheerders zijn cloud-only accounts, nooit gesynchroniseerd.
Logs & alarmenAlle vierAanmeld- en auditlogs minstens een jaar bewaard, met alarmen bij nieuwe beheerders, nieuwe doorstuurregels op mailboxen, nieuwe app-toestemmingen en gebruik van break-glass.
Secure ScoreAlle vierMicrosofts Identity Secure Score, elk kwartaal aan de directie gerapporteerd. Geen doel op zich, maar een getal dat alleen stijgt als de instellingen hierboven echt aanstaan.
The board-level point: the tenant is the company — its mail, its files, its meetings, its identities. Ask two questions: how many people can take it over today, and how many should that be? If the first answer is above five, or nobody knows it, that is the finding. De kern voor de directie: de tenant is het bedrijf — zijn mail, zijn bestanden, zijn vergaderingen, zijn identiteiten. Stel twee vragen: hoeveel mensen kunnen hem vandaag overnemen, en hoeveel zouden dat moeten zijn? Is het eerste antwoord hoger dan vijf, of weet niemand het, dan is dát de bevinding.
// RISK & COMPLIANCERISICO & COMPLIANCE

On the register, and in the audit. In het risicoregister, en in de audit.

indicative — confirm scope and deadlines with legal and complianceindicatief — bevestig reikwijdte en termijnen met legal en compliance
LikelihoodKansHighHoog

Every Microsoft 365 tenant is probed daily with leaked passwords and phishing. Standing admin rights and open legacy protocols are the norm, not the exception.Elke Microsoft 365-tenant wordt dagelijks afgetast met gelekte wachtwoorden en phishing. Permanente beheerrechten en open verouderde protocollen zijn de norm, niet de uitzondering.

ImpactImpactCriticalKritiek

Tenant takeover means every mailbox, file and Teams conversation exposed at once, plus persistent access that survives password resets.Overname van de tenant betekent elke mailbox, elk bestand en elk Teams-gesprek tegelijk blootgelegd, plus blijvende toegang die wachtwoordresets overleeft.

Residual after controlsRestrisico na maatregelenLowLaag

With PIM, a Conditional Access baseline, phishing-resistant MFA for admins and a tier-0 sync server, takeover requires physical access to a hardware key, not a click.Met PIM, een Conditional Access-basisset, phishingbestendige MFA voor beheerders en een tier-0-syncserver vereist overname fysieke toegang tot een hardwaresleutel, geen klik.

Risk ownerRisico-eigenaarCIOCIO

Executes through the identity or Microsoft 365 team. The board owns the answer to “how many people can take over the tenant”.Uitvoering via het identiteits- of Microsoft 365-team. De directie is eigenaar van het antwoord op “hoeveel mensen kunnen de tenant overnemen”.

Key risk indicatorsKernrisico-indicatorenFour numbers to ask forVier getallen om naar te vragen

Number of Global Administrators and how many are permanent rather than PIM-eligible · % of administrators with phishing-resistant MFA · legacy-authentication sign-ins in the last 30 days · guest accounts not reviewed in the last 12 months, and the Identity Secure Score trend.Aantal Global Administrators en hoeveel daarvan permanent zijn in plaats van via PIM · % beheerders met phishingbestendige MFA · aanmeldingen via verouderde authenticatie in de laatste 30 dagen · gastaccounts die in 12 maanden niet zijn beoordeeld, en de trend van de Identity Secure Score.

Risk register entryTekst voor het risicoregisterOne sentenceEén zin

“Takeover of the Microsoft 365 tenant through a phished administrator, an unclosed Conditional Access gap or the hybrid sync server exposes all company email and files and grants persistent attacker access.”“Overname van de Microsoft 365-tenant via een gephishte beheerder, een niet-gesloten gat in Conditional Access of de hybride syncserver legt alle bedrijfsmail en -bestanden bloot en geeft de aanvaller blijvende toegang.”

FrameworkWhat it requires of youWhen a supplier hands you their reportWhen this incident happens
NIS2Access control and identity management, MFA and secure authentication, and asset management are named risk management measures. Management approves them and is accountable for a tenant it may never have looked at.Microsoft's compliance documentation covers the platform, not your tenant settings. Ask MSPs and consultants with admin rights how their own accounts are protected and whether they use PIM in your tenant.A tenant takeover is very likely a significant incident: early warning within 24 hours, notification within 72 hours, final report within a month. Confirm with legal.
DORAIdentity and access management, privileged access controls and logging are part of the ICT risk framework. Microsoft is an ICT third-party provider that belongs in your register with the contractual clauses DORA prescribes.Microsoft's audit reports describe their side of the shared responsibility. Your Conditional Access, PIM and guest settings are your side, and the supervisor will ask about yours.Loss of control over the tenant is a major ICT incident: initial notification within hours of classification, intermediate report within 72 hours, final report within a month. Confirm with legal.
SOC 2If you issue one: logical access controls over the tenant are tested, including who holds administrative roles, how MFA is enforced and how access is reviewed. Standing Global Administrators become a finding.Microsoft 365 has SOC 2 reports; read the complementary user entity controls, which list tenant configuration as your responsibility. A supplier's own SOC 2 tells you how they protect the admin accounts they hold in your tenant.The takeover appears in your next report as an exception in logical access, and customers will ask for the root cause and a bridge letter.
ISAE 3402Relevant where Microsoft 365 or an MSP administering it touches financially relevant processes. Control objectives around user access provisioning and privileged access will be tested.Read whether tenant administration is in the MSP's scope at all. If access reviews and privileged access are not control objectives, the report says nothing about how they run your tenant.A tenant compromise must be disclosed to the user auditors, and every control that relied on the integrity of identities in that period is in question.
KaderWat het van u vraagtAls een leverancier u zijn rapport geeftAls dit incident u treft
NIS2Toegangsbeheer en identiteitsbeheer, MFA en veilige authenticatie, en assetbeheer zijn benoemde risicobeheersmaatregelen. Het bestuur keurt ze goed en is aansprakelijk voor een tenant waar het misschien nooit naar heeft gekeken.Microsofts compliancedocumentatie dekt het platform, niet uw tenantinstellingen. Vraag MSP's en consultants met beheerrechten hoe hun eigen accounts zijn beveiligd en of ze PIM gebruiken in uw tenant.Een tenantovername is zeer waarschijnlijk een significant incident: vroegtijdige waarschuwing binnen 24 uur, melding binnen 72 uur, eindrapport binnen een maand. Bevestig met legal.
DORAIdentiteits- en toegangsbeheer, beheersing van bevoorrechte toegang en logging maken deel uit van het ICT-risicokader. Microsoft is een ICT-derde die in uw register hoort met de contractbepalingen die DORA voorschrijft.Microsofts auditrapporten beschrijven hun kant van de gedeelde verantwoordelijkheid. Uw Conditional Access-, PIM- en gastinstellingen zijn uw kant, en de toezichthouder vraagt naar die van u.Verlies van controle over de tenant is een ernstig ICT-incident: eerste melding binnen enkele uren na classificatie, tussenrapport binnen 72 uur, eindrapport binnen een maand. Bevestig met legal.
SOC 2Als u er zelf een afgeeft: logische toegangsbeheersing over de tenant wordt getest, inclusief wie beheerrollen heeft, hoe MFA wordt afgedwongen en hoe toegang wordt beoordeeld. Permanente Global Administrators worden een bevinding.Microsoft 365 heeft SOC 2-rapporten; lees de complementary user entity controls, die tenantconfiguratie als uw verantwoordelijkheid benoemen. De eigen SOC 2 van een leverancier vertelt hoe hij de beheeraccounts beschermt die hij in uw tenant heeft.De overname verschijnt in uw volgende rapport als afwijking in logische toegang, en klanten vragen naar de oorzaak en een bridge letter.
ISAE 3402Relevant waar Microsoft 365 of een MSP die het beheert financieel relevante processen raakt. Beheersdoelstellingen rond het toekennen van gebruikerstoegang en bevoorrechte toegang worden getest.Lees of tenantbeheer überhaupt binnen de scope van de MSP valt. Zijn toegangsreviews en bevoorrechte toegang geen beheersdoelstellingen, dan zegt het rapport niets over hoe zij uw tenant beheren.Een tenantcompromittering moet aan de auditors van de klanten worden gemeld, en elke maatregel die in die periode op de integriteit van identiteiten vertrouwde, staat ter discussie.