News: 1656655332

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Microsoft gives its partners power to change AD privileges on customer systems – without permission

(2022/07/01)


Microsoft has created a window of time in which its partners can – without permission – create new roles for themselves in customers' Active Directory implementations.

Which sounds bonkers, so let's explain why Microsoft has even entertained the prospect.

To begin, remember that criminals have figured out that attacking IT service providers offers a great way to find many other targets. Evidence of that approach can be found in attacks on ConnectWise, SolarWinds, Kaseya and other vendors that provide software to IT service providers.

[1]

Microsoft wised up to the fact that its partners would likely be targeted, too, and spotted a weakness in the delegated admin privileges (DAP) that partners are given to manage their customers' software purchases.

[2]

[3]

The company's fix is [4]granular delegated admin privileges (GDAP) that, as the name implies, still allow partners to administer their customers but offers finer control and follows zero-trust principles so that partners are limited to certain actions.

Today, GDAP "allows the partner to request and the customer to approve specific Azure Active Directory roles, allowing the partner to perform admin activities on behalf of the customer."

[5]

Microsoft is very keen on GDAP. So keen that on June 30 it [6]announced the following:

Starting July 25, Microsoft will provide a tool that allows partners with existing delegated admin privileges (DAP) relationships to create a GDAP relationship with Azure AD roles – without customer consent.

Microsoft's motive is simple: it wants partners to adopt GDAP so their interactions with customers are more secure.

Partners won't keep this power to change customer rigs forever. The tool will only work until October 31, 2022, and after that date customers will again have to approve the creation of new GDAP relationships.

But for the 98 days that elapse from this tool's debut to its end of life, partners can create GDAP roles without customer intervention.

The Register submits that criminals might be busy on those days, too – making just the sort of attacks on partners that Microsoft hopes GDAP will prevent.

[7]Microsoft postpones shift to New Commerce Experience subscriptions

[8]Microsoft 365, Office 365 price hikes delayed

[9]Five Eyes turn spotlight on MSPs: Potential weak links in IT supply-chain security

Microsoft will deliver more info about the tool on July 11.

Clearly, customers that work with Microsoft partners might want to have a chat about GDAP before the tool debuts. ®

Get our [10]Tech Resources



[1] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2Yr7FyeBuR-5Z45ZeecCbDgAAANg&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Yr7FyeBuR-5Z45ZeecCbDgAAANg&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Yr7FyeBuR-5Z45ZeecCbDgAAANg&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[4] https://www.theregister.com/2022/05/18/microsoft_gdap_advice/

[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Yr7FyeBuR-5Z45ZeecCbDgAAANg&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[6] https://docs.microsoft.com/en-gb/partner-center/announcements/2022-june#18

[7] https://www.theregister.com/2022/06/29/microsoft_nce_indefinite_extension/

[8] https://www.theregister.com/2022/03/08/nce/

[9] https://www.theregister.com/2022/05/11/five_eyes_msp/

[10] https://whitepapers.theregister.com/



Partners with existing delegated admin privileges (DAP) relationships

Warm Braw

This would seem to be the key phrase: they've already been given specific and potentially broad permission to mess around with manage their customers' systems. All that's happening is that for a limited period of time that permission is being extended to the new model. I can't immediately see what access this gives to "partners" they did not already have.

Binraider

Follow up article saying this has been closed early because; in …3…2…

sitta_europea

What could possibly go wrong?

Life is a POPULARITY CONTEST! I'm REFRESHINGLY CANDID!!