Microsoft gives its partners power to change AD privileges on customer systems – without permission

Ireland News News

Microsoft gives its partners power to change AD privileges on customer systems – without permission
Ireland Latest News,Ireland Headlines
  • 📰 TheRegister
  • ⏱ Reading Time:
  • 21 sec. here
  • 2 min. at publisher
  • 📊 Quality Score:
  • News: 12%
  • Publisher: 61%

Somewhat counterintuitively, this is being done to improve security

Microsoft has created a window of time in which its partners can – without permission – create new roles for themselves in customers' Active Directory implementations.To begin, remember that criminals have figured out that attacking IT service providers offers a great way to find many other targets. Evidence of that approach can be found in attacks on ConnectWise, SolarWinds, Kaseya and other vendors that provide software to IT service providers.

Today, GDAP"allows the partner to request and the customer to approve specific Azure Active Directory roles, allowing the partner to perform admin activities on behalf of the customer."Starting July 25, Microsoft will provide a tool that allows partners with existing delegated admin privileges relationships to create a GDAP relationship with Azure AD roles – without customer consent.

We have summarized this news so that you can read it quickly. If you are interested in the news, you can read the full text here. Read more:

TheRegister /  🏆 67. in UK

Ireland Latest News, Ireland Headlines



Render Time: 2025-04-07 05:13:17