AZT507.1 - External Entity Access: Azure Lighthouse#
Adversaries may utilize Azure Lighthouse to manage the target tenant from an external tenant
Resource
AzureAD
Actions
- Microsoft.ManagedServices/registrationAssignments/Write
Examples
Detections
Detection Details#
- The Az PowerShell cmdlets
Get-AzManagedServicesDefinitionandGet-AzManagedServicesAssignment, or az cli cmdletsaz managedservices definition listandaz managedservices assignment listcan be used to list the onboarded customers to the tenant.
Additional Resources
https://docs.microsoft.com/en-us/azure/lighthouse/how-to/onboard-customer
