How to find out if Azure Tenant ID has been compromised

Laurie Marion 0 Reputation points
2024-01-24T16:38:27.7233333+00:00

I need to know if telling a third party the Tenant ID for our Azure/Entra tenant will make it possible for them to access our tenant and the accounts of our users.

Microsoft Entra
{count} votes

2 answers

Sort by: Most helpful
  1. Q&A Assist
    2024-01-24T16:38:27.7266667+00:00
    AI generated content. This question contains an answer created with AI from Q&A Assist. Learn more

    If you suspect that your Azure Tenant ID has been compromised, you should take immediate action to protect your account and data. One of the first steps you can take is to change the credentials for tenant admins and RBAC access on Azure Subscriptions, as well as follow the password guidance and ensure that all tenant admins and RBAC owners have MFA registered and enforced. You can also review which users, tenants, and subscriptions are at risk within the Azure portal and investigate the risk by going to Microsoft Entra ID to review Identity Protection's Risk Reports. Additionally, you can block the IP address of the attacker, enable MFA if it isn't already done, and enable Identity Protection for the user risk and sign-in risk.

    Regarding whether telling a third party the Tenant ID for your Azure/Entra tenant will make it possible for them to access your tenant and the accounts of your users, it is unlikely. The Tenant ID is a unique identifier for your tenant, but it is not a secret. It is used to identify your tenant when you sign up for Azure and to access resources within your tenant. However, it is important to keep your credentials and RBAC access secure, as these can provide access to sensitive data and resources.


    References:

    0 comments No comments

  2. Andy David - MVP 138K Reputation points MVP
    2024-01-24T16:40:41.8066667+00:00

    Anyone can look up a Tenant ID: https://gettenantpartitionweb.azurewebsites.net/ That in of itself is not a security issue

    0 comments No comments