Findings
Generator
Configuration
Lucidum Reverse
Architecture
Statistics
← All Findings
Vendor:
Microsoft Entra ID
FIN-677
Weight:
5
4
3
2
1
Confidence:
High
Medium
Low
Not Verified
What It Detects
This Entra ID user is disabled but still has an active directory role assignment. This is an orphaned privilege — the account cannot authenticate, but if re-enabled (accidentally or maliciously), it would immediately inherit administrative access. This combination represents a significant security gap.
MITRE ATT&CK Techniques
Comma-separated, e.g. T1078, T1190
Checks
read-only
Field
Operator
Value
User Disabled (True/False)
equals
True
Role Name
not_empty
Connectors
match
Entra
Remediation
×
×
×
×
+ Add item
Why It Matters
×
×
×
+ Add item
Save Changes
Export Lucidum