The Cloud Blindspot: What CISA’s "Tale of Two SOCs" Teaches CISOs About Entra ID Security

The Cloud Blindspot: What CISA’s "Tale of Two SOCs" Teaches CISOs About Entra ID Security

CISA conducted concurrent red team assessments at two major organizations: Organization A and Organization B. The assessments yielded two drastically different stories of on-premises defense. Here are the lessons learned for CISOs.

This is part 1 of a multi series blog post.

The Illusion of Control: On-Premises Wins vs. Cloud Losses

Every modern CISO is familiar with the struggle of defending hybrid networks. But a landmark Cybersecurity Advisory published by the Cybersecurity and Infrastructure Security Agency (CISA) on August 25, 2026, exposes a critical structural vulnerability that many security programs are completely ignoring. CISA conducted concurrent red team assessments at two major organizations: Organization A and Organization B. The assessments yielded two drastically different stories of on-premises defense: • Organization A had untuned endpoint detection and response (EDR) tools, fragmented security silos, and passive processes. The red team silently escalated privileges, gained full domain control, captured screenshots and keylogs of the Security Operations Center (SOC) staff, and read SOC emails. • Organization B displayed a highly proactive, modern defense. Within 2 to 20 minutes of the red team's initial payload executions, defenders isolated the compromised workstations, effectively severing the attackers' command and control (C2) channels and forcing the red team into an artificial "assume breach" model. For most security leaders, Organization B’s response would be considered a resounding success. But here is the catch: despite Organization B's rapid endpoint containment, the red team still achieved full domain compromise and successfully hijacked their cloud resources in Entra ID.

The Shared Vulnerability: Underestimating the Cloud Identity Boundary

No matter how fast your SOC can isolate a physical workstation, the cloud represents a fundamentally different attack surface. CISA's assessment highlighted that both organizations significantly underestimated the risks associated with cloud environments.

Even though Organization B caught the initial network intrusion, they fell victim to the exact same cloud identity vectors as Organization A. The red team bypassed traditional perimeters by targeting identity boundaries, leveraging excessive permissions, and exploiting a critical defensive gap: the inability to manage, detect, and remediate stolen cloud identity tokens.

To prevent your organization from becoming a statistic, security leadership must pivot from traditional network-centric containment to cloud-identity governance.

Three Strategic Directives for Security Leadership

The lessons learned from CISA's assessments suggest three primary areas where CISOs must immediately shift their focus and budget to secure Microsoft Entra ID and cloud ecosystems:

1. Close the Workload Identity Loophole

Historically, security programs have poured resources into user-focused protections like multi-factor authentication (MFA). However, attackers are increasingly targeting workload identities; the service principals and applications that systems use to talk to each other.

  • The Trap: Many organizations use broad, high-privilege Application permissions (such as Microsoft Graph Mail.ReadWrite or Application.ReadWrite.All) that operate entirely outside the scope of traditional Conditional Access Policies (CAPs). If an application is compromised, the attacker inherits those global permissions directly.
  • The Action: CISOs must enforce Conditional Access Policies for Workload Identities. This extends traditional CAP boundaries to non-human service accounts, ensuring they can only operate under strict, low-risk conditions and logical boundaries.

2. Establish a Token Revocation Playbook

One of the most significant gaps identified in both organizations was a lack of mature, defined remediation processes for compromised tokens.

  • The Trap: If an attacker steals a Primary Refresh Token (PRT) or generates long-lived access tokens from a compromised device, they can maintain persistent access to your cloud environment from the public internet. Even if your SOC completely evicts the threat actor from the on-premises network, those active cloud tokens remain valid, allowing the attacker to slide right back in.
  • The Action: Security operations must build, document, and routinely practice a dedicated incident response playbook for cloud token revocation. SOC analysts must be empowered and trained to instantly revoke all active refresh and access tokens for compromised user accounts and applications, rather than just resetting active directory passwords.

3. Break Down Silos and Empower Defenders

Ultimately, the best cloud security policies are useless if the human elements of your SOC are paralyzed by bureaucracy.

  • The Trap: Organization A's SOC received alerts indicating red team activity but dismissed them because they were buried under thousands of untuned business false positives. Worse, they operated in silos and lacked standard procedures or authority to act.
  • The Action: Empower your network defenders by granting them the explicit authority to take containment actions (like isolating systems or revoking application access) without waiting for high-level bureaucratic approvals. Additionally, demand that cloud threat logs (like Microsoft Entra ID audit logs) be tightly integrated into unified, on-premises security operations to eliminate visibility blind spots.

Executive Bottom Line

Endpoint security is no longer the final boundary. If your security strategy treats Microsoft Entra ID as a separate, secondary layer rather than a central tier-0 asset, you are leaving your organization open to the exact exploits detailed in CISA’s advisory. Ensuring robust workload identity restrictions, establishing clear token-eviction procedures, and empowering your defensive teams are the keys to surviving a hybrid attack.

How Can Astra Help

Astra customers can use the built in use cases to identify vulnerable identities and workloads in a click of a button.

Contact us for inquiries or a demo https://astrasec.io/#cta