A compromised admin account is all it takes to turn Microsoft Intune into a destructive weapon. This CoreView Threat Advisory article explains how a real-world wipe attack unfolded, and looks at how CoreView helps organizations harden tenant governance before adversaries turn legitimate tools into weapons.
In March 2026, an Iran-linked threat group assessed by Palo Alto Networks Unit 42 as affiliated with Iran’s Ministry of Intelligence and Security (MOIS) executed a destructive operation against a Fortune 500 medical technology manufacturer. The attackers compromised a privileged Microsoft 365 administrator account, created a new Global Administrator identity, and weaponized Microsoft Intune’s built-in Remote Wipe capability to issue factory-reset commands against enrolled endpoints globally.
The result: tens of thousands of Windows workstations and mobile devices including personal devices enrolled through the organization’s BYOD program were erased simultaneously. No ransomware was deployed. No custom malware was required. Order processing, manufacturing, and shipping operations were disrupted across 79 countries, with downstream impacts reported at hospitals dependent on the company’s surgical equipment and supply chains.
This incident is a textbook example of a privileged account takeover combined with Living-off-the-Land (LOTL) techniques at the cloud management plane. The adversary did not need to develop novel tooling; they leveraged the organization’s own trusted administrative infrastructure to achieve destructive effect. In the days following the attack, CISA, in coordination with the FBI and Microsoft, issued formal hardening guidance urging all U.S. organizations to strengthen their endpoint management configurations immediately.
CoreView exists to close the governance gaps that made this attack possible. This advisory details the attack’s mechanics, identifies the specific control failures the adversary exploited, and explains how CoreView’s continuous governance and visibility capabilities help organizations prevent privileged account takeover from escalating to tenant-wide destruction.
Security researchers and incident responders classify this class of operation using the following terminology:
| Classification | Description |
|---|---|
| Attack Type | Privileged Account Takeover → Destructive Wiper Operation |
| Technique | Living-off-the-Land (LOTL) via Cloud Management Plane Abuse |
| Threat Actor Profile | Iran-linked MOIS-affiliated threat group; confirmed by Check Point Research and Palo Alto Networks Unit 42 |
| MITRE ATT&CK | T1078 (Valid Accounts), T1098 (Account Manipulation), T1485 (Data Destruction), T1569 (System Services) |
| Target Surface | Microsoft 365 Tenant — specifically Microsoft Intune management plane |
| Impact | Mass device wipe across tens of thousands of endpoints in 79 countries; operational disruption to manufacturing, ordering, and shipping; downstream hospital supply-chain impact |
| Investigation | Microsoft Detection and Response Team (DART) with support from Palo Alto Networks Unit 42; CISA and FBI coordination |
Based on public reporting from multiple security researchers and news outlets, the attack followed this progression:
In this short video, cybersecurity expert Graham Cluley and Rob Edmondson discuss how quiet Microsoft 365 configuration changes can create serious risk before anyone notices.
This attack is significant precisely because it generated no traditional indicators of compromise:
As one industry analyst noted: this was not an inherent weakness in Microsoft Intune, it was an exploitation of the trust model that organizations place in their management plane, executed through classic living-off-the-land methodology.
In this short video, cybersecurity expert Graham Cluley and Rob Edmondson discuss how endpoint management tools can become a pathway for attackers if the wrong controls or permissions are in place.
This incident was not caused by a software vulnerability. It was caused by the convergence of multiple governance and configuration gaps that gave a single compromised credential the ability to execute tenant-wide destruction. These gaps are common across enterprises and represent the primary attack surface CoreView is designed to address.
Accounts with Global Administrator, Intune Administrator, and other high-impact roles held permanent (standing) privileges rather than being governed through Privileged Identity Management (PIM) with time-limited, approval-gated elevation. This meant a single compromised credential immediately granted the adversary full administrative capability, no additional approval or escalation step was required.
Privileged accounts were not protected by phishing-resistant MFA methods such as FIDO2 security keys, Windows Hello for Business, or certificate-based authentication. Standard MFA methods (SMS, push notifications, TOTP (time-based one-time passwords)) are susceptible to AiTM (Adversary-in-the-Middle) phishing proxies and real-time session hijacking, a technique Iran-affiliated threat actors are known to employ.
Microsoft Intune supports Multi-Admin Approval (MAA), which requires a second administrator to approve high-impact operations before execution. If MAA had been enabled for remote wipe commands, the attacker would have needed to compromise two separate administrative accounts and coordinate real-time approval. This would have presented a significantly higher operational bar.
The Intune administrative surface was not governed with the same rigor applied to domain controllers, PKI infrastructure, or identity providers. Yet its blast radius, the ability to simultaneously wipe, reconfigure, or deploy software to every enrolled endpoint, is at least as large. CISA’s subsequent advisory explicitly calls on organizations to treat endpoint management platforms as critical infrastructure.
Bulk wipe commands, new Global Administrator account creation, and mass policy modifications were not subject to real-time detection, alerting, or automated response. Real-time detection would have surfaced the activity earlier, potentially in time to interrupt it.
In this short video, cybersecurity expert Graham Cluley and Rob Edmondson explore how excessive Microsoft 365 admin access can increase risk and expose the wider tenant.
CoreView provides the continuous governance, visibility, and enforcement layer that sits between your Microsoft 365 tenant configuration and an adversary’s ability to exploit it. The controls below directly address every governance failure identified in this incident.
This attack succeeded because a single compromised credential landed on an account with unrestricted administrative authority. CoreView gives security teams a complete, actionable inventory of every privileged identity across Microsoft 365 and Intune. This means you can eliminate standing over-privilege before an adversary can exploit it.
With CoreView, you can:
Many organizations have PIM and strong MFA configured in policy but cannot verify consistent enforcement across every privileged role, every tenant, and every business unit. CoreView closes the gap between policy intent and operational reality.
CoreView enables you to:
In this incident, destructive Intune commands were executed as if they were routine IT operations for approximately three hours. CoreView makes those actions visible, urgent, and actionable.
CoreView provides:
This incident was catastrophic because multiple misconfigurations and governance gaps aligned simultaneously. CoreView helps you identify and remediate these structural weaknesses before an adversary chains them together into an attack path.
CoreView surfaces:
In this short video, cybersecurity expert Graham Cluley and Rob Edmondson explain why securely recovering Microsoft 365 is more complex than simply restoring data.
In the wake of this incident, CISA explicitly urged organizations to treat endpoint management platforms as critical infrastructure. Boards, auditors, regulators, and cyber insurers increasingly expect evidence that Microsoft 365 and Intune are subject to the same governance rigor as domain controllers and identity providers.
CoreView helps you:
In March 2026, CISA issued formal guidance urging all U.S. organizations to harden their endpoint management system configurations. The advisory was developed in coordination with the FBI, Microsoft, and the affected organization. CoreView’s capabilities map directly to CISA’s three core recommendations:
| CISA Recommendation | Specific Guidance | CoreView Capability |
|---|---|---|
| Least-Privilege Administration | Assign minimum permissions via Intune RBAC; use scope tags to segment access by role and business unit | Complete privileged role inventory; identification of existing over-privilege; enforcement tracking for PIM enrollment and RBAC alignment; zero trust M365 administration |
| Phishing-Resistant MFA and Privileged Access Hygiene | Enforce phishing-resistant MFA for all privileged roles; configure Conditional Access to block access from untrusted contexts | Continuous audit of MFA method strength per privileged account; detection of Conditional Access changes; remediation tracking |
| Multi-Admin Approval for Destructive Actions | Require a second administrator’s approval for high-impact actions including device wipes, script deployments, RBAC changes, and configuration modifications | Monitoring of high-impact admin actions in near real time; alerting on bulk destructive operations; governance reporting for MAA policy coverage |
This incident is not an isolated event. It reflects an escalating pattern in which state-sponsored and hacktivist threat actors deliberately target cloud management planes as force multipliers for destructive operations:
Any organization managing endpoints through Microsoft Intune or any cloud-based endpoint management platform should assume that this attack model will be attempted against them. The question is whether your governance posture will stop a compromised credential from becoming a tenant-wide catastrophe.
You cannot remove powerful administrative capabilities from Microsoft 365 and Intune, they exist because organizations need them. What you can control is who can exercise those capabilities, under what conditions, and how quickly you will know when they are misused.
This incident demonstrates what happens when those controls are absent. A single compromised credential, combined with standing administrative privilege and insufficient monitoring, gave an adversary the ability to wipe tens of thousands of devices across a global enterprise using nothing more than the organization’s own management tools.
CoreView makes the decisions that prevent this outcome visible, enforceable, and auditable. So a privileged account takeover stays a detection event, not a global operational disruption.