Join our Newsletter — 33% off our NHI Course

Notifications
Clear all

Intune wipe permissions and IAM gaps: what teams missed at Stryker


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 19563
Topic starter  

TL;DR: Stryker’s outage shows how compromised administrative access in Microsoft 365, Entra ID, and Intune can turn legitimate device-management functions into destructive actions, according to Veza, after attackers allegedly wiped more than 200,000 devices across 79 countries and extracted 50 terabytes of data. The lesson is that privileged access paths, not just malware, can create enterprise-wide impact when wipe permissions are too broadly granted.

NHIMG editorial — based on content published by Veza covering the Stryker cyberattack: Intune wipe permissions, administrative access, and IAM gaps

By the numbers:

Questions worth separating out

Q: What breaks when Intune wipe permissions are overexposed?

A: A compromised admin or delegated user can turn a normal management action into a destructive enterprise event.

Q: Why do broad admin roles increase the impact of identity compromise?

A: Broad roles collapse the boundary between authentication and action.

Q: How do security teams find hidden device-wipe paths?

A: They need to analyse the full entitlement graph, including direct permissions, inherited role grants, and delegated access in cloud identity systems.

Practitioner guidance

  • Audit destructive Intune permissions Map every role and direct entitlement that can issue wipe, retire, or equivalent device actions, then require explicit business justification for each one.
  • Enforce phishing-resistant admin authentication Require hardware-backed or authenticator-based MFA for every administrative path that can reach Microsoft 365, Entra ID, or Intune control functions.
  • Review access graphs, not just role names Trace inherited, delegated, and direct permissions across Entra ID and Intune so that hidden wipe paths are visible before they are abused.

What's in the full article

Veza's full analysis covers the operational detail this post intentionally leaves for the source:

  • The dashboard queries that map Intune wipe permissions to specific Azure AD and Entra ID access paths.
  • The permission combinations that expose remote wipe capability through direct grants and privileged roles.
  • The remediation logic for tightening conditional access and reducing destructive action scope.
  • The access-graph views used to identify accounts that can reach device-management controls without sufficient review.

👉 Read Veza's analysis of the Stryker Intune wipe attack and identity controls →

Intune wipe permissions and IAM gaps: what teams missed at Stryker?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 4 months ago
Posts: 19154
 

Device-wipe privilege is a destructive control plane, not a routine admin convenience. When Intune or similar MDM actions can disable endpoints at scale, the entitlement itself becomes a high-impact security control. That means identity governance has to classify wipe permissions alongside other privileged actions, with tighter review than ordinary operational access. Practitioners should treat destructive device actions as blast-radius controls, not helpdesk settings.

A few things that frame the scale:

A question worth separating out:

Q: Who should approve privileged device-management actions?

A: Approval should sit with the smallest possible set of operational owners, and only for identities that truly need destructive authority. For high-risk actions, teams should require separate review, tight conditional access, and rapid revocation when the business need ends. The goal is to prevent standing access from becoming a standing outage risk.

👉 Read our full editorial: Stryker’s Intune wipe attack shows how IAM gaps become outages



   
ReplyQuote
Share: