What Changed
The EntraEligibleMembers (Preview) table checkbox has been re-added to the Microsoft Entra ID Assets Data Connector UI definition (EntraIDAssets_DataConnectorDefinition.json). This is the third iteration of this table in the solution recent history:
- v3.3.0 (27-Jun-2026): Initial addition of EntraEligibleMembers
- v3.3.1 (01-Jul-2026): Removed - backend ingestion was not deployed to all regions
- v3.4.0 (20-Jul-2026): Re-added - backend ingestion now confirmed deployed globally
Security Impact (Visibility and Fidelity)
The EntraEligibleMembers table exposes Entra ID Privileged Identity Management (PIM) eligible role assignments - identities that can activate privileged roles on demand. This is high-value data for detecting:
- Unauthorised or unexpected PIM eligibility grants (T1098.003 - Account Manipulation: Additional Cloud Roles)
- Lateral movement via role activation abuse
- Persistence through PIM role assignment (T1078.004 - Valid Accounts: Cloud Accounts)
Environments running v3.3.1 have had no ingestion of eligible role assignments since 01-Jul-2026. Hunting queries or detections referencing this table returned empty results during that window. Upgrading to v3.4.0 restores visibility.
PR discussion context was unavailable, which may affect severity assessment.
Affected Files
Solutions/Microsoft Entra ID Assets/Data Connectors/EntraIDAssets_DataConnectorDefinition.json
(packaging artefacts: 3.4.0.zip, ReleaseNotes.md, Solution_MicrosoftEntraAssets.json, mainTemplate.json)