What is managed-service-provider compromise?¶
Managed-service-provider compromise occurs when an offender gains control of a provider account, device or administration platform and uses the provider's trusted access to reach customer environments.
The customer may see activity from an expected service account or management agent. That identifies the route, not whether the action was authorised or who controlled it.
Why provider access changes the evidence¶
Providers often administer many customers through shared remote-management, identity, backup or software-deployment systems. A single compromised operator account or API credential may therefore create jobs across several tenants. The effect on each customer can still differ according to targeting, permissions, configuration and whether a job completed.
Customer-side logs may record the provider's agent executing a command but omit the browser session or API call that created it. Provider-side evidence may include:
- authentication and device records;
- operator and role audit logs;
- job, script and approval histories;
- tenant and target identifiers; and
- queued, retried or cancelled actions.
Linking those records can show the path from an upstream session to a management instruction and then to a customer effect.
Keep identities and timelines separate¶
An operator account name does not prove that the named employee controlled the session. Test the account evidence against source device, authentication, token and session records. Similarly, compromise of one provider system does not prove that every customer was reached.
Containment may disable accounts, delete jobs or rotate credentials before all records are collected. Document those actions and align provider and customer timelines so later gaps are not mistakenly attributed to the offender.
Key takeaway
Trace provider account, management action, customer target and resulting effect as separate links; trusted provider access is not proof of authorised use or deliberate provider participation.