Analytics Alerts
Browse the Cortex analytics alert reference.
1 alert match the current filters. tactic: TA0003 ✕
Download CSV Show ATT&CK heatmapIdentity assigned an Azure AD Administrator Role Informational Identity Threat Module, SaaS Threat Detection 2 variations
An identity was assigned an Azure AD Administrator role.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- N/A (single event)
- Deduplication:
- 1 Day
ATT&CK tactics: Persistence (TA0003)ATT&CK techniques: Account Manipulation: Additional Cloud Roles (T1098.003)Required data: AzureAD Audit LogAttacker's goals: An attacker may add additional roles or permissions to an attacker controlled cloud account to maintain persistent access to a tenant.Investigative actions: Check if the added account is new to the organization. Check whether the account that added the account to the role is permitted to perform such actions. Check what can be affected by the assigned role* Follow further actions done by the account that was added to the role.Variations
Identity assigned an Azure AD Administrator Role by an Application
Medium overridden
An identity was assigned an Azure AD Administrator role by an application. overridden
Suspicious Azure AD Administrator Role assignment
Low overridden
An identity was assigned an Azure AD Administrator role. overridden