Analytics Alerts

Browse the Cortex analytics alert reference.

Severity
Detection module
Data source

1 alert match the current filters.

Download CSV Show ATT&CK heatmap
  • Unusual Conditional Access operation for an identity Informational Identity Threat Module, SaaS Threat Detection 1 variation

    An identity attempted to add or update an Azure AD Conditional Access policy.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    1 Day
    ATT&CK tactics: Defense Evasion (TA0005)
    ATT&CK techniques: Abuse Elevation Control Mechanism (T1548)
    Required data: AzureAD Audit Log
    Attacker's goals: An attacker attempts to change Active Directory configuration for persistence or defense evasion. With a modified Conditional Access policy, an attacker might be able to access the tenant without possible blockage for later access.
    Investigative actions: Check implications of the updated policy. Check whether the user changing the configuration is permitted to perform such actions.

    Variations

    Suspicious Conditional Access operation for an identity

    Low overridden

    An identity that doesn't usually modify Azure AD Conditional Access policies successfully modified a policy. overridden