Analytics Alerts
Browse the Cortex analytics alert reference.
1 alert match the current filters. tactic: TA0005 ✕
Download CSV Show ATT&CK heatmapUnusual Conditional Access operation for an identity Informational Identity Threat Module, SaaS Threat Detection 1 variation
An identity attempted to add or update an Azure AD Conditional Access policy.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- N/A (single event)
- Deduplication:
- 1 Day
ATT&CK tactics: Defense Evasion (TA0005)ATT&CK techniques: Abuse Elevation Control Mechanism (T1548)Required data: AzureAD Audit LogAttacker's goals: An attacker attempts to change Active Directory configuration for persistence or defense evasion. With a modified Conditional Access policy, an attacker might be able to access the tenant without possible blockage for later access.Investigative actions: Check implications of the updated policy. Check whether the user changing the configuration is permitted to perform such actions.Variations
Suspicious Conditional Access operation for an identity
Low overridden
An identity that doesn't usually modify Azure AD Conditional Access policies successfully modified a policy. overridden