Analytics BIOC
Informational
✕
Authentication method added to an Azure account
An identity attempted to add an Azure authentication method.
- Module:
- Identity Threat Detection (ITDR), SaaS Threat Detection
- Licensed by:
- Identity Threat Detection (ITDR)
- Data source:
- AzureAD Audit Log
ATT&CK tactics: Persistence (TA0003)
ATT&CK techniques: Valid Accounts (T1078)
Attacker's goals:
An attacker can add an authentication method to an account, so they can have later access to the tenant and resources.
Investigative actions:
Check if the authentication method is legitimate in the organization. Check whether the identity is permitted to perform such actions. Follow the account for possible suspicious or unusual logins.
- Test period:
- N/A (single event)
- Deduplication:
- 1 Day
2 variations:
- Suspicious authentication method addition to privileged Azure account Medium (parent: Informational)
- Suspicious authentication method addition to Azure account Low (parent: Informational)