Analytics BIOC Informational

Authentication method added to an Azure account

An identity attempted to add an Azure authentication method.

Module:
Identity Threat Detection (ITDR), SaaS Threat Detection
Licensed by:
Identity Threat Detection (ITDR)
Data source:
AzureAD Audit Log
ATT&CK tactics: Persistence (TA0003)
ATT&CK techniques: Valid Accounts (T1078)
Attacker's goals:

An attacker can add an authentication method to an account, so they can have later access to the tenant and resources.

Investigative actions:

Check if the authentication method is legitimate in the organization. Check whether the identity is permitted to perform such actions. Follow the account for possible suspicious or unusual logins.

Test period:
N/A (single event)
Deduplication:
1 Day
2 variations:
  • Suspicious authentication method addition to privileged Azure account Medium (parent: Informational)
  • Suspicious authentication method addition to Azure account Low (parent: Informational)