Analytics BIOC
Medium
✕
Azure AD PIM alert disabled
An identity disabled an Azure AD PIM alert.
- Module:
- Identity Threat Detection (ITDR), SaaS Threat Detection
- Licensed by:
- Identity Threat Detection (ITDR)
- Data source:
- AzureAD Audit Log
ATT&CK tactics: Defense Evasion (TA0005)
ATT&CK techniques: Domain or Tenant Policy Modification (T1484)
Attacker's goals:
An attacker might want to disable alerts associated with authentication requirements for privileged access. This may allow malicious activities to go unnoticed.
Investigative actions:
Check what alert was disabled. Check whether the user that disabled the alert is permitted to perform such actions.
- Test period:
- N/A (single event)
- Deduplication:
- 1 Day