Analytics BIOC Medium

Azure AD PIM alert disabled

An identity disabled an Azure AD PIM alert.

Module:
Identity Threat Detection (ITDR), SaaS Threat Detection
Licensed by:
Identity Threat Detection (ITDR)
Data source:
AzureAD Audit Log
ATT&CK tactics: Defense Evasion (TA0005)
ATT&CK techniques: Domain or Tenant Policy Modification (T1484)
Attacker's goals:

An attacker might want to disable alerts associated with authentication requirements for privileged access. This may allow malicious activities to go unnoticed.

Investigative actions:

Check what alert was disabled. Check whether the user that disabled the alert is permitted to perform such actions.

Test period:
N/A (single event)
Deduplication:
1 Day