Analytics BIOC Informational

Azure AD PIM elevation request

An Azure AD PIM elevation request was denied/approved.

Module:
Identity Threat Detection (ITDR), SaaS Threat Detection
Licensed by:
Identity Threat Detection (ITDR)
Data source:
AzureAD Audit Log
ATT&CK tactics: Privilege Escalation (TA0004)
ATT&CK techniques: Valid Accounts (T1078)
Attacker's goals:

Getting elevated permissions to perform malicious actions.

Investigative actions:

Check if the elevation is authorized. Follow further actions or suspicious logins from the elevated account.

Test period:
N/A (single event)
Deduplication:
1 Day