Analytics BIOC
Informational
✕
Azure AD account unlock/password reset attempt
An attempt to unlock an Azure AD identity or reset its password has occurred.
- Module:
- Identity Threat Detection (ITDR), SaaS Threat Detection
- Licensed by:
- Identity Threat Detection (ITDR)
- Data source:
- AzureAD Audit Log
ATT&CK tactics: Persistence (TA0003)
ATT&CK techniques: Valid Accounts (T1078)
Attacker's goals:
An attacker may switch a valid account's password for persistence.
Investigative actions:
Check if the password reset is authorized. Check whether the user who reset the password is permitted to perform such actions. Check if the account is in the password reset group or is acting out of scope. Check whether the user has not completed the password reset and cancelled before successfully passing authentication methods. Follow further actions or suspicious logins from the target account.
- Test period:
- N/A (single event)
- Deduplication:
- 1 Day
1 variation:
- Azure AD account unlock/successful password reset Low (parent: Informational)