Analytics BIOC
Informational
✕
Azure Temporary Access Pass (TAP) registered to an account
An identity registered an Azure Temporary Access Pass (TAP) to an account.
- Module:
- Identity Threat Detection (ITDR), SaaS Threat Detection
- Licensed by:
- Identity Threat Detection (ITDR)
- Data source:
- AzureAD Audit Log
ATT&CK tactics: Defense Evasion (TA0005) Privilege Escalation (TA0004)
ATT&CK techniques: Valid Accounts (T1078)
Attacker's goals:
A TAP can allow setting of other authentication methods and can be used as an initial replacement of a multifactor authentication.
Investigative actions:
Check if the account that got the TAP should get it. Check whether the account that registered the TAP is supposed to perform such actions. Check if the TAP was registered to a privileged account. Follow further actions done by the initiator and the account with the TAP.
- Test period:
- N/A (single event)
- Deduplication:
- 1 Day
2 variations:
- Azure Temporary Access Pass (TAP) registered to a privileged account Medium (parent: Informational)
- Abnormal Azure Temporary Access Pass (TAP) account registration Low (parent: Informational)