Analytics BIOC
Informational
✕
Azure service principal assigned app role
An identity assigned an app role (permissions) to a service principal.
- Module:
- Identity Threat Detection (ITDR), SaaS Threat Detection
- Licensed by:
- Identity Threat Detection (ITDR)
- Data source:
- AzureAD Audit Log
ATT&CK tactics: Privilege Escalation (TA0004)
ATT&CK techniques: Valid Accounts (T1078)
Attacker's goals:
An attacker may add roles to service principals that will allow them to access sensitive information and perform other actions.
Investigative actions:
Check if the added service principle is new to the organization. Check whether the account that added the app role is supposed to perform such actions. Check for possible logins and actions from the service principle with the role. Follow further actions done by the application and the assigner.
- Test period:
- N/A (single event)
- Deduplication:
- 1 Day