Analytics BIOC
Informational
✕
Identity assigned an Azure AD Administrator Role
An identity was assigned an Azure AD Administrator role.
- Module:
- Identity Threat Detection (ITDR), SaaS Threat Detection
- Licensed by:
- Identity Threat Detection (ITDR)
- Data source:
- AzureAD Audit Log
ATT&CK tactics: Persistence (TA0003)
ATT&CK techniques: Account Manipulation: Additional Cloud Roles (T1098.003)
Attacker's goals:
An attacker may add additional roles or permissions to an attacker controlled cloud account to maintain persistent access to a tenant.
Investigative actions:
Check if the added account is new to the organization. Check whether the account that added the account to the role is permitted to perform such actions. Check what can be affected by the assigned role* Follow further actions done by the account that was added to the role.
- Test period:
- N/A (single event)
- Deduplication:
- 1 Day
2 variations:
- Identity assigned an Azure AD Administrator Role by an Application Medium (parent: Informational)
- Suspicious Azure AD Administrator Role assignment Low (parent: Informational)