Analytics Low

Multiple Azure AD admin role removals

An Azure AD identity removed multiple administrators from their roles.

Module:
Identity Threat Detection (ITDR), SaaS Threat Detection
Licensed by:
Identity Threat Detection (ITDR)
Data source:
AzureAD Audit Log
ATT&CK tactics: Impact (TA0040)
ATT&CK techniques: Account Access Removal (T1531)
Attacker's goals:

An attacker may want to lock out an organization and retain sole access.

Investigative actions:

Check if the identity performing the actions was authorized to perform them. Check what roles the users were removed from. Check whether the identity is a newly added admin. Check if the identity is operating in its usual manner (location, time, operations)* Check if the identity performed additional operations in the cloud environment that might be malicious.

Test period:
3 Hours
Deduplication:
1 Day