Analytics
Low
✕
Multiple Azure AD admin role removals
An Azure AD identity removed multiple administrators from their roles.
- Module:
- Identity Threat Detection (ITDR), SaaS Threat Detection
- Licensed by:
- Identity Threat Detection (ITDR)
- Data source:
- AzureAD Audit Log
ATT&CK tactics: Impact (TA0040)
ATT&CK techniques: Account Access Removal (T1531)
Attacker's goals:
An attacker may want to lock out an organization and retain sole access.
Investigative actions:
Check if the identity performing the actions was authorized to perform them. Check what roles the users were removed from. Check whether the identity is a newly added admin. Check if the identity is operating in its usual manner (location, time, operations)* Check if the identity performed additional operations in the cloud environment that might be malicious.
- Test period:
- 3 Hours
- Deduplication:
- 1 Day