Analytics BIOC Informational

Unverified domain added to Azure AD

A new unverified domain was added to Azure AD.

Module:
Identity Threat Detection (ITDR), SaaS Threat Detection
Licensed by:
Identity Threat Detection (ITDR)
Data source:
AzureAD Audit Log
ATT&CK tactics: Persistence (TA0003)
ATT&CK techniques: Account Manipulation: Additional Cloud Credentials (T1098.001)
Attacker's goals:

An attacker attempts to change Active Directory configuration for persistence or defense evasion.

Investigative actions:

Check if the new domain is known for the organization. Check whether the user changing the configuration is permitted. Monitor network activity to and from the added domain.

Test period:
N/A (single event)
Deduplication:
1 Hour
1 variation:
  • Rare unverified domain addition to Azure AD Low (parent: Informational)