Title:
CA Policy Removed by Non Approved Actor
Status:
test
Description:Monitor and alert on conditional access changes where non approved actor removed CA Policy.
References:
-https://learn.microsoft.com/en-us/entra/architecture/security-operations-infrastructure#conditional-access
Author: Corissa Koopmans, '@corissalea'
Date: 2022-07-19
modified:None
Tags:
- -'attack.privilege-escalation'
- -'attack.credential-access'
- -'attack.persistence'
- -'attack.defense-impairment'
- -'attack.t1548'
- -'attack.t1556'
Logsource:
- product: azure
- service: auditlogs
Detection:
selection:
properties.message:
'Delete conditional access policy'
condition:
selection
Falsepositives:
-Misconfigured role permissions
-Verify whether the user identity, user agent, and/or hostname should be making changes in your environment.
Level:
medium