New CA Policy by Non-approved Actor

 Original Source: [Sigma source]
Title: New CA Policy by Non-approved Actor
Status: test
Description:Monitor and alert on conditional access changes.
References:
  -https://learn.microsoft.com/en-us/entra/architecture/security-operations-infrastructure
Author: Corissa Koopmans, '@corissalea'
Date: 2022-07-18
modified:None
Tags:
  • -'attack.privilege-escalation'
  • -'attack.t1548'
Logsource:
  • product: azure
  • service: auditlogs
Detection:
  selection:
    properties.message: 'Add conditional access policy'
  condition:selection
Falsepositives:
  -Misconfigured role permissions
  -Verify whether the user identity, user agent, and/or hostname should be making changes in your environment.
Level: medium