This website uses cookies to ensure you get the best experience.
Got it!
Register
|
Login
Menu
Home
Sigma Rules
Splunk Rules
Explore Rules
Analytic Stories
MITRE ATT&CK
Overview
Matrix
Techniques
Groups
Software
Campaigns
Search
About
User Added to an Administrator's Azure AD Role
Original Source:
[Sigma source]
Title:
User Added to an Administrator's Azure AD Role
Status:
test
Description:
User Added to an Administrator's Azure AD Role
References:
-https://web.archive.org/web/20250904191633/https://m365internals.com/2021/07/13/what-ive-learned-from-doing-a-year-of-cloud-forensics-in-azure-ad/
-https://research.splunk.com/cloud/a28f0bc3-3400-4a6e-a2da-89b9e95f0d2a/
-https://analyticsrules.exchange/analyticrules/2a09f8cb-deb7-4c40-b08b-9137667f1c0b/
-https://learn.microsoft.com/en-us/entra/identity/monitoring-health/reference-audit-activities#core-directory
Author:
Raphaƫl CALVET, @MetallicHack
Date:
2021-10-04
modified:
2026-04-30
Tags:
-'attack.initial-access'
-'attack.persistence'
-'attack.privilege-escalation'
-'attack.stealth'
-'attack.t1098.003'
-'attack.t1078'
Logsource:
product: azure
service: auditlogs
Detection:
selection:
operationName
:
'Add member to role'
properties.targetResources|contains
:
-'Admins'
-'Administrator'
condition
:
selection
Falsepositives:
-PIM (Privileged Identity Management) generates this event each time 'eligible role' is enabled.
Level:
medium