App Granted Microsoft Permissions

 Original Source: [Sigma source]
Title: App Granted Microsoft Permissions
Status: test
Description:Detects when an application is granted delegated or app role permissions for Microsoft Graph, Exchange, Sharepoint, or Azure AD
References:
  -https://learn.microsoft.com/en-us/entra/architecture/security-operations-applications#application-granted-highly-privileged-permissions
Author: Bailey Bercik '@baileybercik', Mark Morowczynski '@markmorow'
Date: 2022-07-10
modified:None
Tags:
  • -'attack.credential-access'
  • -'attack.t1528'
Logsource:
  • product: azure
  • service: auditlogs
Detection:
  selection:
    properties.message:
      -'Add delegated permission grant'
      -'Add app role assignment to service principal'

  condition:selection
Falsepositives:
  -When the permission is legitimately needed for the app
Level: high