User Removed From Group With CA Policy Modification Access

 Original Source: [Sigma source]
Title: User Removed From Group With CA Policy Modification Access
Status: test
Description:Monitor and alert on group membership removal of groups that have CA policy modification access
References:
  -https://learn.microsoft.com/en-us/entra/architecture/security-operations-infrastructure#conditional-access
Author: Mark Morowczynski '@markmorow', Thomas Detzner '@tdetzner'
Date: 2022-08-04
modified:None
Tags:
  • -'attack.privilege-escalation'
  • -'attack.credential-access'
  • -'attack.persistence'
  • -'attack.defense-impairment'
  • -'attack.t1548'
  • -'attack.t1556'
Logsource:
  • product: azure
  • service: auditlogs
Detection:
  selection:
    properties.message: 'Remove member from group'
  condition:selection
Falsepositives:
  -User removed from the group is approved
Level: medium