An Azure identity performed multiple actions that were denied
Synopsis
Field
Value
Activation Period
14 Days
Training Period
30 Days
Test Period
10 Minutes
Deduplication Period
5 Days
Required Data
Requires one of the following data sources: Azure Audit Log OR Microsoft Graph Logs
Detection Modules
Cloud
Detector Tags
Microsoft Graph Activity Logs
ATT&CK Tactic
Discovery (TA0007)
ATT&CK Technique
Account Discovery (T1087), Permission Groups Discovery (T1069)
Severity
Informational
Description
An identity performed multiple Microsoft Graph actions that were denied, which may indicate it is being misused.
Attacker's Goals
Execute various of commands to explore the cloud environment.
Investigative actions
Check the identity's role designation in the organization. Check if there are additional calls executed by the identity.
Variations
Was this helpful?
