For the complete documentation index, see llms.txt. This page is also available as Markdown.

An Azure identity performed multiple actions that were denied

Synopsis

Field
Value

Activation Period

14 Days

Training Period

30 Days

Test Period

10 Minutes

Deduplication Period

5 Days

Required Data

Requires one of the following data sources: Azure Audit Log OR Microsoft Graph Logs

Detection Modules

Cloud

Detector Tags

Microsoft Graph Activity Logs

ATT&CK Tactic

Discovery (TA0007)

ATT&CK Technique

Account Discovery (T1087), Permission Groups Discovery (T1069)

Severity

Informational

Description

An identity performed multiple Microsoft Graph actions that were denied, which may indicate it is being misused.

Attacker's Goals

Execute various of commands to explore the cloud environment.

Investigative actions

Check the identity's role designation in the organization. Check if there are additional calls executed by the identity.

Variations

An Azure application attempted multiple actions on resources that were denied

Synopsis

Field
Value

ATT&CK Tactic

Discovery (TA0007)

ATT&CK Technique

Account Discovery (T1087), Permission Groups Discovery (T1069)

Severity

Medium

Description

An identity performed multiple Microsoft Graph actions that were denied, which may indicate it is being misused.

Attacker's Goals

Execute various of commands to explore the cloud environment.

Investigative actions

Check the identity's role designation in the organization. Check if there are additional calls executed by the identity.

An Azure identity attempted multiple actions on resources that were denied

Synopsis

Field
Value

ATT&CK Tactic

Discovery (TA0007)

ATT&CK Technique

Account Discovery (T1087), Permission Groups Discovery (T1069)

Severity

Low

Description

An identity performed multiple Microsoft Graph actions that were denied, which may indicate it is being misused.

Attacker's Goals

Execute various of commands to explore the cloud environment.

Investigative actions

Check the identity's role designation in the organization. Check if there are additional calls executed by the identity.

An Azure application performed multiple actions that were denied

Synopsis

Field
Value

ATT&CK Tactic

Discovery (TA0007)

ATT&CK Technique

Account Discovery (T1087), Permission Groups Discovery (T1069)

Severity

Low

Description

An identity performed multiple Microsoft Graph actions that were denied, which may indicate it is being misused.

Attacker's Goals

Execute various of commands to explore the cloud environment.

Investigative actions

Check the identity's role designation in the organization. Check if there are additional calls executed by the identity.

Was this helpful?