An identity was granted permissions to manage user access to Azure resources
Synopsis
Field
Value
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
5 Days
Required Data
Azure Audit Log
Detection Modules
Cloud
ATT&CK Tactic
Privilege Escalation (TA0004)
ATT&CK Technique
Valid Accounts: Cloud Accounts (T1078.004), Abuse Elevation Control Mechanism: Temporary Elevated Cloud Access (T1548.005)
Severity
Informational
Description
An identity was granted the User Access Administrator permission at the tenant scope.
Attacker's Goals
Elevate permission to gain access to all Azure Subscriptions.
Investigative actions
Verify whether the identity should be making this action.* Check what additional API calls were made by the identity.
PreviousAn identity successfully extracted multiple secrets within the organization
NextAn inactive user attempted to authenticate
Was this helpful?
