An inactive user attempted to authenticate
Synopsis
Field
Value
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
1 Day
Detection Modules
Identity Analytics
ATT&CK Tactic
Initial Access (TA0001)
ATT&CK Technique
Valid Accounts: Cloud Accounts (T1078.004)
Severity
Informational
Description
A user with no activity in the past 30 days with the target, attempted to authenticate via universal authentication.
Attacker's Goals
Use an account that was possibly compromised in the past to gain access to the network.
Investigative actions
Confirm that the activity is benign (e.g. the user returned from a long leave of absence).
Variations
PreviousAn identity was granted permissions to manage user access to Azure resources
NextAn internal Cloud resource performed port scan on external networks
Was this helpful?
