Authentication method added to an Azure account
Synopsis
Field
Value
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
1 Day
Required Data
AzureAD Audit Log
Detection Modules
Identity Threat Module, SaaS Threat Detection
ATT&CK Tactic
Persistence (TA0003)
ATT&CK Technique
Valid Accounts (T1078)
Severity
Informational
Description
An identity attempted to add an Azure authentication method.
Attacker's Goals
An attacker can add an authentication method to an account, so they can have later access to the tenant and resources.
Investigative actions
Check if the authentication method is legitimate in the organization.
Check whether the identity is permitted to perform such actions.
Follow the account for possible suspicious or unusual logins.
Variations
PreviousAuthentication Attempt From a Dormant Account
NextAuthentication method was added to Azure account
Was this helpful?
