Authentication method was added to Azure account
Synopsis
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
5 Days
Required Data
Requires one of the following data sources: Azure Audit Log OR Microsoft Graph Logs
Detection Modules
Cloud
Detector Tags
Microsoft Graph Activity Logs
ATT&CK Tactic
Persistence (TA0003)
ATT&CK Technique
Modify Authentication Process (T1556)
Severity
Informational
Description
A new authentication method was added to an Azure AD user.
Attacker's Goals
Establish a backdoor for persistent access.
Investigative actions
Review recent authentication attempts and access logs to detect any unauthorized activities or potential misuse of the newly added authentication method.
Look for any unusual behavior originated from the suspected identity, and check if they're compromised.
Was this helpful?
