Azure account deletion by a non-standard account
Synopsis
Field
Value
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
1 Day
Required Data
AzureAD Audit Log
Detection Modules
Identity Threat Module, SaaS Threat Detection
ATT&CK Tactic
Impact (TA0040)
ATT&CK Technique
Account Access Removal (T1531)
Severity
Low
Description
An Azure AD account deletion was performed by a user that doesn't typically delete users.
Attacker's Goals
Interrupt availability and access to Azure by deleting access accounts.
Investigative actions
Follow further actions by the initiator.
Check what services, groups and applications are affected by the deleted user being removed.
Check if the deleted user had a privileged role.
Variations
PreviousAzure account creation by a non-standard account
NextAzure AD account unlock/password reset attempt
Was this helpful?
