For the complete documentation index, see llms.txt. This page is also available as Markdown.

Azure AD account unlock/password reset attempt

Synopsis

Field
Value

Activation Period

14 Days

Training Period

30 Days

Test Period

N/A (single event)

Deduplication Period

1 Day

Required Data

AzureAD Audit Log

Detection Modules

Identity Threat Module, SaaS Threat Detection

ATT&CK Tactic

Persistence (TA0003)

ATT&CK Technique

Valid Accounts (T1078)

Severity

Informational

Description

An attempt to unlock an Azure AD identity or reset its password has occurred.

Attacker's Goals

  • An attacker may switch a valid account's password for persistence.

Investigative actions

  • Check if the password reset is authorized.

  • Check whether the user who reset the password is permitted to perform such actions.

  • Check if the account is in the password reset group or is acting out of scope.

  • Check whether the user has not completed the password reset and cancelled before successfully passing authentication methods.

  • Follow further actions or suspicious logins from the target account.

Variations

Azure AD account unlock/successful password reset

Synopsis

Field
Value

ATT&CK Tactic

Persistence (TA0003)

ATT&CK Technique

Valid Accounts (T1078)

Severity

Low

Description

An identity successfully reset or changed Azure AD password.

Attacker's Goals

  • An attacker may switch a valid account's password for persistence.

Investigative actions

  • Check if the password reset is authorized.

  • Check whether the user who reset the password is permitted to perform such actions.

  • Check if the account is in the password reset group or is acting out of scope.

  • Check whether the user has not completed the password reset and cancelled before successfully passing authentication methods.

  • Follow further actions or suspicious logins from the target account.

Was this helpful?