Azure AD account unlock/password reset attempt
Synopsis
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
1 Day
Required Data
AzureAD Audit Log
Detection Modules
Identity Threat Module, SaaS Threat Detection
ATT&CK Tactic
Persistence (TA0003)
ATT&CK Technique
Valid Accounts (T1078)
Severity
Informational
Description
An attempt to unlock an Azure AD identity or reset its password has occurred.
Attacker's Goals
An attacker may switch a valid account's password for persistence.
Investigative actions
Check if the password reset is authorized.
Check whether the user who reset the password is permitted to perform such actions.
Check if the account is in the password reset group or is acting out of scope.
Check whether the user has not completed the password reset and cancelled before successfully passing authentication methods.
Follow further actions or suspicious logins from the target account.
Variations
Was this helpful?
