For the complete documentation index, see llms.txt. This page is also available as Markdown.

Azure AD PIM alert disabled

Synopsis

Field
Value

Activation Period

14 Days

Training Period

30 Days

Test Period

N/A (single event)

Deduplication Period

1 Day

Required Data

AzureAD Audit Log

Detection Modules

Identity Threat Module, SaaS Threat Detection

ATT&CK Tactic

Defense Impairment (TA0112)

ATT&CK Technique

Domain or Tenant Policy Modification (T1484)

Severity

Medium

Description

An identity disabled an Azure AD PIM alert.

Attacker's Goals

  • An attacker might want to disable alerts associated with authentication requirements for privileged access.

  • This may allow malicious activities to go unnoticed.

Investigative actions

  • Check what alert was disabled.

  • Check whether the user that disabled the alert is permitted to perform such actions.

Was this helpful?