Azure AD PIM alert disabled
Synopsis
Field
Value
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
1 Day
Required Data
AzureAD Audit Log
Detection Modules
Identity Threat Module, SaaS Threat Detection
ATT&CK Tactic
Defense Impairment (TA0112)
ATT&CK Technique
Domain or Tenant Policy Modification (T1484)
Severity
Medium
Description
An identity disabled an Azure AD PIM alert.
Attacker's Goals
An attacker might want to disable alerts associated with authentication requirements for privileged access.
This may allow malicious activities to go unnoticed.
Investigative actions
Check what alert was disabled.
Check whether the user that disabled the alert is permitted to perform such actions.
Was this helpful?
