For the complete documentation index, see llms.txt. This page is also available as Markdown.

Azure AD PIM elevation request

Synopsis

Field
Value

Activation Period

14 Days

Training Period

30 Days

Test Period

N/A (single event)

Deduplication Period

1 Day

Required Data

AzureAD Audit Log

Detection Modules

Identity Threat Module, SaaS Threat Detection

ATT&CK Tactic

Privilege Escalation (TA0004)

ATT&CK Technique

Valid Accounts (T1078)

Severity

Informational

Description

An Azure AD PIM elevation request was denied/approved.

Attacker's Goals

Getting elevated permissions to perform malicious actions.

Investigative actions

  • Check if the elevation is authorized.

  • Follow further actions or suspicious logins from the elevated account.

Was this helpful?