For the complete documentation index, see llms.txt. This page is also available as Markdown.

Azure AD PIM role settings change

Synopsis

Field
Value

Activation Period

14 Days

Training Period

30 Days

Test Period

N/A (single event)

Deduplication Period

1 Hour

Required Data

AzureAD Audit Log

Detection Modules

Identity Threat Module, SaaS Threat Detection

ATT&CK Tactic

Stealth (TA0005), Privilege Escalation (TA0004)

ATT&CK Technique

Abuse Elevation Control Mechanism (T1548), Valid Accounts (T1078)

Severity

Low

Description

An identity changed the PIM role settings.

Attacker's Goals

  • An attacker can modify the PIM role settings to make it easier to acquire a privileged account.

Investigative actions

  • Check what role settings have been updated.

  • Check whether the user changing the settings is permitted to perform such actions.

Variations

Suspicious Azure AD PIM role settings change

Synopsis

Field
Value

ATT&CK Tactic

Stealth (TA0005), Privilege Escalation (TA0004)

ATT&CK Technique

Abuse Elevation Control Mechanism (T1548), Valid Accounts (T1078)

Severity

Medium

Description

An identity modified the PIM role settings to a less secure configuration for a privileged role.

Attacker's Goals

  • An attacker can modify the PIM role settings to make it easier to acquire a privileged account.

Investigative actions

  • Check what role settings have been updated.

  • Check whether the user changing the settings is permitted to perform such actions.

Was this helpful?