Azure AD PIM role settings change
Synopsis
Field
Value
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
1 Hour
Required Data
AzureAD Audit Log
Detection Modules
Identity Threat Module, SaaS Threat Detection
ATT&CK Tactic
Stealth (TA0005), Privilege Escalation (TA0004)
ATT&CK Technique
Abuse Elevation Control Mechanism (T1548), Valid Accounts (T1078)
Severity
Low
Description
An identity changed the PIM role settings.
Attacker's Goals
An attacker can modify the PIM role settings to make it easier to acquire a privileged account.
Investigative actions
Check what role settings have been updated.
Check whether the user changing the settings is permitted to perform such actions.
Variations
Was this helpful?
