Azure conditional access policy creation or modification
Synopsis
Field
Value
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
5 Days
Required Data
Requires one of the following data sources: Azure Audit Log OR Microsoft Graph Logs
Detection Modules
Cloud
Detector Tags
Microsoft Graph Activity Logs
ATT&CK Tactic
Defense Impairment (TA0112)
ATT&CK Technique
Modify Authentication Process: Conditional Access Policies (T1556.009)
Severity
Informational
Description
An Azure conditional access policy was created or modified.
Attacker's Goals
Bypass authentication controls.
Investigative actions
Investigate the rule's details and confirm its legitimacy.
Look for any unusual behavior originated from the suspected identity, and check if they're compromised.
PreviousAzure Blob Container Access Level Modification
NextAzure device code authentication flow used
Was this helpful?
