Azure domain federation settings modification attempt
Synopsis
Field
Value
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
1 Day
Required Data
AzureAD Audit Log
Detection Modules
Identity Threat Module, SaaS Threat Detection
ATT&CK Tactic
Persistence (TA0003), Privilege Escalation (TA0004)
ATT&CK Technique
Account Manipulation: Additional Cloud Credentials (T1098.001), Domain or Tenant Policy Modification (T1484)
Severity
Low
Description
A user or application attempted to modify the federation settings of the domain.
Attacker's Goals
An attacker attempts to change Active Directory configuration for persistence or defense evasion.
Investigative actions
Check what configuration has been changed.
Check whether the user changing the configuration is permitted.
Variations
PreviousAzure diagnostic configuration deletion
NextAzure enumeration activity using Microsoft Graph API
Was this helpful?
