For the complete documentation index, see llms.txt. This page is also available as Markdown.

Azure permission delegation granted

Synopsis

Field
Value

Activation Period

14 Days

Training Period

30 Days

Test Period

N/A (single event)

Deduplication Period

5 Days

Required Data

Azure Audit Log

Detection Modules

Cloud

ATT&CK Tactic

Persistence (TA0003)

ATT&CK Technique

Account Manipulation (T1098)

Severity

Informational

Description

An identity delegated permissions to access a certain resource or application.

Attacker's Goals

Gain access to sensitive data.* Gain control over user accounts.

Investigative actions

  • Check the user access logs for any suspicious activity.* Review the permissions granted and the scope of the permissions.

Variations

Azure permission delegation granted by an Azure AD privileged user

Synopsis

Field
Value

ATT&CK Tactic

Persistence (TA0003)

ATT&CK Technique

Account Manipulation (T1098)

Severity

Low

Description

An identity delegated permissions to access a certain resource or application.

Attacker's Goals

Gain access to sensitive data.* Gain control over user accounts.

Investigative actions

  • Check the user access logs for any suspicious activity.* Review the permissions granted and the scope of the permissions.

Was this helpful?