Azure Privilege Escalation Using an Application
Synopsis
Activation Period
14 Days
Training Period
30 Days
Test Period
5 Hours
Deduplication Period
1 Day
Required Data
Requires all of the following: AzureAD Audit Log Microsoft Graph Logs Office 365 Audit Okta Palo Alto Networks Global Protect OR Third-Party VPNs XDR Agent XDR Agent with eXtended Threat Hunting (XTH)
Detection Modules
Identity Threat Module
ATT&CK Tactic
Privilege Escalation (TA0004)
ATT&CK Technique
Abuse Elevation Control Mechanism (T1548)
Severity
Medium
Description
An Azure application was observed assigning an Azure administrator role to a user. This might indicate a privilege escalation attempt.
Attacker's Goals
An attacker may add additional roles or permissions to an attacker controlled cloud account to maintain persistent access to a tenant.
Investigative actions
Check if the affected account is new to the organization.
Check whether the application that added the account to the role is permitted to perform such actions.
Check what can be affected by the assigned role* Follow further actions done by the account that was added to the role.
Was this helpful?
