For the complete documentation index, see llms.txt. This page is also available as Markdown.

Azure Privilege Escalation Using an Application

Synopsis

Field
Value

Activation Period

14 Days

Training Period

30 Days

Test Period

5 Hours

Deduplication Period

1 Day

Required Data

Requires all of the following: AzureAD Audit Log Microsoft Graph Logs Office 365 Audit Okta Palo Alto Networks Global Protect OR Third-Party VPNs XDR Agent XDR Agent with eXtended Threat Hunting (XTH)

Detection Modules

Identity Threat Module

ATT&CK Tactic

Privilege Escalation (TA0004)

ATT&CK Technique

Abuse Elevation Control Mechanism (T1548)

Severity

Medium

Description

An Azure application was observed assigning an Azure administrator role to a user. This might indicate a privilege escalation attempt.

Attacker's Goals

  • An attacker may add additional roles or permissions to an attacker controlled cloud account to maintain persistent access to a tenant.

Investigative actions

  • Check if the affected account is new to the organization.

  • Check whether the application that added the account to the role is permitted to perform such actions.

  • Check what can be affected by the assigned role* Follow further actions done by the account that was added to the role.

Was this helpful?