Azure service principal assigned app role
Synopsis
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
1 Day
Required Data
AzureAD Audit Log
Detection Modules
Identity Threat Module, SaaS Threat Detection
ATT&CK Tactic
Privilege Escalation (TA0004)
ATT&CK Technique
Valid Accounts (T1078)
Severity
Informational
Description
An identity assigned an app role (permissions) to a service principal.
Attacker's Goals
An attacker may add roles to service principals that will allow them to access sensitive information and perform other actions.
Investigative actions
Check if the added service principle is new to the organization.
Check whether the account that added the app role is supposed to perform such actions.
Check for possible logins and actions from the service principle with the role.
Follow further actions done by the application and the assigner.
Was this helpful?
