For the complete documentation index, see llms.txt. This page is also available as Markdown.

Azure service principal assigned app role

Synopsis

Field
Value

Activation Period

14 Days

Training Period

30 Days

Test Period

N/A (single event)

Deduplication Period

1 Day

Required Data

AzureAD Audit Log

Detection Modules

Identity Threat Module, SaaS Threat Detection

ATT&CK Tactic

Privilege Escalation (TA0004)

ATT&CK Technique

Valid Accounts (T1078)

Severity

Informational

Description

An identity assigned an app role (permissions) to a service principal.

Attacker's Goals

  • An attacker may add roles to service principals that will allow them to access sensitive information and perform other actions.

Investigative actions

  • Check if the added service principle is new to the organization.

  • Check whether the account that added the app role is supposed to perform such actions.

  • Check for possible logins and actions from the service principle with the role.

  • Follow further actions done by the application and the assigner.

Was this helpful?