Azure user password reset
Synopsis
Field
Value
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
5 Days
Required Data
Requires one of the following data sources: Azure Audit Log OR Microsoft Graph Logs
Detection Modules
Cloud
Detector Tags
Microsoft Graph Activity Logs
ATT&CK Tactic
Persistence (TA0003)
ATT&CK Technique
Valid Accounts (T1078), Account Manipulation (T1098)
Severity
Informational
Description
The password of an Azure AD user was reset.
Attacker's Goals
An attacker may attempt to gain access to the account.
Investigative actions
Look for any unusual behavior originated from the suspected identity, and check if they're compromised.
Was this helpful?
