Device Registration Policy modification
Synopsis
Field
Value
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
1 Day
Required Data
AzureAD Audit Log
Detection Modules
Identity Threat Module, SaaS Threat Detection
ATT&CK Tactic
Defense Impairment (TA0112)
ATT&CK Technique
Modify Authentication Process (T1556)
Severity
Informational
Description
An identity changed the Device Registration policy.
Attacker's Goals
An attacker attempts to change Active Directory configuration for persistence or defense evasion.
With a modified Device Registration policy, an attacker might be able to access the tenant without possible blockage for later access.
Investigative actions
Check what policy has been changed.
Check whether the user changing the configuration is permitted to perform such actions.
Variations
PreviousDenied API call by a Kubernetes service account
NextDisable AWS audit logs through Event Selectors
Was this helpful?
