For the complete documentation index, see llms.txt. This page is also available as Markdown.

Device Registration Policy modification

Synopsis

Field
Value

Activation Period

14 Days

Training Period

30 Days

Test Period

N/A (single event)

Deduplication Period

1 Day

Required Data

AzureAD Audit Log

Detection Modules

Identity Threat Module, SaaS Threat Detection

ATT&CK Tactic

Defense Impairment (TA0112)

ATT&CK Technique

Modify Authentication Process (T1556)

Severity

Informational

Description

An identity changed the Device Registration policy.

Attacker's Goals

  • An attacker attempts to change Active Directory configuration for persistence or defense evasion.

  • With a modified Device Registration policy, an attacker might be able to access the tenant without possible blockage for later access.

Investigative actions

  • Check what policy has been changed.

  • Check whether the user changing the configuration is permitted to perform such actions.

Variations

A user modified the Device Registration Policy for the first time

Synopsis

Field
Value

ATT&CK Tactic

Defense Impairment (TA0112)

ATT&CK Technique

Modify Authentication Process (T1556)

Severity

Low

Description

An identity changed the Device Registration policy.

Attacker's Goals

  • An attacker attempts to change Active Directory configuration for persistence or defense evasion.

  • With a modified Device Registration policy, an attacker might be able to access the tenant without possible blockage for later access.

Investigative actions

  • Check what policy has been changed.

  • Check whether the user changing the configuration is permitted to perform such actions.

Was this helpful?