For the complete documentation index, see llms.txt. This page is also available as Markdown.

Identity assigned an Azure AD Administrator Role

Synopsis

Field
Value

Activation Period

14 Days

Training Period

30 Days

Test Period

N/A (single event)

Deduplication Period

1 Day

Required Data

AzureAD Audit Log

Detection Modules

Identity Threat Module, SaaS Threat Detection

ATT&CK Tactic

Persistence (TA0003)

ATT&CK Technique

Account Manipulation: Additional Cloud Roles (T1098.003)

Severity

Informational

Description

An identity was assigned an Azure AD Administrator role.

Attacker's Goals

  • An attacker may add additional roles or permissions to an attacker controlled cloud account to maintain persistent access to a tenant.

Investigative actions

  • Check if the added account is new to the organization.

  • Check whether the account that added the account to the role is permitted to perform such actions.

  • Check what can be affected by the assigned role* Follow further actions done by the account that was added to the role.

Variations

Identity assigned an Azure AD Administrator Role by an Application

Synopsis

Field
Value

ATT&CK Tactic

Persistence (TA0003)

ATT&CK Technique

Account Manipulation: Additional Cloud Roles (T1098.003)

Severity

Medium

Description

An identity was assigned an Azure AD Administrator role by an application.

Attacker's Goals

  • An attacker may add additional roles or permissions to an attacker controlled cloud account to maintain persistent access to a tenant.

Investigative actions

  • Check if the added account is new to the organization.

  • Check whether the account that added the account to the role is permitted to perform such actions.

  • Check what can be affected by the assigned role* Follow further actions done by the account that was added to the role.

Suspicious Azure AD Administrator Role assignment

Synopsis

Field
Value

ATT&CK Tactic

Persistence (TA0003)

ATT&CK Technique

Account Manipulation: Additional Cloud Roles (T1098.003)

Severity

Low

Description

An identity was assigned an Azure AD Administrator role.

Attacker's Goals

  • An attacker may add additional roles or permissions to an attacker controlled cloud account to maintain persistent access to a tenant.

Investigative actions

  • Check if the added account is new to the organization.

  • Check whether the account that added the account to the role is permitted to perform such actions.

  • Check what can be affected by the assigned role* Follow further actions done by the account that was added to the role.

Was this helpful?