Identity assigned an Azure AD Administrator Role
Synopsis
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
1 Day
Required Data
AzureAD Audit Log
Detection Modules
Identity Threat Module, SaaS Threat Detection
ATT&CK Tactic
Persistence (TA0003)
ATT&CK Technique
Account Manipulation: Additional Cloud Roles (T1098.003)
Severity
Informational
Description
An identity was assigned an Azure AD Administrator role.
Attacker's Goals
An attacker may add additional roles or permissions to an attacker controlled cloud account to maintain persistent access to a tenant.
Investigative actions
Check if the added account is new to the organization.
Check whether the account that added the account to the role is permitted to perform such actions.
Check what can be affected by the assigned role* Follow further actions done by the account that was added to the role.
Variations
Was this helpful?
