Owner added to Azure application
Synopsis
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
1 Day
Required Data
AzureAD Audit Log
Detection Modules
Identity Threat Module, SaaS Threat Detection
ATT&CK Tactic
Credential Access (TA0006)
ATT&CK Technique
Steal Application Access Token (T1528)
Severity
Informational
Description
An identity was added as an owner to an Azure application.
Attacker's Goals
An attacker may add owners to an application to authenticate as the application later on and access resources.
Investigative actions
Check if the added account is new to the organization.
Check whether the account that added the new owner is supposed to perform such actions.
Check for possible logins from the application modified.
Follow further actions done by the application.
Was this helpful?
