For the complete documentation index, see llms.txt. This page is also available as Markdown.

Owner added to Azure application

Synopsis

Field
Value

Activation Period

14 Days

Training Period

30 Days

Test Period

N/A (single event)

Deduplication Period

1 Day

Required Data

AzureAD Audit Log

Detection Modules

Identity Threat Module, SaaS Threat Detection

ATT&CK Tactic

Credential Access (TA0006)

ATT&CK Technique

Steal Application Access Token (T1528)

Severity

Informational

Description

An identity was added as an owner to an Azure application.

Attacker's Goals

  • An attacker may add owners to an application to authenticate as the application later on and access resources.

Investigative actions

  • Check if the added account is new to the organization.

  • Check whether the account that added the new owner is supposed to perform such actions.

  • Check for possible logins from the application modified.

  • Follow further actions done by the application.

Was this helpful?