PIM privilege member removal
Synopsis
Field
Value
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
5 Days
Required Data
Azure Audit Log
Detection Modules
Cloud
ATT&CK Tactic
Impact (TA0040)
ATT&CK Technique
Account Access Removal (T1531)
Severity
Informational
Description
A cloud identity has removed a user's privileged role within PIM.
Attacker's Goals
Disrupt system and network access by blocking legitimate user accounts.
Investigative actions
Investigate the suspected identity who initiated the removal.
Identify the privileged accounts that were affected.
Review the current access rights of the privileged accounts.
Was this helpful?
