SSO authentication by a service account
Synopsis
Field
Value
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
2 Days
Required Data
Requires one of the following data sources: AzureAD OR Azure SignIn Log OR Idira OR Duo OR Okta OR OneLogin OR PingOne
Detection Modules
Identity Analytics
ATT&CK Tactic
Initial Access (TA0001)
ATT&CK Technique
Valid Accounts: Domain Accounts (T1078.002)
Severity
Low
Description
A service account successfully authenticated via SSO.
Attacker's Goals
Use an account that has access to resources to move laterally in the network and access privileged resources.
Investigative actions
Check whether the account has done any administrative actions it should not usually do.
Look for more logins and authentications by the account throughout the network.
Variations
Was this helpful?
