Successful unusual guest user invitation
Synopsis
Field
Value
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
1 Day
Required Data
AzureAD Audit Log
Detection Modules
Identity Threat Module, SaaS Threat Detection
ATT&CK Tactic
Persistence (TA0003)
ATT&CK Technique
Valid Accounts (T1078)
Severity
Informational
Description
An identity successfully invited a guest user to the tenant with unusual characteristics.
Attacker's Goals
An attacker can invite users to for evasion.
Investigative actions
Check who is the invited guest user.
Check whether the inviter is permitted to perform such actions.
Check if the domain of the invited guest is allowed for invitations in the organization.
Variations
PreviousSuccessful universal authentication with suspicious features
NextSudden spike in outbound email volume
Was this helpful?
