Unusual Conditional Access operation for an identity
Synopsis
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
1 Day
Required Data
AzureAD Audit Log
Detection Modules
Identity Threat Module, SaaS Threat Detection
ATT&CK Tactic
Defense Impairment (TA0112)
ATT&CK Technique
Modify Authentication Process: Conditional Access Policies (T1556.009)
Severity
Informational
Description
An identity attempted to add or update an Azure AD Conditional Access policy.
Attacker's Goals
An attacker attempts to change Active Directory configuration for persistence or defense evasion.
With a modified Conditional Access policy, an attacker might be able to access the tenant without possible blockage for later access.
Investigative actions
Check implications of the updated policy.
Check whether the user changing the configuration is permitted to perform such actions.
Variations
Was this helpful?
