Unverified domain added to Azure AD
Synopsis
Field
Value
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
1 Hour
Required Data
AzureAD Audit Log
Detection Modules
Identity Threat Module, SaaS Threat Detection
ATT&CK Tactic
Persistence (TA0003)
ATT&CK Technique
Account Manipulation: Additional Cloud Credentials (T1098.001)
Severity
Informational
Description
A new unverified domain was added to Azure AD.
Attacker's Goals
An attacker attempts to change Active Directory configuration for persistence or defense evasion.
Investigative actions
Check if the new domain is known for the organization.
Check whether the user changing the configuration is permitted.
Monitor network activity to and from the added domain.
Variations
Was this helpful?
