Threat Essentials - NRT User added to Microsoft Entra ID Privileged Groups

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Content Index


This will alert when a user is added to any of the Privileged Groups. For further information on AuditLogs please see https://docs.microsoft.com/azure/active-directory/reports-monitoring/reference-audit-activities. For Administrator role permissions in Microsoft Entra ID please see https://docs.microsoft.com/azure/active-directory/users-groups-roles/directory-assign-admin-roles

Attribute Value
Type Analytic Rule
Solution SecurityThreatEssentialSolution
ID 0a627f29-f0dd-4924-be92-c3d6dac84367
Severity Medium
Status Available
Kind NRT
Tactics Persistence, PrivilegeEscalation
Techniques T1098, T1078
Required Connectors AzureActiveDirectory
Source View on GitHub

Tables Used

This content item queries data from the following tables:

Table Transformations Ingestion API Lake-Only
AuditLogs ?

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Analytic Rules · Back to SecurityThreatEssentialSolution