[Entra ID] Authentication Method Changed for Privileged Account

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

Back to Content Index


Detects changes to authentication methods on privileged accounts. This may indicate an attacker added a new method to maintain access.

Attribute Value
Type Analytic Rule
Solution eDCRule
ID 9f7197b6-eeb2-46f3-83b1-a2c4dfca46a0
Severity High
Status Available
Kind Scheduled
Tactics Persistence
Techniques T1098
Required Connectors AzureActiveDirectory
Source View on GitHub

Tables Used

This content item queries data from the following tables:

Table Transformations Ingestion API Lake-Only
AuditLogs
IdentityInfo ?

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

Back to Analytic Rules · Back to eDCRule