Multiple Entra ID Admin Removals

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Content Index


Looks for multiple users that had their admin role removed by a single user within a certain period.

Attribute Value
Type Hunting Query
Solution GitHub Only
ID 7ffb31ee-f164-4613-a9a7-4d04d0dba5d7
Tactics Persistence
Required Connectors MicrosoftThreatProtection
Source View on GitHub

Tables Used

This content item queries data from the following tables:

Table Selection Criteria Transformations Ingestion API Lake-Only
CloudAppEvents ActionType in "Remove eligible member from role.,Remove member from role." ?

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Hunting Queries