Dataverse - Suspicious security role modifications

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Content Index


Identifies an unusual pattern of events whereby a new role is created followed by the creator adding members to the role and subsequently removing the member or deleting the role after a short time period.

Attribute Value
Type Analytic Rule
Solution Microsoft Business Applications
ID e44a58b2-b63a-4eb9-92da-85660d73495c
Severity Medium
Status Available
Kind Scheduled
Tactics PrivilegeEscalation
Techniques T1404, T1626, T1548
Required Connectors Dataverse
Source View on GitHub

Tables Used

This content item queries data from the following tables:

Table Transformations Ingestion API Lake-Only
DataverseActivity ?

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Analytic Rules · Back to Microsoft Business Applications