Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊
Identifies role and group membership changes on an account designated as an emergency break-glass account, whose access is meant to stay fixed to the single role documented in the tenant's emergency-access runbook.
| Attribute | Value |
|---|---|
| Type | Hunting Query |
| Solution | Standalone Content |
| ID | 4f529b32-a4ed-40d0-b40b-7ac337a705be |
| Tactics | Persistence, PrivilegeEscalation |
| Techniques | T1098.003 |
| Required Connectors | AzureActiveDirectory |
| Source | [View on GitHub](https://github.com/Azure/Azure-Sentinel/blob/master/Hunting Queries/AuditLogs/BreakGlassAccountRoleOrGroupMembershipChanged.yaml) |
This content item queries data from the following tables:
| Table | Selection Criteria | Transformations | Ingestion API | Lake-Only |
|---|---|---|---|---|
AuditLogs |
OperationName in "Add member to group,Add member to role,Add member to role.,Add owner to group,Remove member from group,Remove member from role,Remove member from role.,Remove owner from group"OperationName has "Add"OperationName has "owner" |
✓ | ✗ | ✓ |
The following connectors provide data for this content item:
| Connector | Solution |
|---|---|
| AzureActiveDirectory | Microsoft Entra ID |
Solutions: Microsoft Entra ID
Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊