Break-glass account role or group membership changed

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

↑ Back to Content Index


Identifies role and group membership changes on an account designated as an emergency break-glass account, whose access is meant to stay fixed to the single role documented in the tenant's emergency-access runbook.

Attribute Value
Type Hunting Query
Solution Standalone Content
ID 4f529b32-a4ed-40d0-b40b-7ac337a705be
Tactics Persistence, PrivilegeEscalation
Techniques T1098.003
Required Connectors AzureActiveDirectory
Source [View on GitHub](https://github.com/Azure/Azure-Sentinel/blob/master/Hunting Queries/AuditLogs/BreakGlassAccountRoleOrGroupMembershipChanged.yaml)

Tables Used

This content item queries data from the following tables:

Table Selection Criteria Transformations Ingestion API Lake-Only
AuditLogs OperationName in "Add member to group,Add member to role,Add member to role.,Add owner to group,Remove member from group,Remove member from role,Remove member from role.,Remove owner from group"
OperationName has "Add"
OperationName has "owner"
✓ ✗ ✓

Associated Connectors

The following connectors provide data for this content item:

Connector Solution
AzureActiveDirectory Microsoft Entra ID

Solutions: Microsoft Entra ID


Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

↑ Back to Hunting Queries