Skip to content
Threat Feed

Product

Azure Active Directory

93 briefs RSS
high advisory

Microsoft Security Updates — July 2026

Roundup of Microsoft security advisories published in July 2026.

PoC PowerShell +511 roundup
11c 354i updated
critical advisory

Critical Azure AD Improper Authentication Vulnerability (CVE-2026-45480)

A critical improper authentication vulnerability, CVE-2026-45480, in Microsoft Azure Active Directory allows an unauthorized attacker to bypass authentication mechanisms and elevate privileges over a network, potentially leading to full administrative control of Azure AD and associated resources.

Azure Active Directory azure active-directory cve critical-vulnerability privilege-escalation authentication-bypass
2r 2t
high advisory

Azure AD User ImmutableId Attribute Modification for Persistence

The following analytic identifies modifications to the SourceAnchor (ImmutableId) attribute for an Azure Active Directory user, which is a step in setting up an Azure AD identity federation backdoor that allows an attacker to impersonate any user and bypass MFA.

Splunk Enterprise +3 azuread persistence identityfederation backdoor cloud
2r 1t
high advisory

ABB Ability OPTIMAX Authentication Bypass Vulnerability

CVE-2025-14510 allows an attacker to bypass Azure Active Directory Single-Sign On authentication in vulnerable ABB Ability OPTIMAX versions, potentially granting unauthorized access to critical infrastructure systems.

OPTIMAX 6.1 +4 authentication bypass ics vulnerability
2r 1t 1c
high advisory

Large-Scale OAuth Device Code Phishing Campaign Observed in April 2026

In early April 2026, Arctic Wolf tracked a large-scale device code phishing campaign across multiple regions and sectors where threat actors abused OAuth device code flow to trick victims into providing authentication codes.

Azure Active Directory oauth device-code phishing initial-access
2r 1t
high advisory

O365 Admin Consent Bypassed by Service Principal

A service principal in Office 365 Azure Active Directory assigns app roles without standard admin consent, potentially bypassing critical administrative controls and leading to unauthorized access or privilege escalation.

Office 365 +1 azuread office365 serviceprincipal adminconsent persistence
2r 2t
medium advisory

Unauthorized Modification of Azure Conditional Access Policy

An unauthorized actor modifies an Azure Conditional Access policy, potentially leading to privilege escalation, credential access, persistence, or defense impairment.

Azure Active Directory azure conditional-access policy-modification attack.privilege-escalation attack.credential-access attack.persistence attack.defense-impairment attack.t1548 +1
2r 2t
medium advisory

Azure AD Root Certificate Authority Added for Passwordless Authentication

An attacker may add a new root certificate authority to an Azure AD tenant to support certificate-based authentication for persistence, privilege escalation, or defense evasion.

Azure Active Directory attack.credential-access attack.persistence attack.privilege-escalation attack.defense-impairment attack.t1556
2r 4t
medium advisory

Azure AD Certificate-Based Authentication Enabled

Enabling certificate-based authentication (CBA) in Azure Active Directory can be abused by attackers to establish persistence, escalate privileges, and impair defenses.

Azure Active Directory azure certificate-based-authentication persistence privilege-escalation
2r 1t
medium advisory

Kubernetes Secret or ConfigMap Access via Azure Arc Proxy

Detection of unauthorized access to Kubernetes secrets or configmaps via the Azure Arc AAD proxy service account, indicating potential abuse of stolen service principal credentials to read, exfiltrate, or modify sensitive data.

Azure Arc +2 kubernetes azure-arc credential-access collection
2r 2t
high advisory

Azure AD Sign-In with Unfamiliar Properties

This alert detects Azure AD sign-ins with properties unfamiliar to the user, indicating potential account compromise or unauthorized access.

Azure Active Directory azure identity_protection sign-in account_compromise risk_detection
2r 4t
medium advisory

Azure AD Authentication from Unexpected Geo-locations

Detection of successful authentications originating from geographic locations outside of an organization's expected operational footprint, potentially indicating compromised credentials or unauthorized access.

Azure Active Directory azuread authentication geo-location unauthorized-access credential-compromise privilege-escalation
2r 1t
low advisory

Entra ID External Guest User Invitation

Detection of external guest user invitations in Entra ID, which can be abused for unauthorized access and persistence by creating overlooked accounts.

Entra ID +1 cloud azure initial-access persistence
2r 2t
critical threat

Azure AD Privileged Graph API Permission Assignment

Detection of high-risk Graph API permission assignments (Application.ReadWrite.All, AppRoleAssignment.ReadWrite.All, and RoleManagement.ReadWrite.Directory) in Azure AD, potentially leading to unauthorized modifications and security breaches.

Azure Active Directory NOBELIUM Group azuread cloud graphapi privilegeescalation persistence
2r 1t
high threat

Azure AD FullAccessAsApp Permission Assignment

Detection of 'full_access_as_app' permission assignment to an application in Office 365 Exchange Online, potentially leading to unauthorized access and data exfiltration.

Office 365 Exchange Online +1 NOBELIUM Group azure azuread office365 persistence nobelium
2r 2t
high advisory

Azure AD Device Registration Policy Changes Detected

Monitoring changes to the device registration policy can detect potential privilege escalation or defense impairment attempts by malicious actors aiming to weaken security controls related to device management in Azure Active Directory.

Azure Active Directory azure device-registration policy-change
2r 1t
high advisory

Azure AD Threat Intelligence Detection

This brief focuses on detecting unusual user activity and sign-in patterns flagged by Azure AD Threat Intelligence, which may indicate stealthy attacks, persistence attempts, privilege escalation, or initial access.

Azure Active Directory azuread threat-intelligence risk-detection
2r 1t
medium advisory

Spoofing AD FS Signing Logs via Azure AD Hybrid Health Service

A threat actor can create a new, rogue AD Health ADFS service within Azure and then create a fake server instance, which can be leveraged to spoof AD FS signing logs without compromising on-prem AD FS servers.

Azure Active Directory +1 cloud azure adfs defense-impairment
2r 1t
medium advisory

Unauthorized Removal of Azure Conditional Access Policy

An unauthorized actor removes a Conditional Access policy in Azure, potentially weakening the organization's security posture and enabling privilege escalation or credential access.

Azure Active Directory azure conditional-access privilege-escalation credential-access persistence defense-impairment
2r 3t
high advisory

Azure AD Activity From Anonymous IP Address

Detection of user activity originating from an IP address identified as an anonymous proxy, potentially indicating unauthorized access, privilege escalation, or persistence within an Azure Active Directory environment.

Azure Active Directory azuread anonymous-proxy identity-protection
2r 4t
high advisory

Azure Service Principal Authentication from Multiple Countries

Detects Azure service principals authenticating from multiple countries within a short time, indicating potentially compromised credentials being used from different geographic locations.

Azure +1 cloud service principal initial access credential compromise
2r 1t
medium advisory

Azure AD Service Principal Enumeration via Microsoft Graph API

An attacker uses Microsoft Graph API to enumerate multiple Azure AD service principals, potentially using tools like AzureHound or ROADtools, to gather information for privilege escalation or lateral movement.

Azure Active Directory +1 azuread serviceprincipal enumeration
2r 2t
high advisory

Azure AD Service Principal Created

The creation of a Service Principal in an Azure AD environment is detected, which can be used by adversaries to establish persistence and bypass multi-factor authentication.

Azure Active Directory azure cloud persistence service-principal
2r 1t
high advisory

Entra ID: Global Administrator Role Assigned to PIM User

An adversary may add an account to the Global Administrator role within Azure AD Privileged Identity Management (PIM) to establish persistence and gain privileged access.

Azure Active Directory +1 azure entra_id persistence privilege_escalation
2r 2t
medium advisory

AzureHound Reconnaissance Activity in Azure AD

Detection of the AzureHound User-Agent in Azure AD logs indicates potential reconnaissance activity by adversaries mapping the Azure AD infrastructure for vulnerabilities.

Azure Active Directory +1 azuread reconnaissance azurehound
2r 2t
medium advisory

Azure AD Bitlocker Key Retrieval

An adversary with sufficient privileges in Azure Active Directory may attempt to retrieve BitLocker keys to decrypt drives for lateral movement or data exfiltration.

Azure Active Directory azure bitlocker key-retrieval persistence privilege-escalation
2r 3t
high advisory

Azure AD User Added to Global or Device Admin Role

An attacker may attempt to add a user to a high-privilege Azure AD role, such as Global Administrator or Device Administrator, to establish persistence, gain initial access, escalate privileges, or operate stealthily within the compromised environment.

Azure Active Directory azuread role-assignment privilege-escalation persistence
2r 3t
high advisory

Azure AD Password Spraying Attack Detection

A single source IP failing to authenticate with multiple valid users in Azure AD, potentially indicating a Password Spraying attack, is detected using Azure SignInLogs and the 3-sigma rule to identify anomalous failed login patterns.

Azure Active Directory azuread password-spraying cloud
2r 3t
medium advisory

User Added to Group with Conditional Access Policy Modification Access

An attacker adds a user to a privileged Azure Active Directory group with permissions to modify Conditional Access policies, potentially leading to privilege escalation, credential access, persistence, and defense impairment.

Azure Active Directory attack.privilege-escalation attack.credential-access attack.persistence attack.defense-impairment attack.t1548 attack.t1556
3r 4t
high advisory

Azure AD Account Concurrent Sessions from Different IPs

Detection of Azure AD accounts with concurrent sessions originating from multiple unique IP addresses within a 5-minute window, potentially indicating session hijacking and unauthorized access.

Azure Active Directory azure azuread compromised-account
2r 1t
high advisory

Detect Application AppID URI Configuration Changes in Azure

Detection of configuration changes to an application's AppID URI in Azure, potentially indicating malicious activity related to initial access, persistence, credential access, privilege escalation, or stealth.

Azure Active Directory azure appid uri application serviceprincipal credential-access privilege-escalation
2r 2t
high advisory

Azure AD Temporary Access Pass Added to Account

Detection of a temporary access pass (TAP) being added to an Azure AD account, which could indicate potential privilege escalation, initial access, persistence, or stealth activity.

Azure Active Directory azuread temporary-access-pass privilege-escalation initial-access persistence
2r 4t
medium advisory

Azure AD Authentication to Important Apps Using Single-Factor Authentication

Detection of successful Azure AD authentications to critical applications that only required single-factor authentication, potentially indicating a security lapse or policy violation leading to unauthorized access.

Azure Active Directory attack.privilege-escalation attack.persistence attack.initial-access attack.stealth attack.t1078
2r 3t
critical advisory

Detection of ConvertTo-AADIntBackdoor Execution via PowerShell

This brief outlines the detection of the ConvertTo-AADIntBackdoor command execution via PowerShell Script Block Logging, a technique used to create a backdoor in federated Azure AD domains by modifying federation settings and allowing attackers to control the authentication process.

Azure Active Directory azure-ad backdoor powershell persistence privilege-escalation
2r 4t
medium advisory

Azure AD User Password Reset Detection

Detects when a user successfully resets their own password in Azure Active Directory, which may indicate malicious activity or account compromise.

Azure Active Directory azure password-reset privilege-escalation initial-access persistence credential-access stealth
2r 1t
medium advisory

Azure AD Guest to Member User Type Conversion

An adversary may convert a guest user account to a member account in Azure Active Directory to elevate privileges and gain persistent access to resources.

Azure Active Directory privilege-escalation azure entra guest-account
2r 1t
high advisory

Detection of Privileged Identity Management (PIM) Settings Modifications

Detects unauthorized or malicious modifications to Privileged Identity Management (PIM) settings within Azure environments, potentially leading to privilege escalation, persistence, and stealthy access by attackers.

Azure Active Directory azure pim privilege-escalation persistence
2r 4t
medium advisory

Azure AD Successful Authentication Increase

This detection identifies a statistically significant (10% or greater) increase in successful sign-ins to Azure Active Directory, potentially indicating credential compromise or account takeover attempts.

Azure Active Directory attack.privilege-escalation attack.persistence attack.initial-access attack.stealth attack.t1078
2r 1t
medium advisory

Azure AD Hybrid Health AD FS Service Deletion for Defense Evasion

Threat actors may delete Azure AD Hybrid Health AD FS service instances after using them to spoof AD FS signing logs for defense evasion.

Azure Active Directory attack.defense-impairment attack.t1578.003 azure
2r 1t
high advisory

Azure Application URI Configuration Modification

Detection of Azure application URI modifications that can be indicative of malicious activity, such as using dangling URIs, non-HTTPS URIs, wildcard domains, or URIs pointing to uncontrolled domains, potentially leading to initial access, stealth, persistence, credential access, and privilege escalation.

Azure Active Directory cloud azure application uri modification persistence credential-access privilege-escalation
3r 4t
medium advisory

User Removed from Group with Conditional Access Policy Modification Access

An attacker removes a user from a privileged Azure Active Directory group with permissions to modify Conditional Access policies, potentially leading to privilege escalation, persistence, or defense evasion.

Azure Active Directory azure conditional-access privilege-escalation
2r 3t
medium advisory

Unauthorized Conditional Access Policy Creation in Azure AD

An unauthorized actor created a new Conditional Access policy in Azure AD, potentially leading to privilege escalation and unauthorized access.

Azure Active Directory azure conditional-access privilege-escalation attack.privilege-escalation attack.t1548
2r 1t
high advisory

Suspicious Azure PowerShell Module Installation via PowerShell Script

Detection of Azure AD and cloud management modules installation via PowerShell Script Block Logging, potentially indicating reconnaissance, privilege escalation, or persistence operations by adversaries.

Azure Active Directory +4 azure powershell module-installation privilege-escalation persistence
2r 5t
high threat

O365 Service Principal Creation Detection

Detection of new service principal creation in O365 tenants, which can be abused by attackers for unauthorized access, API interaction, and data compromise.

Office 365 +5 NOBELIUM Group cloud o365 service_principal persistence azuread
2r 1t
high advisory

O365 Risk-Based Consent Disabled

The disabling of the 'risk-based step-up consent' security setting in Microsoft 365 allows users to grant consent to potentially malicious applications, increasing the risk of OAuth phishing and unauthorized access to sensitive data.

Microsoft 365 +1 o365 azuread oauth consent-phishing defense-evasion
2r 1t
critical threat

O365 ApplicationImpersonation Role Assigned

Detection of the ApplicationImpersonation role being assigned in Office 365, potentially leading to unauthorized mailbox access and impersonation.

Microsoft 365 +1 NOBELIUM Group cloud o365 applicationimpersonation persistence
2r 2t
medium threat

O365 Application Registration Owner Added

A new owner added to an O365 application registration can grant significant control, potentially leading to unauthorized data access, privilege escalation, or malicious behavior.

Azure Active Directory +1 NOBELIUM Group azuread o365 persistence
3r 1t
high advisory

O365 Application Available To Other Tenants

An Azure Active Directory Application is configured to allow authentication from external tenants or personal accounts, potentially leading to unauthorized access to data or capabilities.

Azure Active Directory +1 azuread o365 multitenant
2r 1t
medium advisory

O365 Advanced Audit Disabled

The O365 Advanced Audit feature provides critical logging and insights into user and administrator activities, and this analytic detects instances where it is disabled for a specific user, potentially blinding security teams to malicious actions.

Microsoft 365 +1 o365 audit defense-evasion persistence
2r 1t
high advisory

O365 Add App Role Assignment Grant User

This analytic detects the addition of an application role assignment grant to a user in Office 365, which can indicate unauthorized privilege escalation or the assignment of sensitive roles, leading to unauthorized access within the Office 365 environment.

Office 365 +1 office365 azuread privilege-escalation
2r 1t
medium advisory

Microsoft 365 Risk-Based Step-Up Consent Disabled

The Microsoft 365 'risk-based step-up consent' security setting is disabled by an adversary to allow users to grant consent to malicious applications, potentially leading to unauthorized access and data breaches.

Splunk Enterprise +4 azuread o365 oauth risk-based consent defense-evasion
2r 1t
medium advisory

M365 Identity OAuth Illicit Consent Grant by Rare Client and User

Adversaries may register a malicious application in Microsoft Entra ID and trick users into granting excessive permissions via OAuth consent, allowing the malicious application to access resources in Microsoft 365 on behalf of the user, potentially leading to data exfiltration.

Microsoft 365 +2 o365 oauth consent-grant phishing initial-access
2r 3t
high advisory

High Number of Failed Office 365 Logins from Single Source

The analytic detects multiple failed login attempts in Office365 Azure Active Directory from a single source IP address, potentially indicating brute-force or password spraying attacks.

Office 365 +1 cloud office365 credential-access password-spraying
1r 1t
high advisory

Detection of Privileged Azure AD Role Assignment

Detection of privileged Azure AD role assignments to users, which can indicate persistence and privilege escalation by threat actors.

Azure Active Directory +2 azuread privilege-escalation persistence cloud
2r 2t
critical advisory

Azure AD User ImmutableId Attribute Modification for Persistence

Attackers modify the ImmutableID attribute of an Azure AD user to establish a federation backdoor, bypassing MFA and enabling persistent access.

Azure Active Directory azuread persistence federation immutabilid
2r 1t
medium advisory

Azure AD User Consent Blocked for Risky Application

Azure AD blocked a user's attempt to grant consent to a risky application, indicating potential OAuth abuse and requiring investigation of the user and application involved.

Azure Active Directory azuread oauth consent-phishing cloud
2r 1t
medium advisory

Azure AD User Added to Administrator Role

An adversary adds a user to an Azure Active Directory administrative role to gain initial access, persist in the environment, escalate privileges, and potentially operate stealthily.

Azure Active Directory attack.initial-access attack.persistence attack.privilege-escalation attack.stealth attack.t1098.003 attack.t1078
2r 4t
medium advisory

Azure AD Successful Single-Factor Authentication

Successful single-factor authentication events against Azure Active Directory are identified using Azure SignInLogs data, which may indicate misconfiguration, policy violation, or potential account takeover leading to data breaches and privilege escalation.

Azure Active Directory azuread single-factor authentication account takeover
2r 2t
high advisory

Azure AD Service Principal Credential Addition

Detection of new credentials added to Azure AD Service Principals and Applications via monitoring of the 'Update application*Certificates and secrets management' operation, potentially indicating persistence or privilege escalation attempts.

Azure Active Directory azuread persistence privilege-escalation cloud
2r 2t
high advisory

Azure AD Service Principal Authentication Monitoring

This analytic identifies authentication events of service principals in Azure Active Directory, monitoring sign-in frequency, timing, source IPs, and accessed resources to detect potential anomalies indicative of compromised credentials or malicious activities.

Azure Active Directory azure azuread serviceprincipal accounttakeover
2r 1t
medium advisory

Azure AD Risk-Based Consent Disabled

The analytic detects when the risk-based step-up consent security setting in Azure AD is disabled by monitoring Azure Active Directory logs for the 'Update authorization policy' operation and changes to the 'AllowUserConsentForRiskyApps' setting, potentially exposing organizations to OAuth phishing attacks.

Azure Active Directory azure oauth consent phishing
2r 1t
high advisory

Azure AD Privileged Authentication Administrator Role Assignment Detected

An adversary assigning the 'Privileged Authentication Administrator' role to an account in Azure AD could abuse the new privileges to reset authentication methods for privileged accounts, leading to account takeover and privilege escalation.

Azure Active Directory azure azuread privilege-escalation role-assignment
2r 2t
high advisory

Azure AD PIM Role Assignment Detected

Detection of an Azure AD Privileged Identity Management (PIM) role assignment, specifically identifying when a user is added as an eligible member, which could lead to unauthorized access and privilege escalation.

Azure Active Directory azure pim role assignment privilege escalation
2r 2t
high advisory

Azure AD PIM Role Activation Detection

Detection of Azure AD Privileged Identity Management (PIM) role activation, indicating potential privilege escalation or unauthorized access.

Azure Active Directory +1 azure pim privilege-escalation persistence
2r 2t
high advisory

Azure AD Multiple Denied MFA Requests Indicating Potential Account Compromise

Detection of an unusually high number of denied MFA requests for a single user within a short timeframe in Azure AD, potentially indicating a targeted account compromise attempt.

Azure Active Directory azuread mfa account-compromise credential-access
2r 2t
high advisory

Azure AD Multiple AppIDs and UserAgents Authentication Spike

Detects anomalous Azure AD authentication activity characterized by a single user exceeding 8 authentication attempts, utilizing 3+ unique application IDs and 5+ unique user agents within a 5-minute window, potentially indicating MFA probing or account compromise.

Azure Active Directory azuread account-takeover mfa-bypass credential-access
2r 2t
high advisory

Azure AD MFA Fatigue Attack

An attacker attempts to bypass multi-factor authentication by flooding a user with MFA requests, potentially leading to account compromise.

Azure Active Directory mfa azuread credential-access
2r 2t
medium advisory

Azure AD MFA Disabled to Bypass Authentication

An adversary may disable multi-factor authentication (MFA) in Azure Active Directory to weaken an organization's security posture and bypass authentication mechanisms, potentially gaining unauthorized access to sensitive resources and maintaining persistence.

Azure Active Directory azure mfa credential-access persistence defense-impairment
2r 1t
high advisory

Azure AD High-Risk Sign-in Detection

Detection of high-risk Azure Active Directory sign-in attempts, identified by Azure Identity Protection, indicating potentially compromised accounts and unauthorized access to sensitive resources.

Azure Active Directory azuread account-takeover cloud
2r 3t
high advisory

Azure AD Federated Domain Added

This analytic detects the addition of a new federated domain within an Azure Active Directory tenant, potentially indicating the establishment of an Azure AD identity federation backdoor for persistence and unauthorized access.

Azure Active Directory azuread persistence cloud
2r 1t
high advisory

Azure AD Device Code Phishing Attack Detection

This brief details the detection of Azure AD Device Code Phishing attacks, where attackers bypass MFA and Conditional Access Policies (CAPs) to gain unauthorized access to Azure AD resources by abusing the device code authentication protocol.

Azure Active Directory +2 azuread devicecode phishing accounttakeover credentialaccess
2r 2t
high advisory

Azure AD Custom Domain Addition for Persistence

Detection of a new custom domain addition in Azure AD audit logs, potentially indicating an attacker establishing persistence via identity federation backdoors for unauthorized access and privilege escalation.

Azure Active Directory +1 azuread persistence cloud
2r 1t
high advisory

Azure AD Brute Force Attack Detected

An IP address with 20 or more failed authentication attempts to an Azure AD tenant within 10 minutes, indicative of a brute force attack targeting user accounts in Azure Active Directory.

Azure Active Directory azure brute-force credential-access
2r 2t
high advisory

Azure AD Authentication Failed During MFA Challenge

Detection of failed authentication attempts against an Azure AD tenant during the MFA challenge, specifically flagged by error code 500121, leveraging Azure AD SignInLogs, which may indicate an adversary attempting to authenticate using compromised credentials on an account with MFA enabled, potentially leading to unauthorized access.

Azure Active Directory azuread mfa credential-access
3r 3t
high advisory

Azure AD Application Administrator Role Assigned to User

An adversary may assign the Azure AD Application Administrator role to a user account for privilege escalation and application credential management, potentially leading to sensitive resource access and tenant compromise.

Azure Active Directory azuread privilege-escalation role-assignment
2r 1t
high advisory

Azure AD Admin Consent Bypassed by Service Principal

A service principal in Azure Active Directory is assigning app roles without standard admin consent, potentially leading to unauthorized privilege escalation by exploiting automation to assign sensitive permissions without proper oversight.

Azure Active Directory +1 azuread admin-consent service-principal privilege-escalation
2r 1t
high advisory

Azure AD Account Enabled and Password Reset for Backdoor

Detection of an Azure AD user enabling a disabled account and immediately resetting the password, indicating a potential backdoor being established by an adversary with administrative access.

Azure Active Directory azuread persistence backdoor
2r 1t
high advisory

Azure AD PowerShell Authentication Abuse

Adversaries may compromise accounts and leverage successful PowerShell authentication in Azure AD to enumerate cloud resources, escalate privileges, and further exploit the Azure environment.

Azure Active Directory +1 azuread powershell authentication cloud
2r 2t
critical advisory

Azure AD Global Administrator Role Assigned

Detection of Azure AD Global Administrator role assignment to a user, potentially leading to privilege escalation and control over Azure resources.

Azure Active Directory azuread privilege-escalation persistence
2r 2t
medium threat

Azure AD External Guest User Invitation

Detection of an external guest user invitation in Azure AD through monitoring Azure AD AuditLogs, which, if malicious, can lead to unauthorized access, data breaches, or further exploitation by abusing external identities.

exploited Azure Active Directory azuread cloud persistence
2r 1t
high advisory

Azure AD Account Authentication from Multiple IPs

An Azure AD account successfully authenticating from multiple unique IP addresses within a 30-minute window, detected using Azure AD SignInLogs, which may indicate compromised credentials and unauthorized access to corporate resources.

Azure Active Directory azure credential-access compromised-account
1r 3t
high advisory

Azure Identity Protection Atypical Travel Anomaly

The Atypical Travel detection in Azure Identity Protection identifies potentially compromised user accounts by detecting geographically improbable sign-in activity, indicative of account compromise or misuse.

Azure Active Directory +1 azure identity-protection atypical-travel account-compromise credential-theft
2r 1t
high advisory

Azure AD Privileged Role Assignment

Detection of a user being added to a privileged role in Azure AD, potentially indicating privilege escalation or persistence by an attacker.

Azure Active Directory azure privileged-access role-assignment
2r 2t
high advisory

Azure AD Account Created and Deleted Within a Close Time Frame

Detection of Azure Active Directory accounts that are created and deleted within a short timeframe, potentially indicating malicious activity such as privilege escalation or persistence attempts.

Azure Active Directory privilege-escalation persistence initial-access stealth account-manipulation
2r 3t
medium advisory

Azure AD Failed Authentication Increase

Detects a significant increase (10% or greater) in failed Azure AD sign-in attempts, potentially indicating brute-force attacks, credential stuffing, or other unauthorized access attempts.

Azure Active Directory azuread brute-force credential-stuffing authentication
2r 1t
high advisory

O365 Cross-Tenant Access Policy Changes

Adversaries modify Azure Active Directory cross-tenant access policies for lateral movement or persistence within compromised Microsoft 365 environments.

Azure Active Directory +1 azuread office365 cross-tenant persistence
2r 2t
high advisory

Impossible Travel Detection in Azure AD

This brief describes the detection of 'impossible travel' events in Azure AD, where a user appears to log in from geographically distant locations within an implausibly short time frame, potentially indicating account compromise.

Azure Active Directory azuread identity-protection impossible-travel account-compromise lateral-movement
2r 1t
medium advisory

Entra ID High Risk User Sign-in Detection

This rule identifies high-risk Azure Active Directory (AD) sign-ins by leveraging Microsoft Identity Protection machine learning and heuristics, specifically focusing on events with a risk state of `confirmedCompromised` or `atRisk`, indicating potential initial access attempts.

Azure Active Directory azure initial-access cloud
2r 1t
high advisory

Azure PIM - Role Assignment Outside of Privileged Identity Management

Detection of privilege role assignments outside of Azure Privileged Identity Management (PIM) can indicate potential attacker activity related to initial access, stealth, persistence, or privilege escalation within the Azure environment.

Azure Active Directory azure pim role-assignment attack.initial-access attack.stealth attack.t1078 attack.persistence attack.privilege-escalation
2r 4t
medium advisory

Azure Domain Federation Settings Modified

An attacker may modify Azure domain federation settings to establish persistence, escalate privileges, or gain unauthorized access to resources.

Azure Active Directory azure federation privilege-escalation persistence initial-access
2r 2t
high threat

Azure AD Service Principal Owner Added

Detection of a new owner being added to an Azure AD Service Principal, potentially indicating persistence or privilege escalation by an attacker exploiting the lack of multi-factor authentication on service principals.

Azure Active Directory NOBELIUM Group azure cloud persistence privilege-escalation
2r 1t
high advisory

Azure AD Brute Force Attack Detected via High Failed Authentication Count

Detection of a potential brute-force attack against an Azure AD account, identified by a high number of failed authentication attempts within a short time frame, potentially leading to unauthorized access and data breaches.

Azure Active Directory azuread brute-force credential-access cloud
2r 1t
high advisory

Azure AD Multi-Factor Authentication Disabled

Detection of attempts to disable multi-factor authentication (MFA) for an Azure AD user by identifying the 'Disable Strong Authentication' operation in Azure Active Directory AuditLogs, which allows adversaries to maintain persistence.

Azure Active Directory azure mfa persistence credential-access
2r 2t