Skip to content
Threat Feed

Tag

Azuread

48 briefs RSS
high advisory

Azure AD User ImmutableId Attribute Modification for Persistence

The following analytic identifies modifications to the SourceAnchor (ImmutableId) attribute for an Azure Active Directory user, which is a step in setting up an Azure AD identity federation backdoor that allows an attacker to impersonate any user and bypass MFA.

Splunk Enterprise +3 azuread persistence identityfederation backdoor cloud
2r 1t
high threat

Fleet Windows MDM Azure AD JWT Authentication Bypass Vulnerability

A vulnerability in Fleet versions prior to 4.82.0 allows authentication tokens from any Azure AD tenant to be accepted, enabling unauthorized device enrollment and MDM API access due to improper JWT signature validation, tracked as CVE-2026-24899.

fleetdm/fleet/v4 +1 jwt azuread authentication bypass mdm fleetdm
2r 2t 1i
high advisory

O365 Admin Consent Bypassed by Service Principal

A service principal in Office 365 Azure Active Directory assigns app roles without standard admin consent, potentially bypassing critical administrative controls and leading to unauthorized access or privilege escalation.

Office 365 +1 azuread office365 serviceprincipal adminconsent persistence
2r 2t
medium advisory

Azure AD Authentication from Unexpected Geo-locations

Detection of successful authentications originating from geographic locations outside of an organization's expected operational footprint, potentially indicating compromised credentials or unauthorized access.

Azure Active Directory azuread authentication geo-location unauthorized-access credential-compromise privilege-escalation
2r 1t
critical threat

Azure AD Privileged Graph API Permission Assignment

Detection of high-risk Graph API permission assignments (Application.ReadWrite.All, AppRoleAssignment.ReadWrite.All, and RoleManagement.ReadWrite.Directory) in Azure AD, potentially leading to unauthorized modifications and security breaches.

Azure Active Directory NOBELIUM Group azuread cloud graphapi privilegeescalation persistence
2r 1t
high threat

Azure AD FullAccessAsApp Permission Assignment

Detection of 'full_access_as_app' permission assignment to an application in Office 365 Exchange Online, potentially leading to unauthorized access and data exfiltration.

Office 365 Exchange Online +1 NOBELIUM Group azure azuread office365 persistence nobelium
2r 2t
high advisory

Azure AD Threat Intelligence Detection

This brief focuses on detecting unusual user activity and sign-in patterns flagged by Azure AD Threat Intelligence, which may indicate stealthy attacks, persistence attempts, privilege escalation, or initial access.

Azure Active Directory azuread threat-intelligence risk-detection
2r 1t
high advisory

Entra ID Service Principal Federated Issuer Modification

Entra ID (Azure AD) service principal federated issuers can be modified by an attacker to establish persistence within a target environment.

Entra ID azuread persistence federated_identity
2r 1t
medium advisory

BloodHound Suite User-Agent Detected in Entra ID Sign-ins

Detection of BloodHound tools like AzureHound and SharpHound being used to enumerate Microsoft Entra ID and Microsoft 365 environments, potentially indicating reconnaissance activity by red teams or malicious actors.

Microsoft Azure +2 azuread bloodhound enumeration discovery
3r 6t
high advisory

Azure AD Activity From Anonymous IP Address

Detection of user activity originating from an IP address identified as an anonymous proxy, potentially indicating unauthorized access, privilege escalation, or persistence within an Azure Active Directory environment.

Azure Active Directory azuread anonymous-proxy identity-protection
2r 4t
medium advisory

Azure AD Service Principal Enumeration via Microsoft Graph API

An attacker uses Microsoft Graph API to enumerate multiple Azure AD service principals, potentially using tools like AzureHound or ROADtools, to gather information for privilege escalation or lateral movement.

Azure Active Directory +1 azuread serviceprincipal enumeration
2r 2t
medium advisory

AzureHound Reconnaissance Activity in Azure AD

Detection of the AzureHound User-Agent in Azure AD logs indicates potential reconnaissance activity by adversaries mapping the Azure AD infrastructure for vulnerabilities.

Azure Active Directory +1 azuread reconnaissance azurehound
2r 2t
high advisory

Azure AD User Added to Global or Device Admin Role

An attacker may attempt to add a user to a high-privilege Azure AD role, such as Global Administrator or Device Administrator, to establish persistence, gain initial access, escalate privileges, or operate stealthily within the compromised environment.

Azure Active Directory azuread role-assignment privilege-escalation persistence
2r 3t
high advisory

Azure AD Password Spraying Attack Detection

A single source IP failing to authenticate with multiple valid users in Azure AD, potentially indicating a Password Spraying attack, is detected using Azure SignInLogs and the 3-sigma rule to identify anomalous failed login patterns.

Azure Active Directory azuread password-spraying cloud
2r 3t
high advisory

Azure AD Account Concurrent Sessions from Different IPs

Detection of Azure AD accounts with concurrent sessions originating from multiple unique IP addresses within a 5-minute window, potentially indicating session hijacking and unauthorized access.

Azure Active Directory azure azuread compromised-account
2r 1t
high advisory

Azure AD Temporary Access Pass Added to Account

Detection of a temporary access pass (TAP) being added to an Azure AD account, which could indicate potential privilege escalation, initial access, persistence, or stealth activity.

Azure Active Directory azuread temporary-access-pass privilege-escalation initial-access persistence
2r 4t
high threat

O365 Service Principal Creation Detection

Detection of new service principal creation in O365 tenants, which can be abused by attackers for unauthorized access, API interaction, and data compromise.

Office 365 +5 NOBELIUM Group cloud o365 service_principal persistence azuread
2r 1t
high advisory

O365 Risk-Based Consent Disabled

The disabling of the 'risk-based step-up consent' security setting in Microsoft 365 allows users to grant consent to potentially malicious applications, increasing the risk of OAuth phishing and unauthorized access to sensitive data.

Microsoft 365 +1 o365 azuread oauth consent-phishing defense-evasion
2r 1t
medium threat

O365 Application Registration Owner Added

A new owner added to an O365 application registration can grant significant control, potentially leading to unauthorized data access, privilege escalation, or malicious behavior.

Azure Active Directory +1 NOBELIUM Group azuread o365 persistence
3r 1t
high advisory

O365 Application Available To Other Tenants

An Azure Active Directory Application is configured to allow authentication from external tenants or personal accounts, potentially leading to unauthorized access to data or capabilities.

Azure Active Directory +1 azuread o365 multitenant
2r 1t
high advisory

O365 Add App Role Assignment Grant User

This analytic detects the addition of an application role assignment grant to a user in Office 365, which can indicate unauthorized privilege escalation or the assignment of sensitive roles, leading to unauthorized access within the Office 365 environment.

Office 365 +1 office365 azuread privilege-escalation
2r 1t
medium advisory

Microsoft 365 Risk-Based Step-Up Consent Disabled

The Microsoft 365 'risk-based step-up consent' security setting is disabled by an adversary to allow users to grant consent to malicious applications, potentially leading to unauthorized access and data breaches.

Splunk Enterprise +4 azuread o365 oauth risk-based consent defense-evasion
2r 1t
high advisory

Detection of Privileged Azure AD Role Assignment

Detection of privileged Azure AD role assignments to users, which can indicate persistence and privilege escalation by threat actors.

Azure Active Directory +2 azuread privilege-escalation persistence cloud
2r 2t
critical advisory

Azure AD User ImmutableId Attribute Modification for Persistence

Attackers modify the ImmutableID attribute of an Azure AD user to establish a federation backdoor, bypassing MFA and enabling persistent access.

Azure Active Directory azuread persistence federation immutabilid
2r 1t
medium advisory

Azure AD User Consent Blocked for Risky Application

Azure AD blocked a user's attempt to grant consent to a risky application, indicating potential OAuth abuse and requiring investigation of the user and application involved.

Azure Active Directory azuread oauth consent-phishing cloud
2r 1t
medium advisory

Azure AD Successful Single-Factor Authentication

Successful single-factor authentication events against Azure Active Directory are identified using Azure SignInLogs data, which may indicate misconfiguration, policy violation, or potential account takeover leading to data breaches and privilege escalation.

Azure Active Directory azuread single-factor authentication account takeover
2r 2t
high advisory

Azure AD Service Principal Credential Addition

Detection of new credentials added to Azure AD Service Principals and Applications via monitoring of the 'Update application*Certificates and secrets management' operation, potentially indicating persistence or privilege escalation attempts.

Azure Active Directory azuread persistence privilege-escalation cloud
2r 2t
high advisory

Azure AD Service Principal Authentication Monitoring

This analytic identifies authentication events of service principals in Azure Active Directory, monitoring sign-in frequency, timing, source IPs, and accessed resources to detect potential anomalies indicative of compromised credentials or malicious activities.

Azure Active Directory azure azuread serviceprincipal accounttakeover
2r 1t
high advisory

Azure AD Privileged Authentication Administrator Role Assignment Detected

An adversary assigning the 'Privileged Authentication Administrator' role to an account in Azure AD could abuse the new privileges to reset authentication methods for privileged accounts, leading to account takeover and privilege escalation.

Azure Active Directory azure azuread privilege-escalation role-assignment
2r 2t
high advisory

Azure AD Multiple Denied MFA Requests Indicating Potential Account Compromise

Detection of an unusually high number of denied MFA requests for a single user within a short timeframe in Azure AD, potentially indicating a targeted account compromise attempt.

Azure Active Directory azuread mfa account-compromise credential-access
2r 2t
high advisory

Azure AD Multiple AppIDs and UserAgents Authentication Spike

Detects anomalous Azure AD authentication activity characterized by a single user exceeding 8 authentication attempts, utilizing 3+ unique application IDs and 5+ unique user agents within a 5-minute window, potentially indicating MFA probing or account compromise.

Azure Active Directory azuread account-takeover mfa-bypass credential-access
2r 2t
high advisory

Azure AD MFA Fatigue Attack

An attacker attempts to bypass multi-factor authentication by flooding a user with MFA requests, potentially leading to account compromise.

Azure Active Directory mfa azuread credential-access
2r 2t
high advisory

Azure AD High-Risk Sign-in Detection

Detection of high-risk Azure Active Directory sign-in attempts, identified by Azure Identity Protection, indicating potentially compromised accounts and unauthorized access to sensitive resources.

Azure Active Directory azuread account-takeover cloud
2r 3t
high advisory

Azure AD Federated Domain Added

This analytic detects the addition of a new federated domain within an Azure Active Directory tenant, potentially indicating the establishment of an Azure AD identity federation backdoor for persistence and unauthorized access.

Azure Active Directory azuread persistence cloud
2r 1t
high advisory

Azure AD Device Code Phishing Attack Detection

This brief details the detection of Azure AD Device Code Phishing attacks, where attackers bypass MFA and Conditional Access Policies (CAPs) to gain unauthorized access to Azure AD resources by abusing the device code authentication protocol.

Azure Active Directory +2 azuread devicecode phishing accounttakeover credentialaccess
2r 2t
high advisory

Azure AD Custom Domain Addition for Persistence

Detection of a new custom domain addition in Azure AD audit logs, potentially indicating an attacker establishing persistence via identity federation backdoors for unauthorized access and privilege escalation.

Azure Active Directory +1 azuread persistence cloud
2r 1t
high advisory

Azure AD Authentication Failed During MFA Challenge

Detection of failed authentication attempts against an Azure AD tenant during the MFA challenge, specifically flagged by error code 500121, leveraging Azure AD SignInLogs, which may indicate an adversary attempting to authenticate using compromised credentials on an account with MFA enabled, potentially leading to unauthorized access.

Azure Active Directory azuread mfa credential-access
3r 3t
high advisory

Azure AD Application Administrator Role Assigned to User

An adversary may assign the Azure AD Application Administrator role to a user account for privilege escalation and application credential management, potentially leading to sensitive resource access and tenant compromise.

Azure Active Directory azuread privilege-escalation role-assignment
2r 1t
high advisory

Azure AD Admin Consent Bypassed by Service Principal

A service principal in Azure Active Directory is assigning app roles without standard admin consent, potentially leading to unauthorized privilege escalation by exploiting automation to assign sensitive permissions without proper oversight.

Azure Active Directory +1 azuread admin-consent service-principal privilege-escalation
2r 1t
high advisory

Azure AD Account Enabled and Password Reset for Backdoor

Detection of an Azure AD user enabling a disabled account and immediately resetting the password, indicating a potential backdoor being established by an adversary with administrative access.

Azure Active Directory azuread persistence backdoor
2r 1t
high advisory

Azure AD PowerShell Authentication Abuse

Adversaries may compromise accounts and leverage successful PowerShell authentication in Azure AD to enumerate cloud resources, escalate privileges, and further exploit the Azure environment.

Azure Active Directory +1 azuread powershell authentication cloud
2r 2t
critical advisory

Azure AD Global Administrator Role Assigned

Detection of Azure AD Global Administrator role assignment to a user, potentially leading to privilege escalation and control over Azure resources.

Azure Active Directory azuread privilege-escalation persistence
2r 2t
medium threat

Azure AD External Guest User Invitation

Detection of an external guest user invitation in Azure AD through monitoring Azure AD AuditLogs, which, if malicious, can lead to unauthorized access, data breaches, or further exploitation by abusing external identities.

exploited Azure Active Directory azuread cloud persistence
2r 1t
medium advisory

Azure AD Failed Authentication Increase

Detects a significant increase (10% or greater) in failed Azure AD sign-in attempts, potentially indicating brute-force attacks, credential stuffing, or other unauthorized access attempts.

Azure Active Directory azuread brute-force credential-stuffing authentication
2r 1t
medium advisory

Unauthorized Guest User Invitations in Azure AD

Detection of unauthorized guest user invitations within an Azure Active Directory tenant, indicating potential privilege escalation, persistence, or initial access attempts.

azure azuread guest-user privilege-escalation persistence initial-access
2r 3t
high advisory

O365 Cross-Tenant Access Policy Changes

Adversaries modify Azure Active Directory cross-tenant access policies for lateral movement or persistence within compromised Microsoft 365 environments.

Azure Active Directory +1 azuread office365 cross-tenant persistence
2r 2t
high advisory

Impossible Travel Detection in Azure AD

This brief describes the detection of 'impossible travel' events in Azure AD, where a user appears to log in from geographically distant locations within an implausibly short time frame, potentially indicating account compromise.

Azure Active Directory azuread identity-protection impossible-travel account-compromise lateral-movement
2r 1t
high advisory

Azure AD Brute Force Attack Detected via High Failed Authentication Count

Detection of a potential brute-force attack against an Azure AD account, identified by a high number of failed authentication attempts within a short time frame, potentially leading to unauthorized access and data breaches.

Azure Active Directory azuread brute-force credential-access cloud
2r 1t