Tag
high
advisory
Azure AD Device Registration Policy Changes Detected
2 rules 1 TTPMonitoring changes to the device registration policy can detect potential privilege escalation or defense impairment attempts by malicious actors aiming to weaken security controls related to device management in Azure Active Directory.
Azure Active Directory
azure
device-registration
policy-change
2r
1t
medium
advisory
Cisco Duo Policy Change to Allow Devices Without Screen Lock
2 rules 1 TTPA Splunk detection analytic identifies when a Duo policy is created or updated to allow devices without a screen lock, potentially weakening device security controls and increasing the risk of unauthorized access and data breaches.
Duo
cisco-duo
screen-lock
policy-change
2r
1t