Audit Logs / Microsoft Entra ID AuditLogs category
Audit Logs: ApplicationManagement
| OperationName | Description | Sample | Rule |
|---|---|---|---|
| Add app role assignment grant to user | An app role was assigned to a user. | Y | N |
| Add app role assignment to service principal | An application (app-only) role assignment was granted to a service principal. | Y | Y |
| Add application | An application registration was created. | Y | Y |
| Add delegated permission grant | An OAuth2 delegated permission grant was created for an application. | Y | Y |
| Add OAuth2 | An OAuth2 delegated permission grant was created. | N | Y |
| Add owner to application | An owner was added to an application registration. | Y | Y |
| Add owner to service principal | An owner was added to a service principal. | Y | Y |
| Add service principal | A service principal (enterprise application instance) was created. | Y | Y |
| Add service principal credentials | Credentials were added to a service principal (common persistence technique). | Y | Y |
| Consent to application | Admin or user consent was granted to an application (illicit-consent-grant target). | Y | Y |
| Delete application | An application registration was deleted. | Y | Y |
| Hard Delete application | An application registration was permanently deleted (purged from the deleted-items store, not recoverable). | N | Y |
| Remove service principal | A service principal was removed. | Y | Y |
| Remove service principal credentials | Credentials were removed from a service principal. | Y | N |
| Restore application | A soft-deleted application registration was restored. | N | Y |
| Update application | An application registration was modified. | Y | Y |
| Update application – Certificates and secrets management | Credentials (certificate or client secret) were added or changed on an application. | Y | Y |
| Add member to role approval requested (PIM activation) | A PIM activation of an eligible Entra role was requested and is awaiting approver action. | N | N |
| Add member to role in PIM requested (timebound) | A time-bound (expiring) Entra role assignment was requested in PIM. | N | N |
| Add policy to application | A directory policy was assigned (applied) to an application. | N | N |
| Add policy to service principal | Assigns a directory policy (token lifetime, token issuance, claims-mapping, home realm discovery, or app management) to a service principal. | N | N |
| Approve request - direct role assignment | An approver approved a PIM request resulting in a direct Microsoft Entra role assignment; relevant to privilege escalation. | N | N |
| Assign Hardware Oath Token | A hardware OATH token (physical MFA device) was assigned to a user as an authentication method. | N | N |
| Authentication Methods Policy Reset | Reset of the tenant Authentication methods policy (governs available auth/MFA methods); exact reset scope unconfirmed. | N | N |
| Authentication Strength Combination Configuration Create | A combination configuration was created in a custom authentication strength policy (e.g., FIDO2 AAGUID or certificate restrictions). | N | N |
| Authentication Strength Combination Configuration Delete | A combination configuration was deleted from a custom authentication strength policy, relaxing method restrictions. | N | N |
| Authentication Strength Combination Configuration Update | Update to an authentication strength's combination configurations (allowed FIDO2 AAGUIDs or certificate issuer SKIs/policy OIDs). | N | N |
| Authentication Strength Policy Create | A custom Conditional Access authentication strength policy was created. | N | N |
| Authentication Strength Policy Delete | A custom Conditional Access authentication strength policy was deleted. | N | N |
| Authentication Strength Policy Update | A custom Conditional Access authentication strength policy was modified. | N | N |
| Bulk upload Hardware Oath Token | Hardware OATH tokens were bulk-uploaded from a CSV into Microsoft Entra ID. | N | N |
| Cancel application update with safe rollout | A staged ('safe rollout') update to a directory application object was cancelled before completion. | N | N |
| Complete application update after safe rollout | A staged ('safe rollout') update to a directory application object was completed and applied. | N | N |
| Create application collection | An application collection was created on the My Apps portal to group enterprise apps into a named tab for assigned users. | N | N |
| Create Certificate | A certificate was created within Global Secure Access (exact object unconfirmed; e.g. the TLS-inspection intermediate CA). | N | N |
| Create Hardware Oath Token | A hardware OATH TOTP token was created in the tenant as an MFA method. | N | N |
| Delete application collection | A My Apps application collection (curated app grouping/tab) was deleted. | N | N |
| Delete Certificate | A Global Secure Access TLS inspection certificate was deleted. | N | N |
| Delete Hardware Oath Token | Deletion of a hardware OATH (TOTP) token authentication method, removing one of a user's MFA methods. | N | N |
| Hard delete service principal | Permanent, non-recoverable removal of a service principal object from the tenant. | N | N |
| MFA Service Policy Update | An update to the tenant's multifactor authentication (MFA) service policy/settings. | N | N |
| PATCH User | A user's authentication sign-in preferences (e.g., system-preferred MFA) were updated. | N | N |
| PATCH User | A user's QR code authentication-method PIN was reset (new temporary PIN, force-change at next sign-in). | N | N |
| PATCH User | The PIN for a user's QR code authentication method was updated/changed. | N | N |
| PIM activation request expired | A PIM role-activation request expired before completion (e.g., approval not granted in time). | N | N |
| PIM policy removed | A PIM policy (role activation/assignment settings) was removed. | N | N |
| POST User | A software OATH (TOTP) token was registered as an MFA method for a user. | N | N |
| Remove app role assignment from service principal | An app role assignment was removed from a service principal, revoking an application's granted app role. | Y | N |
| Remove delegated permission grant | An OAuth2 delegated permission grant was deleted, revoking the delegated API permissions granted to an application. | Y | N |
| Remove member from role in PIM completed (timebound) | PIM completed removal of a member's time-bound (expiring) role assignment. | N | N |
| Remove owner from application | Removal of an owner from an application, changing who can manage the app's configuration and ownership. | Y | Y |
| Remove owner from service principal | An owner was removed from a service principal, revoking their ability to manage the application's configuration and credentials. | Y | Y |
| Remove policy from application | A policy was removed (detached) from an application object, ending that policy's enforcement for the app. | N | N |
| Remove policy from service principal | A policy was removed (detached) from a service principal, ending that policy's enforcement for the app. | N | N |
| Remove request | A pending Privileged Identity Management assignment request was removed (canceled). | N | N |
| Restore consent | A previously removed application consent (OAuth2 permission grant) was restored. | N | N |
| Restore service principal | A soft-deleted service principal (enterprise application) was restored from the directory recycle bin. | N | N |
| Role definition created | A role definition (custom role) was created in Privileged Identity Management. | N | N |
| Set verified publisher | An application was marked with a verified publisher (a verified Microsoft partner was associated with the app). | N | N |
| Unset verified publisher | The verified-publisher (MPN/partner) status was removed from an app registration. | N | N |
| Update application collection | Modification of a My Apps application collection (a grouping of apps shown to users on the portal). | N | N |
| Update application collection order | Records a change to the display order of application collections shown to users in the My Apps portal. | N | N |
| Update application with safe rollout | Records an update to a directory application object applied via a safe (staged) rollout mechanism. | N | N |
| Update Certificate | Update to a certificate in a Microsoft Entra Global Secure Access configuration. | N | N |
| Update external secrets | Credential secrets an application uses to authenticate to an external system were updated. | N | N |
| Update Hardware Oath Token | Change to a hardware OATH token (physical OTP device) used as an Entra MFA method (assign/activate/modify). | N | N |
| Update preview settings | My Apps app-launcher preview settings were updated. | N | N |
| Update service principal | A service principal object was modified (properties, credentials, or tags). | Y | Y |
| Create application – Certificates and secrets management | A certificate or client-secret credential was added to an application via the Certificates & secrets blade (the add counterpart of the Update form on event 12000073). | Y | N |
Add app role assignment grant to user
#Description
An app role was assigned to a user.
Example Audit Log Entry #
{
"AADOperationType": "Assign",
"AADTenantId": "11111111-1111-1111-1111-111111111111",
"ActivityDateTime": "2026-07-24T03:21:18.2659948Z",
"ActivityDisplayName": "Add app role assignment grant to user",
"AdditionalDetails": [
{
"key": "User-Agent",
"value": "python/3.14.5 (Linux-6.1.0-51-amd64-x86_64-with-glibc2.36) AZURECLI/2.88.0 (DEB)"
},
{
"key": "AppId",
"value": "0d810552-12c8-4592-99b8-e4fdc0f04f42"
},
{
"key": "ServicePrincipalProvisioningType",
"value": "Other"
}
],
"Category": "UserManagement",
"CorrelationId": "0bb21419-a44e-47fc-86a8-3f01b732b3b3",
"DurationMs": "0",
"Id": "Directory_0bb21419-a44e-47fc-86a8-3f01b732b3b3_H7NJ3_571412",
"InitiatedBy": {
"user": {
"id": "aaaaaaaa-0000-0000-0000-000000000001",
"displayName": null,
"userPrincipalName": "adminuser@example.onmicrosoft.com",
"ipAddress": "203.0.113.10",
"roles": [],
"agentType": "notAgentic"
}
},
"LoggedByService": "Core Directory",
"OperationName": "Add app role assignment grant to user",
"OperationVersion": "1.0",
"Resource": "Microsoft.aadiam",
"ResourceGroup": "Microsoft.aadiam",
"ResourceId": "/tenants/11111111-1111-1111-1111-111111111111/providers/Microsoft.aadiam",
"Result": "success",
"ResultSignature": "None",
"TargetResources": [
{
"id": "f543a660-eb12-47b5-9af6-2948b5efb45c",
"displayName": "dw-harness-ara-cf516524",
"type": "ServicePrincipal",
"modifiedProperties": [
{
"displayName": "AppRole.Id",
"oldValue": null,
"newValue": "\"4fd7fe7b-8dc6-5774-8691-a09576fcb161\""
},
{
"displayName": "AppRole.Value",
"oldValue": null,
"newValue": "\"dwharness\""
},
{
"displayName": "AppRole.DisplayName",
"oldValue": null,
"newValue": "\"dwharness\""
},
{
"displayName": "AppRoleAssignment.CreatedDateTime",
"oldValue": null,
"newValue": "\"2026-07-24T03:21:18.1619889Z\""
},
{
"displayName": "AppRoleAssignment.LastModifiedDateTime",
"oldValue": null,
"newValue": "\"2026-07-24T03:21:18.1619889Z\""
},
{
"displayName": "User.ObjectID",
"oldValue": null,
"newValue": "\"aaaaaaaa-0000-0000-0000-000000000001\""
},
{
"displayName": "User.UPN",
"oldValue": null,
"newValue": "\"adminuser@example.onmicrosoft.com\""
},
{
"displayName": "User.PUID",
"oldValue": null,
"newValue": "\"1111111111111111\""
},
{
"displayName": "TargetId.ServicePrincipalNames",
"oldValue": null,
"newValue": "\"0d810552-12c8-4592-99b8-e4fdc0f04f42\""
}
],
"administrativeUnits": [],
"agentType": "notAgentic"
},
{
"id": "aaaaaaaa-0000-0000-0000-000000000001",
"displayName": null,
"type": "User",
"userPrincipalName": "adminuser@example.onmicrosoft.com",
"modifiedProperties": [],
"administrativeUnits": [],
"agentType": "notAgentic"
}
]
}
References #
Add app role assignment to service principal
#Description
An application (app-only) role assignment was granted to a service principal.
Example Audit Log Entry #
{
"AADOperationType": "Assign",
"AADTenantId": "11111111-1111-1111-1111-111111111111",
"ActivityDateTime": "2026-07-24T03:21:22.01158Z",
"ActivityDisplayName": "Add app role assignment to service principal",
"AdditionalDetails": [
{
"key": "User-Agent",
"value": "python/3.14.5 (Linux-6.1.0-51-amd64-x86_64-with-glibc2.36) AZURECLI/2.88.0 (DEB)"
},
{
"key": "AppId",
"value": "0d810552-12c8-4592-99b8-e4fdc0f04f42"
},
{
"key": "ServicePrincipalProvisioningType",
"value": "Other"
}
],
"Category": "ApplicationManagement",
"CorrelationId": "295dedae-6aca-49bb-9fb9-4c84d580049f",
"DurationMs": "0",
"Id": "Directory_295dedae-6aca-49bb-9fb9-4c84d580049f_ZY05Q_10597091",
"InitiatedBy": {
"user": {
"id": "aaaaaaaa-0000-0000-0000-000000000001",
"displayName": null,
"userPrincipalName": "adminuser@example.onmicrosoft.com",
"ipAddress": "203.0.113.10",
"roles": [],
"agentType": "notAgentic"
}
},
"LoggedByService": "Core Directory",
"OperationName": "Add app role assignment to service principal",
"OperationVersion": "1.0",
"Resource": "Microsoft.aadiam",
"ResourceGroup": "Microsoft.aadiam",
"ResourceId": "/tenants/11111111-1111-1111-1111-111111111111/providers/Microsoft.aadiam",
"Result": "success",
"ResultSignature": "None",
"TargetResources": [
{
"id": "f543a660-eb12-47b5-9af6-2948b5efb45c",
"displayName": "dw-harness-ara-cf516524",
"type": "ServicePrincipal",
"modifiedProperties": [
{
"displayName": "AppRole.Id",
"oldValue": null,
"newValue": "\"4fd7fe7b-8dc6-5774-8691-a09576fcb161\""
},
{
"displayName": "AppRole.Value",
"oldValue": null,
"newValue": "\"dwharness\""
},
{
"displayName": "AppRole.DisplayName",
"oldValue": null,
"newValue": "\"dwharness\""
},
{
"displayName": "AppRoleAssignment.CreatedDateTime",
"oldValue": null,
"newValue": "\"2026-07-24T03:21:21.8105676Z\""
},
{
"displayName": "AppRoleAssignment.LastModifiedDateTime",
"oldValue": null,
"newValue": "\"2026-07-24T03:21:21.8105676Z\""
},
{
"displayName": "ServicePrincipal.ObjectID",
"oldValue": null,
"newValue": "\"f543a660-eb12-47b5-9af6-2948b5efb45c\""
},
{
"displayName": "ServicePrincipal.DisplayName",
"oldValue": null,
"newValue": "\"dw-harness-ara-cf516524\""
},
{
"displayName": "ServicePrincipal.AppId",
"oldValue": null,
"newValue": "\"0d810552-12c8-4592-99b8-e4fdc0f04f42\""
},
{
"displayName": "ServicePrincipal.Name",
"oldValue": null,
"newValue": "\"0d810552-12c8-4592-99b8-e4fdc0f04f42\""
},
{
"displayName": "TargetId.ServicePrincipalNames",
"oldValue": null,
"newValue": "\"0d810552-12c8-4592-99b8-e4fdc0f04f42\""
}
],
"administrativeUnits": [],
"agentType": "notAgentic"
},
{
"id": "f543a660-eb12-47b5-9af6-2948b5efb45c",
"displayName": "0d810552-12c8-4592-99b8-e4fdc0f04f42",
"type": "ServicePrincipal",
"modifiedProperties": [],
"administrativeUnits": [],
"agentType": "notAgentic"
}
]
}
Common Indicators #
Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.
| Field | Kind | Value | Rules | Vendors |
|---|---|---|---|---|
PermissionGrant (kusto rule field) | contains | rolemanagement.readwrite.directory | 4 rules | kusto |
azure_ad::logged_by_service (kusto rule field) | eq | core directory | 4 rules | kusto |
AADOperationType (kusto rule field) | eq | assign | 2 rules | kusto |
PermissionGrant_TimeGenerated (kusto rule field) | cross_field_compare | RoleAssignment_TimeGenerated | 2 rules | kusto |
RoleAssignment (kusto rule field) | contains | admin | 2 rules | kusto |
app (kusto rule field) | is_not_null | | 2 rules | kusto |
azure_ad::modified_properties_new (kusto rule field) | gt | 0 | 2 rules | kusto |
displayName (kusto rule field) | eq | AppRole.Value | 2 rules | kusto |
displayName (kusto rule field) | eq | serviceprincipal.displayname | 2 rules | kusto |
displayName (kusto rule field) | eq | serviceprincipal.objectid | 2 rules | kusto |
displayName (kusto rule field) | in | Role.DisplayName | 2 rules | kusto |
displayName (kusto rule field) | in | RoleDefinition.DisplayName | 2 rules | kusto |
displayName (kusto rule field) | in | approle.value | 2 rules | kusto |
displayName (kusto rule field) | in | delegatedpermissiongrant.scope | 2 rules | kusto |
displayName (kusto rule field) | is_not_null | | 2 rules | kusto |
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Sigma #
T1528↳ also matches Add delegated permission grant T1098, T1098.003Splunk #
azure_monitor_aad data source, focusing on the "Add app role…T1098, T1098.003T1098, T1098.003Kusto #
T1078, T1078.004T1078, T1078.004, T1098, T1098.003T1078, T1078.004, T1098, T1098.003↳ also matches Add delegated permission grant
References #
Add application
#Description
An application registration was created.
Example Audit Log Entry #
{
"AADOperationType": "Add",
"AADTenantId": "11111111-1111-1111-1111-111111111111",
"ActivityDateTime": "2026-07-24T03:21:14.5140881Z",
"ActivityDisplayName": "Add application",
"AdditionalDetails": [
{
"key": "User-Agent",
"value": "python/3.14.5 (Linux-6.1.0-51-amd64-x86_64-with-glibc2.36) AZURECLI/2.88.0 (DEB)"
},
{
"key": "AppId",
"value": "0d810552-12c8-4592-99b8-e4fdc0f04f42"
}
],
"Category": "ApplicationManagement",
"CorrelationId": "206705f7-3a5d-4fcd-a5e3-3b5bf179ca08",
"DurationMs": "0",
"Id": "Directory_206705f7-3a5d-4fcd-a5e3-3b5bf179ca08_YYEKK_10369133",
"InitiatedBy": {
"user": {
"id": "aaaaaaaa-0000-0000-0000-000000000001",
"displayName": null,
"userPrincipalName": "adminuser@example.onmicrosoft.com",
"ipAddress": "203.0.113.10",
"roles": [],
"agentType": "notAgentic"
}
},
"LoggedByService": "Core Directory",
"OperationName": "Add application",
"OperationVersion": "1.0",
"Resource": "Microsoft.aadiam",
"ResourceGroup": "Microsoft.aadiam",
"ResourceId": "/tenants/11111111-1111-1111-1111-111111111111/providers/Microsoft.aadiam",
"Result": "success",
"ResultSignature": "None",
"TargetResources": [
{
"id": "8f6edab2-5e40-49e7-bc95-5d1f4d278db5",
"displayName": "dw-harness-ara-cf516524",
"type": "Application",
"modifiedProperties": [
{
"displayName": "AppId",
"oldValue": [],
"newValue": [
"0d810552-12c8-4592-99b8-e4fdc0f04f42"
]
},
{
"displayName": "AvailableToOtherTenants",
"oldValue": [],
"newValue": [
false
]
},
{
"displayName": "DisplayName",
"oldValue": [],
"newValue": [
"dw-harness-ara-cf516524"
]
},
{
"displayName": "Entitlement",
"oldValue": [],
"newValue": [
{
"EntitlementEncodingVersion": 2,
"EntitlementId": "4fd7fe7b-8dc6-5774-8691-a09576fcb161",
"IsDisabled": false,
"Origin": 0,
"Name": "dwharness",
"Description": "detection.wiki harness role",
"Definition": null,
"ClaimValue": "dwharness",
"ResourceScopeType": 0,
"IsPrivate": false,
"UserConsentDisplayName": null,
"UserConsentDescription": null,
"DirectAccessGrantTypes": [
20,
29
],
"ImpersonationAccessGrantTypes": [],
"EntitlementCategory": 0,
"DependentMicrosoftGraphPermissions": [],
"IsPreauthzOnlyDirectAccessGrant": false,
"IsPreauthzOnlyImpersonationGrant": false,
"ImpersonationPrivilegeLevel": 0,
"DirectAccessPrivilegeLevel": 0
}
]
},
{
"displayName": "PublisherDomain",
"oldValue": [],
"newValue": [
"example.onmicrosoft.com"
]
},
{
"displayName": "ServicePrincipalLockConfiguration",
"oldValue": [],
"newValue": [
{
"IsEnabled": true,
"AllProperties": true,
"CredentialsWithUsageVerify": null,
"CredentialsWithUsageSign": null,
"IdentifierUris": null,
"TokenEncryptionKeyId": null,
"ServicePrincipalLockExtension": "AQEAAAA="
}
]
},
{
"displayName": "SignInAudience",
"oldValue": [],
"newValue": [
"AzureADMyOrg"
]
},
{
"displayName": "Included Updated Properties",
"oldValue": null,
"newValue": "\"AppId, AvailableToOtherTenants, DisplayName, Entitlement, PublisherDomain, ServicePrincipalLockConfiguration, SignInAudience\""
}
],
"administrativeUnits": [],
"agentType": "notAgentic"
}
]
}
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →YARA-L #
References #
Add delegated permission grant
#Description
An OAuth2 delegated permission grant was created for an application.
Example Audit Log Entry #
{
"AADOperationType": "Assign",
"AADTenantId": "11111111-1111-1111-1111-111111111111",
"ActivityDateTime": "2026-07-24T03:20:30.2084018Z",
"ActivityDisplayName": "Add delegated permission grant",
"AdditionalDetails": [
{
"key": "User-Agent",
"value": "python/3.14.5 (Linux-6.1.0-51-amd64-x86_64-with-glibc2.36) AZURECLI/2.88.0 (DEB)"
},
{
"key": "AppId",
"value": "00000003-0000-0000-c000-000000000000"
},
{
"key": "ServicePrincipalProvisioningType",
"value": "Other"
}
],
"Category": "ApplicationManagement",
"CorrelationId": "c68a17a1-1dc8-457e-b86c-0dabec606a3f",
"DurationMs": "0",
"Id": "Directory_c68a17a1-1dc8-457e-b86c-0dabec606a3f_IXXZ5_10644521",
"InitiatedBy": {
"user": {
"id": "aaaaaaaa-0000-0000-0000-000000000001",
"displayName": null,
"userPrincipalName": "adminuser@example.onmicrosoft.com",
"ipAddress": "203.0.113.10",
"roles": [],
"agentType": "notAgentic"
}
},
"LoggedByService": "Core Directory",
"OperationName": "Add delegated permission grant",
"OperationVersion": "1.0",
"Resource": "Microsoft.aadiam",
"ResourceGroup": "Microsoft.aadiam",
"ResourceId": "/tenants/11111111-1111-1111-1111-111111111111/providers/Microsoft.aadiam",
"Result": "success",
"ResultSignature": "None",
"TargetResources": [
{
"id": "2e5ab30e-ae89-43c2-b130-0022f3d655a7",
"displayName": "Microsoft Graph",
"type": "ServicePrincipal",
"modifiedProperties": [
{
"displayName": "DelegatedPermissionGrant.Scope",
"oldValue": null,
"newValue": "\"User.Read\""
},
{
"displayName": "DelegatedPermissionGrant.ConsentType",
"oldValue": null,
"newValue": "\"Principal\""
},
{
"displayName": "ServicePrincipal.ObjectID",
"oldValue": null,
"newValue": "\"af2cee02-3ad4-4486-85a2-e8eafc78cd6e\""
},
{
"displayName": "ServicePrincipal.DisplayName",
"oldValue": null,
"newValue": null
},
{
"displayName": "ServicePrincipal.AppId",
"oldValue": null,
"newValue": null
},
{
"displayName": "ServicePrincipal.Name",
"oldValue": null,
"newValue": null
},
{
"displayName": "TargetId.ServicePrincipalNames",
"oldValue": null,
"newValue": "\"00000003-0000-0000-c000-000000000000/ags.windows.net;00000003-0000-0000-c000-000000000000;https://canary.graph.microsoft.com;https://graph.microsoft.com;https://ags.windows.net;https://graph.microsoft.us;https://graph.microsoft.com/;https://dod-graph.microsoft.us;https://canary.graph.microsoft.com/;https://graph.microsoft.us/;https://dod-graph.microsoft.us/\""
}
],
"administrativeUnits": [],
"agentType": "notAgentic"
},
{
"id": "af2cee02-3ad4-4486-85a2-e8eafc78cd6e",
"displayName": null,
"type": "ServicePrincipal",
"modifiedProperties": [],
"administrativeUnits": [],
"agentType": "notAgentic"
}
]
}
Common Indicators #
Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.
| Field | Kind | Value | Rules | Vendors |
|---|---|---|---|---|
azure_ad::logged_by_service (kusto rule field) | eq | core directory | 5 rules | kusto |
azure_ad::modified_properties_new (kusto rule field) | contains | addresstype | 3 rules | kusto |
azure_ad::modified_properties_new (kusto rule field) | gt | 0 | 5 rules | kusto |
displayName (kusto rule field) | eq | appaddress | 3 rules | kusto |
displayName (kusto rule field) | eq | consentaction.permissions | 3 rules | kusto |
displayName (kusto rule field) | is_not_null | | 5 rules | kusto |
type (kusto rule field) | eq | serviceprincipal | 5 rules | kusto |
GrantConsentType (kusto rule field) | ne | AllPrincipals | 3 rules | kusto |
ConsentFull (kusto rule field) | contains | files.read | 2 rules | kusto |
ConsentFull (kusto rule field) | contains | files.read.all | 2 rules | kusto |
ConsentFull (kusto rule field) | contains | mail.read | 2 rules | kusto |
ConsentFull (kusto rule field) | contains | mail.send | 2 rules | kusto |
ConsentFull (kusto rule field) | contains | offline_access | 2 rules | kusto |
ConsentFull (kusto rule field) | contains | user.read | 2 rules | kusto |
PermissionGrant (kusto rule field) | contains | rolemanagement.readwrite.directory | 2 rules | kusto |
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Sigma #
T1528T1528↳ also matches Add app role assignment to service principal Kusto #
T1528, T1550↳ also matches Add OAuth2PermissionGrant, Add service principal, Consent to application T1528, T1550↳ also matches Add OAuth2PermissionGrant, Add service principal, Consent to application T1528↳ also matches Add OAuth2PermissionGrant, Add service principal, Consent to application
References #
Add OAuth2PermissionGrant
#Description
An OAuth2 delegated permission grant was created.
Common Indicators #
Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.
| Field | Kind | Value | Rules | Vendors |
|---|---|---|---|---|
GrantConsentType (kusto rule field) | ne | AllPrincipals | 3 rules | kusto |
azure_ad::logged_by_service (kusto rule field) | eq | core directory | 3 rules | kusto |
azure_ad::modified_properties_new (kusto rule field) | contains | addresstype | 3 rules | kusto |
azure_ad::modified_properties_new (kusto rule field) | gt | 0 | 3 rules | kusto |
displayName (kusto rule field) | eq | appaddress | 3 rules | kusto |
displayName (kusto rule field) | eq | consentaction.permissions | 3 rules | kusto |
displayName (kusto rule field) | is_not_null | | 3 rules | kusto |
type (kusto rule field) | eq | serviceprincipal | 3 rules | kusto |
ConsentFull (kusto rule field) | contains | files.read | 2 rules | kusto |
ConsentFull (kusto rule field) | contains | files.read.all | 2 rules | kusto |
ConsentFull (kusto rule field) | contains | mail.read | 2 rules | kusto |
ConsentFull (kusto rule field) | contains | mail.send | 2 rules | kusto |
ConsentFull (kusto rule field) | contains | offline_access | 2 rules | kusto |
ConsentFull (kusto rule field) | contains | user.read | 2 rules | kusto |
azure_ad::target_resources (kusto rule field) | contains | offline | 2 rules | kusto |
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Kusto #
T1528, T1550↳ also matches Add delegated permission grant, Add service principal, Consent to application T1528, T1550↳ also matches Add delegated permission grant, Add service principal, Consent to application T1528↳ also matches Add delegated permission grant, Add service principal, Consent to application
References #
Add owner to application
#Description
An owner was added to an application registration.
Example Audit Log Entry #
{
"AADOperationType": "Assign",
"AADTenantId": "11111111-1111-1111-1111-111111111111",
"ActivityDateTime": "2026-07-24T03:20:08.5025607Z",
"ActivityDisplayName": "Add owner to application",
"AdditionalDetails": [
{
"key": "User-Agent",
"value": "python/3.14.5 (Linux-6.1.0-51-amd64-x86_64-with-glibc2.36) AZURECLI/2.88.0 (DEB)"
}
],
"Category": "ApplicationManagement",
"CorrelationId": "81f6cc99-b0f6-4a94-ac78-043f6ed5e439",
"DurationMs": "0",
"Id": "Directory_81f6cc99-b0f6-4a94-ac78-043f6ed5e439_FROXF_10026633",
"InitiatedBy": {
"user": {
"id": "aaaaaaaa-0000-0000-0000-000000000001",
"displayName": null,
"userPrincipalName": "adminuser@example.onmicrosoft.com",
"ipAddress": "203.0.113.10",
"roles": [],
"agentType": "notAgentic"
}
},
"LoggedByService": "Core Directory",
"OperationName": "Add owner to application",
"OperationVersion": "1.0",
"Resource": "Microsoft.aadiam",
"ResourceGroup": "Microsoft.aadiam",
"ResourceId": "/tenants/11111111-1111-1111-1111-111111111111/providers/Microsoft.aadiam",
"Result": "success",
"ResultSignature": "None",
"TargetResources": [
{
"id": "aaaaaaaa-0000-0000-0000-000000000001",
"displayName": null,
"type": "User",
"userPrincipalName": "adminuser@example.onmicrosoft.com",
"modifiedProperties": [
{
"displayName": "Application.ObjectID",
"oldValue": null,
"newValue": "\"d5dcc899-cc10-4152-93d9-ecaa990c016e\""
},
{
"displayName": "Application.DisplayName",
"oldValue": null,
"newValue": "\"dw-harness-owner-cf516524\""
},
{
"displayName": "Application.AppId",
"oldValue": null,
"newValue": "\"af83d2a0-7c27-4e07-849a-41886ab13674\""
}
],
"administrativeUnits": [],
"agentType": "notAgentic"
},
{
"id": "d5dcc899-cc10-4152-93d9-ecaa990c016e",
"displayName": null,
"type": "Application",
"modifiedProperties": [],
"administrativeUnits": [],
"agentType": "notAgentic"
}
]
}
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Sigma #
T1552Elastic #
T1098, T1528Splunk #
T1098Kusto #
T1078, T1078.004
References #
Add owner to service principal
#Description
An owner was added to a service principal.
Example Audit Log Entry #
{
"AADOperationType": "Assign",
"AADTenantId": "11111111-1111-1111-1111-111111111111",
"ActivityDateTime": "2026-07-24T03:20:11.7100237Z",
"ActivityDisplayName": "Add owner to service principal",
"AdditionalDetails": [
{
"key": "User-Agent",
"value": "python/3.14.5 (Linux-6.1.0-51-amd64-x86_64-with-glibc2.36) AZURECLI/2.88.0 (DEB)"
}
],
"Category": "ApplicationManagement",
"CorrelationId": "0a53d892-9443-4659-8928-0e04bcc4f75d",
"DurationMs": "0",
"Id": "Directory_0a53d892-9443-4659-8928-0e04bcc4f75d_ZY05Q_10589172",
"InitiatedBy": {
"user": {
"id": "aaaaaaaa-0000-0000-0000-000000000001",
"displayName": null,
"userPrincipalName": "adminuser@example.onmicrosoft.com",
"ipAddress": "203.0.113.10",
"roles": [],
"agentType": "notAgentic"
}
},
"LoggedByService": "Core Directory",
"OperationName": "Add owner to service principal",
"OperationVersion": "1.0",
"Resource": "Microsoft.aadiam",
"ResourceGroup": "Microsoft.aadiam",
"ResourceId": "/tenants/11111111-1111-1111-1111-111111111111/providers/Microsoft.aadiam",
"Result": "success",
"ResultSignature": "None",
"TargetResources": [
{
"id": "aaaaaaaa-0000-0000-0000-000000000001",
"displayName": null,
"type": "User",
"userPrincipalName": "adminuser@example.onmicrosoft.com",
"modifiedProperties": [
{
"displayName": "ServicePrincipal.ObjectID",
"oldValue": null,
"newValue": "\"11c4b230-304b-422e-b8fb-a2b507982bd6\""
},
{
"displayName": "ServicePrincipal.DisplayName",
"oldValue": null,
"newValue": "\"dw-harness-owner-cf516524\""
},
{
"displayName": "ServicePrincipal.AppId",
"oldValue": null,
"newValue": "\"af83d2a0-7c27-4e07-849a-41886ab13674\""
},
{
"displayName": "ServicePrincipal.Name",
"oldValue": null,
"newValue": "\"af83d2a0-7c27-4e07-849a-41886ab13674\""
}
],
"administrativeUnits": [],
"agentType": "notAgentic"
},
{
"id": "11c4b230-304b-422e-b8fb-a2b507982bd6",
"displayName": "af83d2a0-7c27-4e07-849a-41886ab13674",
"type": "ServicePrincipal",
"modifiedProperties": [],
"administrativeUnits": [],
"agentType": "notAgentic"
}
]
}
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Elastic #
T1078, T1078.004, T1098
References #
Add service principal
#Description
A service principal (enterprise application instance) was created.
Example Audit Log Entry #
{
"AADOperationType": "Add",
"AADTenantId": "11111111-1111-1111-1111-111111111111",
"ActivityDateTime": "2026-07-24T03:21:15.7048858Z",
"ActivityDisplayName": "Add service principal",
"AdditionalDetails": [
{
"key": "User-Agent",
"value": "python/3.14.5 (Linux-6.1.0-51-amd64-x86_64-with-glibc2.36) AZURECLI/2.88.0 (DEB)"
},
{
"key": "AppId",
"value": "0d810552-12c8-4592-99b8-e4fdc0f04f42"
},
{
"key": "AppOwnerOrganizationId",
"value": "11111111-1111-1111-1111-111111111111"
},
{
"key": "ServicePrincipalProvisioningType",
"value": "Other"
}
],
"Category": "ApplicationManagement",
"CorrelationId": "29b3975e-a3b7-4fcb-9e4a-b7b42a68af39",
"DurationMs": "0",
"Id": "Directory_29b3975e-a3b7-4fcb-9e4a-b7b42a68af39_LCVO1_10003939",
"InitiatedBy": {
"user": {
"id": "aaaaaaaa-0000-0000-0000-000000000001",
"displayName": null,
"userPrincipalName": "adminuser@example.onmicrosoft.com",
"ipAddress": "203.0.113.10",
"roles": [],
"agentType": "notAgentic"
}
},
"LoggedByService": "Core Directory",
"OperationName": "Add service principal",
"OperationVersion": "1.0",
"Resource": "Microsoft.aadiam",
"ResourceGroup": "Microsoft.aadiam",
"ResourceId": "/tenants/11111111-1111-1111-1111-111111111111/providers/Microsoft.aadiam",
"Result": "success",
"ResultSignature": "None",
"TargetResources": [
{
"id": "f543a660-eb12-47b5-9af6-2948b5efb45c",
"displayName": "dw-harness-ara-cf516524",
"type": "ServicePrincipal",
"modifiedProperties": [
{
"displayName": "AccountEnabled",
"oldValue": [],
"newValue": [
true
]
},
{
"displayName": "AppPrincipalId",
"oldValue": [],
"newValue": [
"0d810552-12c8-4592-99b8-e4fdc0f04f42"
]
},
{
"displayName": "DisplayName",
"oldValue": [],
"newValue": [
"dw-harness-ara-cf516524"
]
},
{
"displayName": "ServicePrincipalName",
"oldValue": [],
"newValue": [
"0d810552-12c8-4592-99b8-e4fdc0f04f42"
]
},
{
"displayName": "Credential",
"oldValue": [],
"newValue": [
{
"CredentialType": 2,
"KeyStoreId": "291154f0-a9f5-45bb-87be-9c8ee5b6d62c",
"KeyGroupId": "291154f0-a9f5-45bb-87be-9c8ee5b6d62c"
}
]
},
{
"displayName": "Included Updated Properties",
"oldValue": null,
"newValue": "\"AccountEnabled, AppPrincipalId, DisplayName, ServicePrincipalName, Credential\""
}
],
"administrativeUnits": [],
"agentType": "notAgentic"
}
]
}
Common Indicators #
Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.
| Field | Kind | Value | Rules | Vendors |
|---|---|---|---|---|
GrantConsentType (kusto rule field) | ne | AllPrincipals | 3 rules | kusto |
azure_ad::logged_by_service (kusto rule field) | eq | core directory | 3 rules | kusto |
azure_ad::modified_properties_new (kusto rule field) | contains | addresstype | 3 rules | kusto |
azure_ad::modified_properties_new (kusto rule field) | gt | 0 | 3 rules | kusto |
displayName (kusto rule field) | eq | appaddress | 3 rules | kusto |
displayName (kusto rule field) | eq | consentaction.permissions | 3 rules | kusto |
displayName (kusto rule field) | is_not_null | | 3 rules | kusto |
type (kusto rule field) | eq | serviceprincipal | 3 rules | kusto |
ConsentFull (kusto rule field) | contains | files.read | 2 rules | kusto |
ConsentFull (kusto rule field) | contains | files.read.all | 2 rules | kusto |
ConsentFull (kusto rule field) | contains | mail.read | 2 rules | kusto |
ConsentFull (kusto rule field) | contains | mail.send | 2 rules | kusto |
ConsentFull (kusto rule field) | contains | offline_access | 2 rules | kusto |
ConsentFull (kusto rule field) | contains | user.read | 2 rules | kusto |
azure_ad::target_resources (kusto rule field) | contains | offline | 2 rules | kusto |
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Sigma #
Elastic #
T1136, T1136.003Splunk #
T1136, T1136.003T1136, T1136.003T1136, T1136.003Kusto #
T1528, T1550↳ also matches Add delegated permission grant, Add OAuth2PermissionGrant, Consent to application T1528, T1550↳ also matches Add delegated permission grant, Add OAuth2PermissionGrant, Consent to application T1528↳ also matches Add delegated permission grant, Add OAuth2PermissionGrant, Consent to application
References #
Add service principal credentials
#Description
Credentials were added to a service principal (common persistence technique).
Example Audit Log Entry #
{
"AADOperationType": "Update",
"AADTenantId": "11111111-1111-1111-1111-111111111111",
"ActivityDateTime": "2026-07-24T03:20:02.9311374Z",
"ActivityDisplayName": "Add service principal credentials",
"AdditionalDetails": [
{
"key": "User-Agent",
"value": "python/3.14.5 (Linux-6.1.0-51-amd64-x86_64-with-glibc2.36) AZURECLI/2.88.0 (DEB)"
},
{
"key": "AppId",
"value": "0880df21-e1b6-42e5-b399-8840779d78c4"
},
{
"key": "AppOwnerOrganizationId",
"value": "11111111-1111-1111-1111-111111111111"
},
{
"key": "ServicePrincipalProvisioningType",
"value": "Other"
}
],
"Category": "ApplicationManagement",
"CorrelationId": "feb89f71-6257-416b-afb4-fe5bf7a11b78",
"DurationMs": "0",
"Id": "Directory_feb89f71-6257-416b-afb4-fe5bf7a11b78_4OTNI_10119999",
"InitiatedBy": {
"user": {
"id": "aaaaaaaa-0000-0000-0000-000000000001",
"displayName": null,
"userPrincipalName": "adminuser@example.onmicrosoft.com",
"ipAddress": "203.0.113.10",
"roles": [],
"agentType": "notAgentic"
}
},
"LoggedByService": "Core Directory",
"OperationName": "Add service principal credentials",
"OperationVersion": "1.0",
"Resource": "Microsoft.aadiam",
"ResourceGroup": "Microsoft.aadiam",
"ResourceId": "/tenants/11111111-1111-1111-1111-111111111111/providers/Microsoft.aadiam",
"Result": "success",
"ResultSignature": "None",
"TargetResources": [
{
"id": "e637b633-f84a-4e3a-9e92-1dda38b7daa0",
"displayName": "dw-harness-credential-cf516524",
"type": "ServicePrincipal",
"modifiedProperties": [
{
"displayName": "KeyDescription",
"oldValue": [],
"newValue": [
"[KeyIdentifier=384afc65-9185-49a9-b690-8d4a75bd5609,KeyType=Password,KeyUsage=Verify,DisplayName=dw-harness]"
]
},
{
"displayName": "Included Updated Properties",
"oldValue": null,
"newValue": "\"KeyDescription\""
}
],
"administrativeUnits": [],
"agentType": "notAgentic"
}
]
}
Common Indicators #
Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.
| Field | Kind | Value | Rules | Vendors |
|---|---|---|---|---|
displayName (kusto rule field) | eq | consentaction.permissions | 1 rule | kusto |
displayName (kusto rule field) | eq | consentcontext.isadminconsent | 1 rule | kusto |
displayName (kusto rule field) | eq | included updated properties | 1 rule | kusto |
displayName (kusto rule field) | eq | keydescription | 1 rule | kusto |
displayName (kusto rule field) | eq | targetid.serviceprincipalnames | 1 rule | kusto |
type (kusto rule field) | eq | serviceprincipal | 1 rule | kusto |
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Elastic #
T1098, T1098.001Kusto #
T1098, T1555↳ also matches Consent to application
References #
Consent to application
#Description
Admin or user consent was granted to an application (illicit-consent-grant target).
Example Audit Log Entry #
{
"AADOperationType": "Assign",
"AADTenantId": "11111111-1111-1111-1111-111111111111",
"ActivityDateTime": "2026-07-02T16:09:30.7133364Z",
"ActivityDisplayName": "Consent to application",
"AdditionalDetails": [
{
"key": "AppId",
"value": "22222222-2222-2222-2222-222222222222"
},
{
"key": "ServicePrincipalProvisioningType",
"value": "Other"
}
],
"Category": "ApplicationManagement",
"CorrelationId": "80e78fc4-d3fb-4bae-b3a6-230bb1ea44d6",
"DurationMs": "0",
"Id": "Directory_80e78fc4-d3fb-4bae-b3a6-230bb1ea44d6_0LDA1_52763192",
"InitiatedBy": {
"user": {
"displayName": null,
"agentType": "notAgentic",
"id": "aaaaaaaa-0000-0000-0000-000000000001",
"userPrincipalName": "adminuser@example.onmicrosoft.com",
"ipAddress": "203.0.113.10",
"roles": []
}
},
"LoggedByService": "Core Directory",
"OperationName": "Consent to application",
"OperationVersion": "1.0",
"Resource": "Microsoft.aadiam",
"ResourceGroup": "Microsoft.aadiam",
"ResourceId": "/tenants/11111111-1111-1111-1111-111111111111/providers/Microsoft.aadiam",
"Result": "success",
"ResultSignature": "None",
"TargetResources": [
{
"id": "af2cee02-3ad4-4486-85a2-e8eafc78cd6e",
"displayName": "dw-activity-gen",
"type": "ServicePrincipal",
"modifiedProperties": [
{
"displayName": "ConsentContext.IsAdminConsent",
"oldValue": null,
"newValue": "\"True\""
},
{
"displayName": "ConsentContext.IsAppOnly",
"oldValue": null,
"newValue": "\"False\""
},
{
"displayName": "ConsentContext.OnBehalfOfAll",
"oldValue": null,
"newValue": "\"True\""
},
{
"displayName": "ConsentContext.Tags",
"oldValue": null,
"newValue": "\"WindowsAzureActiveDirectoryIntegratedApp\""
},
{
"displayName": "ConsentAction.Permissions",
"oldValue": null,
"newValue": "\"[[Id: Au4sr9Q6hkSFoujq_HjNbg6zWi6JrsJDsTAAIvPWVac, ClientId: af2cee02-3ad4-4486-85a2-e8eafc78cd6e, PrincipalId: , ResourceId: 2e5ab30e-ae89-43c2-b130-0022f3d655a7, ConsentType: AllPrincipals, Scope: Files.ReadWrite Mail.ReadWrite Sites.ReadWrite.All Mail.Send Calendars.ReadWrite Contacts.ReadWrite Team.Create Channel.Create Channel.Delete.All ChannelMessage.Send ChannelMember.ReadWrite.All TeamMember.ReadWrite.All Tasks.ReadWrite Group.ReadWrite.All TeamSettings.ReadWrite.All User.Read AuditLogsQuery.Read.All, CreatedDateTime: , LastModifiedDateTime ]] => [[Id: Au4sr9Q6hkSFoujq_HjNbg6zWi6JrsJDsTAAIvPWVac, ClientId: af2cee02-3ad4-4486-85a2-e8eafc78cd6e, PrincipalId: , ResourceId: 2e5ab30e-ae89-43c2-b130-0022f3d655a7, ConsentType: AllPrincipals, Scope: Files.ReadWrite Mail.ReadWrite Sites.ReadWrite.All Mail.Send Calendars.ReadWrite Contacts.ReadWrite Team.Create Channel.Create Channel.Delete.All ChannelMessage.Send ChannelMember.ReadWrite.All TeamMember.ReadWrite.All Tasks.ReadWrite Group.ReadWrite.All TeamSettings.ReadWrite.All User.Read AuditLogsQuery.Read.All, CreatedDateTime: , LastModifiedDateTime ]]; \""
}
],
"administrativeUnits": [],
"agentType": "notAgentic"
}
]
}
Common Indicators #
Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.
| Field | Kind | Value | Rules | Vendors |
|---|---|---|---|---|
displayName (kusto rule field) | eq | consentaction.permissions | 5 rules | kusto |
displayName (kusto rule field) | eq | appaddress | 3 rules | kusto |
displayName (kusto rule field) | is_not_null | | 3 rules | kusto |
azure_ad::logged_by_service (kusto rule field) | eq | core directory | 4 rules | kusto |
type (kusto rule field) | eq | serviceprincipal | 4 rules | kusto |
GrantConsentType (kusto rule field) | ne | AllPrincipals | 3 rules | kusto |
azure_ad::modified_properties_new (kusto rule field) | contains | addresstype | 3 rules | kusto |
azure_ad::modified_properties_new (kusto rule field) | gt | 0 | 3 rules | kusto |
key (kusto rule field) | eq | user-agent | 3 rules | kusto |
ConsentFull (kusto rule field) | contains | files.read | 2 rules | kusto |
ConsentFull (kusto rule field) | contains | files.read.all | 2 rules | kusto |
ConsentFull (kusto rule field) | contains | mail.read | 2 rules | kusto |
ConsentFull (kusto rule field) | contains | mail.send | 2 rules | kusto |
ConsentFull (kusto rule field) | contains | offline_access | 2 rules | kusto |
ConsentFull (kusto rule field) | contains | user.read | 2 rules | kusto |
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Elastic #
T1199, T1528, T1566, T1566.002Splunk #
T1528T1098, T1098.003T1528Kusto #
T1550, T1550.001T1098, T1555↳ also matches Add service principal credentials T1528, T1550↳ also matches Add delegated permission grant, Add OAuth2PermissionGrant, Add service principal
References #
Delete application
#Description
An application registration was deleted.
Example Audit Log Entry #
{
"AADOperationType": "Delete",
"AADTenantId": "11111111-1111-1111-1111-111111111111",
"ActivityDateTime": "2026-07-24T03:21:26.0289117Z",
"ActivityDisplayName": "Delete application",
"AdditionalDetails": [
{
"key": "User-Agent",
"value": "python/3.14.5 (Linux-6.1.0-51-amd64-x86_64-with-glibc2.36) AZURECLI/2.88.0 (DEB)"
},
{
"key": "AppId",
"value": "0d810552-12c8-4592-99b8-e4fdc0f04f42"
}
],
"Category": "ApplicationManagement",
"CorrelationId": "7c7a7ae6-bc89-4dd8-9da1-a0445ee147de",
"DurationMs": "0",
"Id": "Directory_7c7a7ae6-bc89-4dd8-9da1-a0445ee147de_0KIMT_10479137",
"InitiatedBy": {
"user": {
"id": "aaaaaaaa-0000-0000-0000-000000000001",
"displayName": null,
"userPrincipalName": "adminuser@example.onmicrosoft.com",
"ipAddress": "203.0.113.10",
"roles": [],
"agentType": "notAgentic"
}
},
"LoggedByService": "Core Directory",
"OperationName": "Delete application",
"OperationVersion": "1.0",
"Resource": "Microsoft.aadiam",
"ResourceGroup": "Microsoft.aadiam",
"ResourceId": "/tenants/11111111-1111-1111-1111-111111111111/providers/Microsoft.aadiam",
"Result": "success",
"ResultSignature": "None",
"TargetResources": [
{
"id": "8f6edab2-5e40-49e7-bc95-5d1f4d278db5",
"displayName": "dw-harness-ara-cf516524",
"type": "Application",
"modifiedProperties": [],
"administrativeUnits": [],
"agentType": "notAgentic"
}
]
}
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Sigma #
T1489↳ also matches Hard Delete application, Delete administrative unit YARA-L #
References #
Hard Delete application
#Description
An application registration was permanently deleted (purged from the deleted-items store, not recoverable).
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Sigma #
T1489↳ also matches Delete application, Delete administrative unit YARA-L #
References #
Remove service principal
#Description
A service principal was removed.
Example Audit Log Entry #
{
"AADOperationType": "Delete",
"AADTenantId": "11111111-1111-1111-1111-111111111111",
"ActivityDateTime": "2026-07-24T03:21:25.1551267Z",
"ActivityDisplayName": "Remove service principal",
"AdditionalDetails": [
{
"key": "User-Agent",
"value": "python/3.14.5 (Linux-6.1.0-51-amd64-x86_64-with-glibc2.36) AZURECLI/2.88.0 (DEB)"
},
{
"key": "AppId",
"value": "0d810552-12c8-4592-99b8-e4fdc0f04f42"
},
{
"key": "AppOwnerOrganizationId",
"value": "11111111-1111-1111-1111-111111111111"
},
{
"key": "ServicePrincipalProvisioningType",
"value": "Other"
}
],
"Category": "ApplicationManagement",
"CorrelationId": "e26b3bd2-a159-46d2-a187-afd1ebd1b642",
"DurationMs": "0",
"Id": "Directory_e26b3bd2-a159-46d2-a187-afd1ebd1b642_H7NJ3_572113",
"InitiatedBy": {
"user": {
"id": "aaaaaaaa-0000-0000-0000-000000000001",
"displayName": null,
"userPrincipalName": "adminuser@example.onmicrosoft.com",
"ipAddress": "203.0.113.10",
"roles": [],
"agentType": "notAgentic"
}
},
"LoggedByService": "Core Directory",
"OperationName": "Remove service principal",
"OperationVersion": "1.0",
"Resource": "Microsoft.aadiam",
"ResourceGroup": "Microsoft.aadiam",
"ResourceId": "/tenants/11111111-1111-1111-1111-111111111111/providers/Microsoft.aadiam",
"Result": "success",
"ResultSignature": "None",
"TargetResources": [
{
"id": "f543a660-eb12-47b5-9af6-2948b5efb45c",
"displayName": "dw-harness-ara-cf516524",
"type": "ServicePrincipal",
"modifiedProperties": [],
"administrativeUnits": [],
"agentType": "notAgentic"
}
]
}
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Sigma #
Kusto #
T1078, T1528↳ also matches Add app role assignment to service principal, Add service principal
References #
Remove service principal credentials
#Description
Credentials were removed from a service principal.
Example Audit Log Entry #
{
"AADOperationType": "Update",
"AADTenantId": "11111111-1111-1111-1111-111111111111",
"ActivityDateTime": "2026-07-24T03:20:03.90873Z",
"ActivityDisplayName": "Remove service principal credentials",
"AdditionalDetails": [
{
"key": "User-Agent",
"value": "python/3.14.5 (Linux-6.1.0-51-amd64-x86_64-with-glibc2.36) AZURECLI/2.88.0 (DEB)"
},
{
"key": "AppId",
"value": "0880df21-e1b6-42e5-b399-8840779d78c4"
},
{
"key": "AppOwnerOrganizationId",
"value": "11111111-1111-1111-1111-111111111111"
},
{
"key": "ServicePrincipalProvisioningType",
"value": "Other"
}
],
"Category": "ApplicationManagement",
"CorrelationId": "479c6b41-32ab-4a83-b02e-2193b98b3452",
"DurationMs": "0",
"Id": "Directory_479c6b41-32ab-4a83-b02e-2193b98b3452_BOAS4_10216774",
"InitiatedBy": {
"user": {
"id": "aaaaaaaa-0000-0000-0000-000000000001",
"displayName": null,
"userPrincipalName": "adminuser@example.onmicrosoft.com",
"ipAddress": "203.0.113.10",
"roles": [],
"agentType": "notAgentic"
}
},
"LoggedByService": "Core Directory",
"OperationName": "Remove service principal credentials",
"OperationVersion": "1.0",
"Resource": "Microsoft.aadiam",
"ResourceGroup": "Microsoft.aadiam",
"ResourceId": "/tenants/11111111-1111-1111-1111-111111111111/providers/Microsoft.aadiam",
"Result": "success",
"ResultSignature": "None",
"TargetResources": [
{
"id": "e637b633-f84a-4e3a-9e92-1dda38b7daa0",
"displayName": "dw-harness-credential-cf516524",
"type": "ServicePrincipal",
"modifiedProperties": [
{
"displayName": "KeyDescription",
"oldValue": [
"[KeyIdentifier=384afc65-9185-49a9-b690-8d4a75bd5609,KeyType=Password,KeyUsage=Verify,DisplayName=dw-harness]"
],
"newValue": []
},
{
"displayName": "Included Updated Properties",
"oldValue": null,
"newValue": "\"KeyDescription\""
}
],
"administrativeUnits": [],
"agentType": "notAgentic"
}
]
}
References #
Restore application
#Description
A soft-deleted application registration was restored.
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →YARA-L #
References #
Update application
#Description
An application registration was modified.
Example Audit Log Entry #
{
"AADOperationType": "Update",
"AADTenantId": "11111111-1111-1111-1111-111111111111",
"ActivityDateTime": "2026-07-24T03:20:17.2567244Z",
"ActivityDisplayName": "Update application",
"AdditionalDetails": [
{
"key": "User-Agent",
"value": "python/3.14.5 (Linux-6.1.0-51-amd64-x86_64-with-glibc2.36) AZURECLI/2.88.0 (DEB)"
},
{
"key": "AppId",
"value": "fa629f38-1390-4d23-a30d-3fcbacadb9d7"
}
],
"Category": "ApplicationManagement",
"CorrelationId": "a4ba2b50-7ea5-4cd1-8e91-3ed4e6bc6d4e",
"DurationMs": "0",
"Id": "Directory_a4ba2b50-7ea5-4cd1-8e91-3ed4e6bc6d4e_48KOK_10607842",
"InitiatedBy": {
"user": {
"id": "aaaaaaaa-0000-0000-0000-000000000001",
"displayName": null,
"userPrincipalName": "adminuser@example.onmicrosoft.com",
"ipAddress": "203.0.113.10",
"roles": [],
"agentType": "notAgentic"
}
},
"LoggedByService": "Core Directory",
"OperationName": "Update application",
"OperationVersion": "1.0",
"Resource": "Microsoft.aadiam",
"ResourceGroup": "Microsoft.aadiam",
"ResourceId": "/tenants/11111111-1111-1111-1111-111111111111/providers/Microsoft.aadiam",
"Result": "success",
"ResultSignature": "None",
"TargetResources": [
{
"id": "640d643e-4dab-40d1-a674-1d9d715eb1e1",
"displayName": "dw-harness-extension-cf516524",
"type": "Application",
"modifiedProperties": [
{
"displayName": "Included Updated Properties",
"oldValue": null,
"newValue": "\"\""
}
],
"administrativeUnits": [],
"agentType": "notAgentic"
}
]
}
Common Indicators #
Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.
| Field | Kind | Value | Rules | Vendors |
|---|---|---|---|---|
AddedUrls (kusto rule field) | gt | 0 | 2 rules | kusto |
Details (kusto rule field) | is_not_null | | 2 rules | kusto |
Key (kusto rule field) | is_not_null | | 2 rules | kusto |
Result (kusto rule field) | eq | success | 2 rules | kusto |
category (splunk rule field) | eq | auditlogs | 2 rules | splunk |
displayName (kusto rule field) | eq | appaddress | 2 rules | kusto |
Domain (kusto rule field) | is_not_null | | 1 rule | kusto |
EntityName (kusto rule field) | eq | systemuser | 1 rule | kusto |
Message (kusto rule field) | eq | Create | 1 rule | kusto |
{}.RequiredAppPermissions{}.EntitlementId (splunk rule field) | eq | 06b708a9-e830-4db3-a914-8e69da51d44f | 1 rule | splunk |
{}.RequiredAppPermissions{}.EntitlementId (splunk rule field) | eq | 9e3f62cf-ca93-4989-b6ce-bf83c28f9fe8 | 1 rule | splunk |
{}.RequiredAppPermissions{}.EntitlementId (splunk rule field) | eq | dc890d15-9560-4a4c-9b7f-a736ec74ec40 | 1 rule | splunk |
{}.ResourceAppId (splunk rule field) | eq | 00000002-0000-0ff1-ce00-000000000000 | 1 rule | splunk |
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Sigma #
T1078, T1078.004, T1552↳ also matches Update service principal Elastic #
T1528, T1556T1098, T1098.001, T1484, T1484.002Splunk #
T1098, T1098.002, T1098.003T1003, T1003.002Kusto #
T1078, T1078.004T1078, T1078.004T0859, T1078, T1098YARA-L #
References #
Update application – Certificates and secrets management
#Description
Credentials (certificate or client secret) were added or changed on an application.
Example Audit Log Entry #
{
"AADOperationType": "Update",
"AADTenantId": "11111111-1111-1111-1111-111111111111",
"ActivityDateTime": "2026-07-24T03:20:00.9665677Z",
"ActivityDisplayName": "Update application – Certificates and secrets management ",
"AdditionalDetails": [
{
"key": "User-Agent",
"value": "python/3.14.5 (Linux-6.1.0-51-amd64-x86_64-with-glibc2.36) AZURECLI/2.88.0 (DEB)"
},
{
"key": "AppId",
"value": "0880df21-e1b6-42e5-b399-8840779d78c4"
}
],
"Category": "ApplicationManagement",
"CorrelationId": "f9015dc5-d0c5-41e6-974e-ae79e56ddebf",
"DurationMs": "0",
"Id": "Directory_f9015dc5-d0c5-41e6-974e-ae79e56ddebf_4Q5OQ_10498338",
"InitiatedBy": {
"user": {
"id": "aaaaaaaa-0000-0000-0000-000000000001",
"displayName": null,
"userPrincipalName": "adminuser@example.onmicrosoft.com",
"ipAddress": "203.0.113.10",
"roles": [],
"agentType": "notAgentic"
}
},
"LoggedByService": "Core Directory",
"OperationName": "Update application – Certificates and secrets management ",
"OperationVersion": "1.0",
"Resource": "Microsoft.aadiam",
"ResourceGroup": "Microsoft.aadiam",
"ResourceId": "/tenants/11111111-1111-1111-1111-111111111111/providers/Microsoft.aadiam",
"Result": "success",
"ResultSignature": "None",
"TargetResources": [
{
"id": "88f127f9-3564-40c4-a3c6-201e448f5d3a",
"displayName": "dw-harness-credential-cf516524",
"type": "Application",
"modifiedProperties": [
{
"displayName": "KeyDescription",
"oldValue": [
"[KeyIdentifier=d0b56347-2d3a-4658-814d-dde322b4a3a3,KeyType=Password,KeyUsage=Verify,DisplayName=dw-harness]"
],
"newValue": []
},
{
"displayName": "Included Updated Properties",
"oldValue": null,
"newValue": "\"KeyDescription\""
}
],
"administrativeUnits": [],
"agentType": "notAgentic"
}
]
}
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Sigma #
T1098, T1098.001Elastic #
T1098, T1098.001
References #
Add member to role approval requested (PIM activation)
#Description
A user requested activation of an eligible Microsoft Entra role through Privileged Identity Management, and because the role's settings require approval, an approval was requested from the designated approvers. Detection relevance: PIM activations are just-in-time privilege elevations and warrant monitoring for privilege escalation.
References #
Add member to role in PIM requested (timebound)
#Description
A request was submitted through Privileged Identity Management to create a time-bound (expiring) Microsoft Entra role assignment.
References #
Add policy to application
#Description
Records the assignment of a directory policy (for example a token lifetime, claims-mapping, or home realm discovery policy) to an application object. Attaching a claims-mapping or home-realm-discovery policy to an application can alter that app's issued token claims or federated authentication behavior.
References #
Add policy to service principal
#Description
Records the assignment of a directory policy object to a service principal. Assignable policies include token lifetime, token issuance, claims-mapping, home realm discovery, and app management policies; changes that extend token lifetimes or alter claims or home-realm behavior can support persistence or token manipulation, making this relevant to service-principal abuse monitoring.
References #
Approve request - direct role assignment
#Description
Records an approver approving a Privileged Identity Management request whose outcome is a direct Microsoft Entra role assignment for the requester. Approval of privileged-role requests is directly relevant to privilege-escalation monitoring.
References #
Assign Hardware Oath Token
#Description
Records the assignment of a hardware OATH token (a physical OATH-TOTP code-generating device) to a user as an authentication method. Adding or changing a user's MFA methods is relevant to account-persistence and takeover monitoring, since an attacker-controlled token could be registered to maintain access.
References #
Authentication Methods Policy Reset
#Description
Records a reset of the tenant Authentication methods policy, which governs which authentication and MFA methods users may register and use. The precise scope of the reset was not confirmed by a retrieved Microsoft Learn doc, so the description is held to the operation name, category, and service.
References #
Authentication Strength Combination Configuration Create
#Description
Records the creation of a combination configuration within a custom authentication strength policy, such as restricting allowed FIDO2 security keys by AAGUID or constraining certificate-based methods by issuer or policy OID. Changes to authentication strength enforcement are relevant to monitoring for weakened or altered MFA requirements.
References #
Authentication Strength Combination Configuration Delete
#Description
Records the deletion of a combination configuration from a custom authentication strength policy, for example removing a FIDO2 AAGUID restriction or a certificate issuer/policy-OID constraint. Removing such restrictions can relax which methods satisfy the policy, which is relevant to defense-evasion monitoring.
References #
Authentication Strength Combination Configuration Update
#Description
Records an update to the combination configurations of a Conditional Access authentication strength: the advanced restrictions that limit which credentials satisfy an allowed method combination, such as permitted FIDO2 passkey AAGUIDs or the certificate issuer SKIs and policy OIDs for certificate-based authentication. Loosening these restrictions can weaken an enforced MFA grant control (defense evasion).
References #
Authentication Strength Policy Create
#Description
Records creation of a custom Conditional Access authentication strength policy: a named, admin-defined set of allowed authentication-method combinations that a Conditional Access grant control can require for access to a resource.
References #
Authentication Strength Policy Delete
#Description
Records deletion of a custom Conditional Access authentication strength policy. A strength still referenced by a Conditional Access policy cannot be deleted; removing one that gated access can weaken authentication requirements (defense evasion).
References #
Authentication Strength Policy Update
#Description
Records a modification to an existing custom Conditional Access authentication strength policy, such as changing its name, description, or the set of allowed authentication-method combinations.
References #
Bulk upload Hardware Oath Token
#Description
Records a bulk upload of hardware OATH tokens from a CSV (containing values such as UPN, serial number, and secret key) into Microsoft Entra ID. Registering attacker-controlled OATH tokens can establish multifactor-authentication persistence or enable account takeover.
References #
Cancel application update with safe rollout
#Description
A staged ("safe rollout") update to an application object in the directory was cancelled before it completed. This activity is part of the Core Directory safe-rollout update sequence, alongside the sibling activities "Update application with safe rollout" and "Complete application update after safe rollout".
References #
Complete application update after safe rollout
#Description
A staged ("safe rollout") update to an application object in the directory was finalized and applied. This activity completes the Core Directory safe-rollout update sequence (begun by "Update application with safe rollout").
References #
Create application collection
#Description
An application collection was created on the My Apps portal, grouping selected enterprise applications into a named tab shown to the assigned users and groups. A collection applies a filter to applications a user can already access, so it organizes the end-user app launcher and does not itself grant access to the underlying apps.
References #
Create Certificate
#Description
A certificate was created within Microsoft Entra Global Secure Access. The specific certificate this operation provisions is not confirmed from documentation; one documented use of certificates in Global Secure Access is the intermediate certificate authority that TLS (Transport Layer Security) inspection uses to issue per-site leaf certificates.
References #
Create Hardware Oath Token
#Description
A hardware OATH TOTP token was created (registered) in the tenant for use as a multifactor authentication method. Registration or change of authentication methods is relevant to monitoring for MFA manipulation and persistence.
References #
Delete application collection
#Description
A My Apps collection was deleted. Collections are admin-curated groupings that organize applications into separate tabs on the My Apps portal, so deleting one removes that grouping without changing users' underlying access to the applications.
References #
Delete Certificate
#Description
Records the deletion of a certificate used by Global Secure Access Transport Layer Security (TLS) inspection. This is the certificate Global Secure Access uses to break and inspect encrypted TLS traffic for Microsoft Entra Internet Access; removing it disables or interrupts TLS inspection and the security controls that depend on it.
References #
Delete Hardware Oath Token
#Description
A hardware OATH token was deleted. Hardware OATH tokens are physical OATH-TOTP devices registered as a Microsoft Entra authentication method (currently in preview), so removing one deletes one of a user's MFA methods, which is relevant to MFA tampering and authentication-method weakening.
References #
Hard delete service principal
#Description
Records the permanent, non-recoverable removal of a service principal object from the tenant, either an administrator purging a soft-deleted service principal or the automatic purge after the 30-day soft-delete window. Hard deletion blocks restoration and erases an application's identity, which can be cleanup of an attacker-created or abused app (defense evasion).
References #
MFA Service Policy Update
#Description
Records an update to the tenant's multifactor authentication service policy/settings, logged by the Authentication Methods service. Changes to MFA policy configuration are security-sensitive because they can strengthen or weaken authentication requirements, with relaxed settings being relevant to defense evasion.
References #
PATCH UserAuthMethod.PatchSignInPreferencesAsync
#Description
Records an update (PATCH) to a user's authentication sign-in preferences in Microsoft Entra ID, such as the per-user system-preferred multifactor authentication setting or preferred secondary authentication method. Changes that disable or weaken a user's preferred MFA can be relevant to authentication-control tampering.
References #
PATCH UserAuthMethod.ResetQRPinAsync
#Description
Records an administrator-initiated reset of the PIN for a user's QR code authentication method, which generates a new temporary PIN that the user must change at next sign-in. QR code with PIN is a frontline-worker sign-in method, so resetting another user's PIN is an account-access change worth monitoring.
References #
PATCH UserAuthMethod.UpdateQRPinAsync
#Description
Records an update to the PIN of a user's QR code authentication method, the updatePin operation that changes the current PIN to a new value (used when a user changes their PIN, including the forced change after a reset). QR code with PIN is a frontline-worker authentication method.
References #
PIM activation request expired
#Description
Records that a Privileged Identity Management role-activation request expired before it was completed, for example because a required approval was not granted within the (fixed 24-hour) approval window. The eligible role was therefore not activated.
References #
PIM policy removed
#Description
Records removal of a Privileged Identity Management policy, the role-settings/assignment policy that governs activation requirements (such as MFA on activation, approval, justification, and maximum activation duration) for a role. Removing or weakening PIM policies reduces safeguards around privileged-role activation and is relevant to privilege escalation and defense evasion.
References #
POST UserAuthMethod.SoftwareOathProofupRegistration
#Description
Records the registration (proof-up) of a software OATH (TOTP) token as a multifactor authentication method for a user. Newly registered MFA methods are a known persistence and account-takeover signal, where an actor enrolls their own authenticator to retain access.
References #
Remove app role assignment from service principal
#Description
An app role assignment was removed from a service principal, revoking an application's granted app role (such as an application permission to another resource or API). Removal of app role grants is relevant to monitoring application-permission and consent changes.
Example Audit Log Entry #
{
"AADOperationType": "Unassign",
"AADTenantId": "11111111-1111-1111-1111-111111111111",
"ActivityDateTime": "2026-07-24T03:21:23.1198548Z",
"ActivityDisplayName": "Remove app role assignment from service principal",
"AdditionalDetails": [
{
"key": "User-Agent",
"value": "python/3.14.5 (Linux-6.1.0-51-amd64-x86_64-with-glibc2.36) AZURECLI/2.88.0 (DEB)"
},
{
"key": "AppId",
"value": "0d810552-12c8-4592-99b8-e4fdc0f04f42"
},
{
"key": "ServicePrincipalProvisioningType",
"value": "Other"
}
],
"Category": "ApplicationManagement",
"CorrelationId": "cedd6f16-52c8-4041-8b57-c621c98aa297",
"DurationMs": "0",
"Id": "Directory_cedd6f16-52c8-4041-8b57-c621c98aa297_0KIMT_10478958",
"InitiatedBy": {
"user": {
"id": "aaaaaaaa-0000-0000-0000-000000000001",
"displayName": null,
"userPrincipalName": "adminuser@example.onmicrosoft.com",
"ipAddress": "203.0.113.10",
"roles": [],
"agentType": "notAgentic"
}
},
"LoggedByService": "Core Directory",
"OperationName": "Remove app role assignment from service principal",
"OperationVersion": "1.0",
"Resource": "Microsoft.aadiam",
"ResourceGroup": "Microsoft.aadiam",
"ResourceId": "/tenants/11111111-1111-1111-1111-111111111111/providers/Microsoft.aadiam",
"Result": "success",
"ResultSignature": "None",
"TargetResources": [
{
"id": "f543a660-eb12-47b5-9af6-2948b5efb45c",
"displayName": "dw-harness-ara-cf516524",
"type": "ServicePrincipal",
"modifiedProperties": [
{
"displayName": "AppRole.Id",
"oldValue": "\"4fd7fe7b-8dc6-5774-8691-a09576fcb161\"",
"newValue": null
},
{
"displayName": "AppRole.Value",
"oldValue": null,
"newValue": null
},
{
"displayName": "AppRole.DisplayName",
"oldValue": null,
"newValue": null
},
{
"displayName": "AppRoleAssignment.CreatedDateTime",
"oldValue": "\"2026-07-24T03:21:21.8105676Z\"",
"newValue": null
},
{
"displayName": "AppRoleAssignment.LastModifiedDateTime",
"oldValue": "\"2026-07-24T03:21:21.8105676Z\"",
"newValue": null
},
{
"displayName": "ServicePrincipal.ObjectID",
"oldValue": "\"f543a660-eb12-47b5-9af6-2948b5efb45c\"",
"newValue": null
},
{
"displayName": "ServicePrincipal.DisplayName",
"oldValue": "\"dw-harness-ara-cf516524\"",
"newValue": null
},
{
"displayName": "ServicePrincipal.AppId",
"oldValue": null,
"newValue": "\"0d810552-12c8-4592-99b8-e4fdc0f04f42\""
},
{
"displayName": "ServicePrincipal.Name",
"oldValue": null,
"newValue": "\"0d810552-12c8-4592-99b8-e4fdc0f04f42\""
},
{
"displayName": "TargetId.ServicePrincipalNames",
"oldValue": null,
"newValue": "\"0d810552-12c8-4592-99b8-e4fdc0f04f42\""
}
],
"administrativeUnits": [],
"agentType": "notAgentic"
},
{
"id": "f543a660-eb12-47b5-9af6-2948b5efb45c",
"displayName": "0d810552-12c8-4592-99b8-e4fdc0f04f42",
"type": "ServicePrincipal",
"modifiedProperties": [],
"administrativeUnits": [],
"agentType": "notAgentic"
}
]
}
References #
Remove delegated permission grant
#Description
An OAuth2 delegated permission grant was deleted, revoking the delegated API permissions it had granted to an application; existing access tokens stay valid until they expire but no new tokens are issued for those scopes. Tracking grant removals supports OAuth consent-grant and application-permission auditing.
Example Audit Log Entry #
{
"AADOperationType": "Unassign",
"AADTenantId": "11111111-1111-1111-1111-111111111111",
"ActivityDateTime": "2026-07-24T03:20:31.0771685Z",
"ActivityDisplayName": "Remove delegated permission grant",
"AdditionalDetails": [
{
"key": "User-Agent",
"value": "python/3.14.5 (Linux-6.1.0-51-amd64-x86_64-with-glibc2.36) AZURECLI/2.88.0 (DEB)"
},
{
"key": "AppId",
"value": "00000003-0000-0000-c000-000000000000"
},
{
"key": "ServicePrincipalProvisioningType",
"value": "Other"
}
],
"Category": "ApplicationManagement",
"CorrelationId": "66b9b854-394f-4097-8771-7d4663a4a169",
"DurationMs": "0",
"Id": "Directory_66b9b854-394f-4097-8771-7d4663a4a169_1PR04_10689729",
"InitiatedBy": {
"user": {
"id": "aaaaaaaa-0000-0000-0000-000000000001",
"displayName": null,
"userPrincipalName": "adminuser@example.onmicrosoft.com",
"ipAddress": "203.0.113.10",
"roles": [],
"agentType": "notAgentic"
}
},
"LoggedByService": "Core Directory",
"OperationName": "Remove delegated permission grant",
"OperationVersion": "1.0",
"Resource": "Microsoft.aadiam",
"ResourceGroup": "Microsoft.aadiam",
"ResourceId": "/tenants/11111111-1111-1111-1111-111111111111/providers/Microsoft.aadiam",
"Result": "success",
"ResultSignature": "None",
"TargetResources": [
{
"id": "2e5ab30e-ae89-43c2-b130-0022f3d655a7",
"displayName": "Microsoft Graph",
"type": "ServicePrincipal",
"modifiedProperties": [
{
"displayName": "DelegatedPermissionGrant.Scope",
"oldValue": "\"User.Read\"",
"newValue": null
},
{
"displayName": "DelegatedPermissionGrant.ConsentType",
"oldValue": "\"Principal\"",
"newValue": null
},
{
"displayName": "ServicePrincipal.ObjectID",
"oldValue": "\"af2cee02-3ad4-4486-85a2-e8eafc78cd6e\"",
"newValue": null
},
{
"displayName": "ServicePrincipal.DisplayName",
"oldValue": null,
"newValue": null
},
{
"displayName": "ServicePrincipal.AppId",
"oldValue": null,
"newValue": null
},
{
"displayName": "ServicePrincipal.Name",
"oldValue": null,
"newValue": null
},
{
"displayName": "TargetId.ServicePrincipalNames",
"oldValue": null,
"newValue": "\"00000003-0000-0000-c000-000000000000/ags.windows.net;00000003-0000-0000-c000-000000000000;https://canary.graph.microsoft.com;https://graph.microsoft.com;https://ags.windows.net;https://graph.microsoft.us;https://graph.microsoft.com/;https://dod-graph.microsoft.us;https://canary.graph.microsoft.com/;https://graph.microsoft.us/;https://dod-graph.microsoft.us/\""
}
],
"administrativeUnits": [],
"agentType": "notAgentic"
},
{
"id": "af2cee02-3ad4-4486-85a2-e8eafc78cd6e",
"displayName": null,
"type": "ServicePrincipal",
"modifiedProperties": [],
"administrativeUnits": [],
"agentType": "notAgentic"
}
]
}
References #
Remove owner from application
#Description
Records removal of an owner from an application in Microsoft Entra ID. An application owner can manage the app's organization-specific configuration (such as single sign-on, provisioning, and user assignment) and can add or remove other owners, so ownership changes affect who controls the application; monitor to avoid ownerless apps and loss of accountability.
Example Audit Log Entry #
{
"AADOperationType": "Unassign",
"AADTenantId": "11111111-1111-1111-1111-111111111111",
"ActivityDateTime": "2026-07-24T03:20:09.3763462Z",
"ActivityDisplayName": "Remove owner from application",
"AdditionalDetails": [
{
"key": "User-Agent",
"value": "python/3.14.5 (Linux-6.1.0-51-amd64-x86_64-with-glibc2.36) AZURECLI/2.88.0 (DEB)"
}
],
"Category": "ApplicationManagement",
"CorrelationId": "2111c558-893f-4cba-b426-959c7f9c95d8",
"DurationMs": "0",
"Id": "Directory_2111c558-893f-4cba-b426-959c7f9c95d8_A2Q6L_10306340",
"InitiatedBy": {
"user": {
"id": "aaaaaaaa-0000-0000-0000-000000000001",
"displayName": null,
"userPrincipalName": "adminuser@example.onmicrosoft.com",
"ipAddress": "203.0.113.10",
"roles": [],
"agentType": "notAgentic"
}
},
"LoggedByService": "Core Directory",
"OperationName": "Remove owner from application",
"OperationVersion": "1.0",
"Resource": "Microsoft.aadiam",
"ResourceGroup": "Microsoft.aadiam",
"ResourceId": "/tenants/11111111-1111-1111-1111-111111111111/providers/Microsoft.aadiam",
"Result": "success",
"ResultSignature": "None",
"TargetResources": [
{
"id": "aaaaaaaa-0000-0000-0000-000000000001",
"displayName": null,
"type": "User",
"userPrincipalName": "adminuser@example.onmicrosoft.com",
"modifiedProperties": [
{
"displayName": "Application.ObjectID",
"oldValue": "\"d5dcc899-cc10-4152-93d9-ecaa990c016e\"",
"newValue": null
},
{
"displayName": "Application.DisplayName",
"oldValue": "\"dw-harness-owner-cf516524\"",
"newValue": null
},
{
"displayName": "Application.AppId",
"oldValue": null,
"newValue": "\"af83d2a0-7c27-4e07-849a-41886ab13674\""
}
],
"administrativeUnits": [],
"agentType": "notAgentic"
},
{
"id": "d5dcc899-cc10-4152-93d9-ecaa990c016e",
"displayName": null,
"type": "Application",
"modifiedProperties": [],
"administrativeUnits": [],
"agentType": "notAgentic"
}
]
}
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Sigma #
References #
Remove owner from service principal
#Description
Records that an owner was removed from a service principal (enterprise application), revoking that principal's ability to manage the application's configuration and credentials. Because service principal owners can add credentials, ownership changes are relevant to application persistence and privilege monitoring.
Example Audit Log Entry #
{
"AADOperationType": "Unassign",
"AADTenantId": "11111111-1111-1111-1111-111111111111",
"ActivityDateTime": "2026-07-24T03:20:12.7447299Z",
"ActivityDisplayName": "Remove owner from service principal",
"AdditionalDetails": [
{
"key": "User-Agent",
"value": "python/3.14.5 (Linux-6.1.0-51-amd64-x86_64-with-glibc2.36) AZURECLI/2.88.0 (DEB)"
}
],
"Category": "ApplicationManagement",
"CorrelationId": "4094afcb-147b-4a94-b658-61a8b89c9b9a",
"DurationMs": "0",
"Id": "Directory_4094afcb-147b-4a94-b658-61a8b89c9b9a_H7NJ3_564939",
"InitiatedBy": {
"user": {
"id": "aaaaaaaa-0000-0000-0000-000000000001",
"displayName": null,
"userPrincipalName": "adminuser@example.onmicrosoft.com",
"ipAddress": "203.0.113.10",
"roles": [],
"agentType": "notAgentic"
}
},
"LoggedByService": "Core Directory",
"OperationName": "Remove owner from service principal",
"OperationVersion": "1.0",
"Resource": "Microsoft.aadiam",
"ResourceGroup": "Microsoft.aadiam",
"ResourceId": "/tenants/11111111-1111-1111-1111-111111111111/providers/Microsoft.aadiam",
"Result": "success",
"ResultSignature": "None",
"TargetResources": [
{
"id": "aaaaaaaa-0000-0000-0000-000000000001",
"displayName": null,
"type": "User",
"userPrincipalName": "adminuser@example.onmicrosoft.com",
"modifiedProperties": [
{
"displayName": "ServicePrincipal.ObjectID",
"oldValue": "\"11c4b230-304b-422e-b8fb-a2b507982bd6\"",
"newValue": null
},
{
"displayName": "ServicePrincipal.DisplayName",
"oldValue": "\"dw-harness-owner-cf516524\"",
"newValue": null
},
{
"displayName": "ServicePrincipal.AppId",
"oldValue": null,
"newValue": "\"af83d2a0-7c27-4e07-849a-41886ab13674\""
},
{
"displayName": "ServicePrincipal.Name",
"oldValue": null,
"newValue": "\"af83d2a0-7c27-4e07-849a-41886ab13674\""
}
],
"administrativeUnits": [],
"agentType": "notAgentic"
},
{
"id": "11c4b230-304b-422e-b8fb-a2b507982bd6",
"displayName": "af83d2a0-7c27-4e07-849a-41886ab13674",
"type": "ServicePrincipal",
"modifiedProperties": [],
"administrativeUnits": [],
"agentType": "notAgentic"
}
]
}
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Sigma #
References #
Remove policy from application
#Description
Records that a policy (such as a token lifetime, claims-mapping, or home-realm-discovery policy) was detached from an application object, removing that policy's enforcement for the application.
References #
Remove policy from service principal
#Description
Records that a policy (such as a token lifetime, claims-mapping, or home-realm-discovery policy) was detached from a service principal, removing that policy's enforcement for the enterprise application.
References #
Remove request
#Description
Records that a pending Privileged Identity Management assignment request was removed (canceled) before completion.
References #
Restore consent
#Description
Records that a previously removed application consent (OAuth2 permission grant) was restored. Restoring a consent re-enables an application's granted delegated or application permissions, which is relevant to illicit-consent and OAuth abuse investigations.
References #
Restore service principal
#Description
A soft-deleted service principal (enterprise application) was restored from the directory recycle bin within the 30-day recovery window, recovering its prior configuration except policies such as Conditional Access. Restoring an application identity can re-establish access or persistence and is relevant to defense-evasion monitoring.
References #
Role definition created
#Description
A role definition (typically a custom role) was created in Privileged Identity Management, defining a role and the permissions it grants. Creating a role definition with elevated permissions is relevant to privilege-escalation and persistence monitoring.
References #
Set verified publisher
#Description
An application registration was marked with a verified publisher, associating a verified Microsoft partner (Partner ID / MPN) with the app. The verified-publisher status lends legitimacy in consent prompts, so unexpected changes are relevant to consent-phishing and app-impersonation monitoring.
References #
Unset verified publisher
#Description
Records that the verified-publisher status (the Microsoft AI Cloud Partner Program, formerly Microsoft Partner Network/MPN, association) was removed from an app registration, clearing its publisher-verified indication. Because verified-publisher status shapes user and admin trust during consent, removing it or its presence on a malicious app is relevant to illicit-consent and app-impersonation analysis.
References #
Update application collection
#Description
Records modification of an application collection on the My Apps portal, a grouping of applications presented to users on a separate tab. A collection filters the apps a user already has access to, so the change affects presentation rather than granting access.
References #
Update application collection order
#Description
Records a change to the display order of application collections shown to users in the Microsoft Entra My Apps portal. Collections group related applications onto separate tabs in that portal; this operation records a change to the order in which the collections are presented.
References #
Update application with safe rollout
#Description
Records an update to an application object in the directory that is applied through a safe (staged) rollout mechanism. The audit name does not by itself identify which application properties changed.
References #
Update Certificate
#Description
Records an update to a certificate associated with a Microsoft Entra Global Secure Access configuration. Global Secure Access writes configuration changes to the Entra audit logs, so this entry supports monitoring of certificate changes within a Global Secure Access deployment. The specific certificate object is not named in current Global Secure Access documentation.
References #
Update external secrets
#Description
The external secrets tied to an application or service principal were updated. These are credential secrets an application uses to authenticate to an external system (for example, the synchronization secrets configured for Microsoft Entra application provisioning), so the event can indicate routine credential rotation or, if unexpected, a path to persistence or data access through a connected system.
References #
Update Hardware Oath Token
#Description
Records a change to a hardware OATH token (a physical device that generates time-based one-time passcodes) used as a Microsoft Entra MFA method, such as assigning, activating, or modifying the token for a user under the Authentication methods policy. Tampering with a user's registered authentication methods can indicate MFA manipulation for account persistence.
References #
Update preview settings
#Description
My Apps portal preview settings were updated, opting the tenant in or out of preview features for the app-launcher end-user experience.
References #
Update service principal
#Description
A service principal (the tenant-local representation of an application) was modified, such as a change to its properties, credentials, or tags. Adding credentials to a service principal is a recognized persistence and privilege-escalation technique, so these changes warrant review.
Example Audit Log Entry #
{
"AADOperationType": "Update",
"AADTenantId": "11111111-1111-1111-1111-111111111111",
"ActivityDateTime": "2026-07-24T03:20:12.6857283Z",
"ActivityDisplayName": "Update service principal",
"AdditionalDetails": [
{
"key": "User-Agent",
"value": "python/3.14.5 (Linux-6.1.0-51-amd64-x86_64-with-glibc2.36) AZURECLI/2.88.0 (DEB)"
},
{
"key": "AppId",
"value": "af83d2a0-7c27-4e07-849a-41886ab13674"
},
{
"key": "AppOwnerOrganizationId",
"value": "11111111-1111-1111-1111-111111111111"
},
{
"key": "ServicePrincipalProvisioningType",
"value": "Other"
}
],
"Category": "ApplicationManagement",
"CorrelationId": "4094afcb-147b-4a94-b658-61a8b89c9b9a",
"DurationMs": "0",
"Id": "Directory_4094afcb-147b-4a94-b658-61a8b89c9b9a_H7NJ3_564904",
"InitiatedBy": {
"user": {
"id": "aaaaaaaa-0000-0000-0000-000000000001",
"displayName": null,
"userPrincipalName": "adminuser@example.onmicrosoft.com",
"ipAddress": "203.0.113.10",
"roles": [],
"agentType": "notAgentic"
}
},
"LoggedByService": "Core Directory",
"OperationName": "Update service principal",
"OperationVersion": "1.0",
"Resource": "Microsoft.aadiam",
"ResourceGroup": "Microsoft.aadiam",
"ResourceId": "/tenants/11111111-1111-1111-1111-111111111111/providers/Microsoft.aadiam",
"Result": "success",
"ResultSignature": "None",
"TargetResources": [
{
"id": "11c4b230-304b-422e-b8fb-a2b507982bd6",
"displayName": "dw-harness-owner-cf516524",
"type": "ServicePrincipal",
"modifiedProperties": [
{
"displayName": "Included Updated Properties",
"oldValue": null,
"newValue": "\"\""
}
],
"administrativeUnits": [],
"agentType": "notAgentic"
}
]
}
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Sigma #
T1078, T1078.004, T1552↳ also matches Update application
References #
Create application – Certificates and secrets management
#Description
A certificate or client-secret credential was added to an application via the Certificates & secrets blade (the add counterpart of the Update form on event 12000073).
Example Audit Log Entry #
{
"AADOperationType": "Add",
"AADTenantId": "11111111-1111-1111-1111-111111111111",
"ActivityDateTime": "2026-07-24T03:21:14.4410905Z",
"ActivityDisplayName": "Create application – Certificates and secrets management ",
"AdditionalDetails": [
{
"key": "User-Agent",
"value": "python/3.14.5 (Linux-6.1.0-51-amd64-x86_64-with-glibc2.36) AZURECLI/2.88.0 (DEB)"
},
{
"key": "AppId",
"value": "0d810552-12c8-4592-99b8-e4fdc0f04f42"
}
],
"Category": "ApplicationManagement",
"CorrelationId": "206705f7-3a5d-4fcd-a5e3-3b5bf179ca08",
"DurationMs": "0",
"Id": "Directory_206705f7-3a5d-4fcd-a5e3-3b5bf179ca08_YYEKK_10369120",
"InitiatedBy": {
"user": {
"id": "aaaaaaaa-0000-0000-0000-000000000001",
"displayName": null,
"userPrincipalName": "adminuser@example.onmicrosoft.com",
"ipAddress": "203.0.113.10",
"roles": [],
"agentType": "notAgentic"
}
},
"LoggedByService": "Core Directory",
"OperationName": "Create application – Certificates and secrets management ",
"OperationVersion": "1.0",
"Resource": "Microsoft.aadiam",
"ResourceGroup": "Microsoft.aadiam",
"ResourceId": "/tenants/11111111-1111-1111-1111-111111111111/providers/Microsoft.aadiam",
"Result": "success",
"ResultSignature": "None",
"TargetResources": [
{
"id": "8f6edab2-5e40-49e7-bc95-5d1f4d278db5",
"displayName": "dw-harness-ara-cf516524",
"type": "Application",
"modifiedProperties": [
{
"displayName": "KeyDescription",
"oldValue": [],
"newValue": []
},
{
"displayName": "Included Updated Properties",
"oldValue": null,
"newValue": "\"KeyDescription\""
}
],
"administrativeUnits": [],
"agentType": "notAgentic"
}
]
}
References #
Rules often query computed field names, not native AuditLogs columns #
Many Entra detection rules pivot on field names that are not columns in this table but KQL projections the rule author computes from two dynamic columns. Searching the field list for those names finds nothing; use the canonical paths instead.
InitiatingUserPrincipalName(and siblingInitiating*names) is not a column. Rules project it fromInitiatedBy, for exampleextend InitiatingUserPrincipalName = tostring(InitiatedBy.user.userPrincipalName). The native paths areInitiatedBy.user.userPrincipalName,InitiatedBy.user.displayName, andInitiatedBy.user.idfor user actors, andInitiatedBy.app.displayName/InitiatedBy.app.appIdfor application or service-principal actors.- What changed lives in
TargetResources, adynamicarray. Expand it before filtering on the change:AuditLogs | mv-expand TargetResources | extend props = TargetResources.modifiedProperties, then readprops[].displayName,props[].oldValue, andprops[].newValue.
Column shapes per the AuditLogs table reference and the Graph directoryAudit resource.