Audit Logs / Microsoft Entra ID AuditLogs category

Audit Logs: ApplicationManagement

OperationNameDescriptionSampleRule
Add app role assignment grant to userAn app role was assigned to a user.YN
Add app role assignment to service principalAn application (app-only) role assignment was granted to a service principal.YY
Add applicationAn application registration was created.YY
Add delegated permission grantAn OAuth2 delegated permission grant was created for an application.YY
Add OAuth2PermissionGrantAn OAuth2 delegated permission grant was created.NY
Add owner to applicationAn owner was added to an application registration.YY
Add owner to service principalAn owner was added to a service principal.YY
Add service principalA service principal (enterprise application instance) was created.YY
Add service principal credentialsCredentials were added to a service principal (common persistence technique).YY
Consent to applicationAdmin or user consent was granted to an application (illicit-consent-grant target).YY
Delete applicationAn application registration was deleted.YY
Hard Delete applicationAn application registration was permanently deleted (purged from the deleted-items store, not recoverable).NY
Remove service principalA service principal was removed.YY
Remove service principal credentialsCredentials were removed from a service principal.YN
Restore applicationA soft-deleted application registration was restored.NY
Update applicationAn application registration was modified.YY
Update application – Certificates and secrets management Credentials (certificate or client secret) were added or changed on an application.YY
Add member to role approval requested (PIM activation)A PIM activation of an eligible Entra role was requested and is awaiting approver action.NN
Add member to role in PIM requested (timebound)A time-bound (expiring) Entra role assignment was requested in PIM.NN
Add policy to applicationA directory policy was assigned (applied) to an application.NN
Add policy to service principalAssigns a directory policy (token lifetime, token issuance, claims-mapping, home realm discovery, or app management) to a service principal.NN
Approve request - direct role assignmentAn approver approved a PIM request resulting in a direct Microsoft Entra role assignment; relevant to privilege escalation.NN
Assign Hardware Oath TokenA hardware OATH token (physical MFA device) was assigned to a user as an authentication method.NN
Authentication Methods Policy ResetReset of the tenant Authentication methods policy (governs available auth/MFA methods); exact reset scope unconfirmed.NN
Authentication Strength Combination Configuration CreateA combination configuration was created in a custom authentication strength policy (e.g., FIDO2 AAGUID or certificate restrictions).NN
Authentication Strength Combination Configuration DeleteA combination configuration was deleted from a custom authentication strength policy, relaxing method restrictions.NN
Authentication Strength Combination Configuration UpdateUpdate to an authentication strength's combination configurations (allowed FIDO2 AAGUIDs or certificate issuer SKIs/policy OIDs).NN
Authentication Strength Policy CreateA custom Conditional Access authentication strength policy was created.NN
Authentication Strength Policy DeleteA custom Conditional Access authentication strength policy was deleted.NN
Authentication Strength Policy UpdateA custom Conditional Access authentication strength policy was modified.NN
Bulk upload Hardware Oath TokenHardware OATH tokens were bulk-uploaded from a CSV into Microsoft Entra ID.NN
Cancel application update with safe rolloutA staged ('safe rollout') update to a directory application object was cancelled before completion.NN
Complete application update after safe rolloutA staged ('safe rollout') update to a directory application object was completed and applied.NN
Create application collectionAn application collection was created on the My Apps portal to group enterprise apps into a named tab for assigned users.NN
Create CertificateA certificate was created within Global Secure Access (exact object unconfirmed; e.g. the TLS-inspection intermediate CA).NN
Create Hardware Oath TokenA hardware OATH TOTP token was created in the tenant as an MFA method.NN
Delete application collectionA My Apps application collection (curated app grouping/tab) was deleted.NN
Delete CertificateA Global Secure Access TLS inspection certificate was deleted.NN
Delete Hardware Oath TokenDeletion of a hardware OATH (TOTP) token authentication method, removing one of a user's MFA methods.NN
Hard delete service principalPermanent, non-recoverable removal of a service principal object from the tenant.NN
MFA Service Policy UpdateAn update to the tenant's multifactor authentication (MFA) service policy/settings.NN
PATCH UserAuthMethod.PatchSignInPreferencesAsyncA user's authentication sign-in preferences (e.g., system-preferred MFA) were updated.NN
PATCH UserAuthMethod.ResetQRPinAsyncA user's QR code authentication-method PIN was reset (new temporary PIN, force-change at next sign-in).NN
PATCH UserAuthMethod.UpdateQRPinAsyncThe PIN for a user's QR code authentication method was updated/changed.NN
PIM activation request expiredA PIM role-activation request expired before completion (e.g., approval not granted in time).NN
PIM policy removedA PIM policy (role activation/assignment settings) was removed.NN
POST UserAuthMethod.SoftwareOathProofupRegistrationA software OATH (TOTP) token was registered as an MFA method for a user.NN
Remove app role assignment from service principalAn app role assignment was removed from a service principal, revoking an application's granted app role.YN
Remove delegated permission grantAn OAuth2 delegated permission grant was deleted, revoking the delegated API permissions granted to an application.YN
Remove member from role in PIM completed (timebound)PIM completed removal of a member's time-bound (expiring) role assignment.NN
Remove owner from applicationRemoval of an owner from an application, changing who can manage the app's configuration and ownership.YY
Remove owner from service principalAn owner was removed from a service principal, revoking their ability to manage the application's configuration and credentials.YY
Remove policy from applicationA policy was removed (detached) from an application object, ending that policy's enforcement for the app.NN
Remove policy from service principalA policy was removed (detached) from a service principal, ending that policy's enforcement for the app.NN
Remove requestA pending Privileged Identity Management assignment request was removed (canceled).NN
Restore consentA previously removed application consent (OAuth2 permission grant) was restored.NN
Restore service principalA soft-deleted service principal (enterprise application) was restored from the directory recycle bin.NN
Role definition createdA role definition (custom role) was created in Privileged Identity Management.NN
Set verified publisherAn application was marked with a verified publisher (a verified Microsoft partner was associated with the app).NN
Unset verified publisherThe verified-publisher (MPN/partner) status was removed from an app registration.NN
Update application collectionModification of a My Apps application collection (a grouping of apps shown to users on the portal).NN
Update application collection orderRecords a change to the display order of application collections shown to users in the My Apps portal.NN
Update application with safe rolloutRecords an update to a directory application object applied via a safe (staged) rollout mechanism.NN
Update CertificateUpdate to a certificate in a Microsoft Entra Global Secure Access configuration.NN
Update external secretsCredential secrets an application uses to authenticate to an external system were updated.NN
Update Hardware Oath TokenChange to a hardware OATH token (physical OTP device) used as an Entra MFA method (assign/activate/modify).NN
Update preview settingsMy Apps app-launcher preview settings were updated.NN
Update service principalA service principal object was modified (properties, credentials, or tags).YY
Create application – Certificates and secrets management A certificate or client-secret credential was added to an application via the Certificates & secrets blade (the add counterpart of the Update form on event 12000073).YN

Add app role assignment grant to user

#
Source
Microsoft Entra ID audit log
Audit Category
ApplicationManagement

Description

An app role was assigned to a user.

Example Audit Log Entry #

{
  "AADOperationType": "Assign",
  "AADTenantId": "11111111-1111-1111-1111-111111111111",
  "ActivityDateTime": "2026-07-24T03:21:18.2659948Z",
  "ActivityDisplayName": "Add app role assignment grant to user",
  "AdditionalDetails": [
    {
      "key": "User-Agent",
      "value": "python/3.14.5 (Linux-6.1.0-51-amd64-x86_64-with-glibc2.36) AZURECLI/2.88.0 (DEB)"
    },
    {
      "key": "AppId",
      "value": "0d810552-12c8-4592-99b8-e4fdc0f04f42"
    },
    {
      "key": "ServicePrincipalProvisioningType",
      "value": "Other"
    }
  ],
  "Category": "UserManagement",
  "CorrelationId": "0bb21419-a44e-47fc-86a8-3f01b732b3b3",
  "DurationMs": "0",
  "Id": "Directory_0bb21419-a44e-47fc-86a8-3f01b732b3b3_H7NJ3_571412",
  "InitiatedBy": {
    "user": {
      "id": "aaaaaaaa-0000-0000-0000-000000000001",
      "displayName": null,
      "userPrincipalName": "adminuser@example.onmicrosoft.com",
      "ipAddress": "203.0.113.10",
      "roles": [],
      "agentType": "notAgentic"
    }
  },
  "LoggedByService": "Core Directory",
  "OperationName": "Add app role assignment grant to user",
  "OperationVersion": "1.0",
  "Resource": "Microsoft.aadiam",
  "ResourceGroup": "Microsoft.aadiam",
  "ResourceId": "/tenants/11111111-1111-1111-1111-111111111111/providers/Microsoft.aadiam",
  "Result": "success",
  "ResultSignature": "None",
  "TargetResources": [
    {
      "id": "f543a660-eb12-47b5-9af6-2948b5efb45c",
      "displayName": "dw-harness-ara-cf516524",
      "type": "ServicePrincipal",
      "modifiedProperties": [
        {
          "displayName": "AppRole.Id",
          "oldValue": null,
          "newValue": "\"4fd7fe7b-8dc6-5774-8691-a09576fcb161\""
        },
        {
          "displayName": "AppRole.Value",
          "oldValue": null,
          "newValue": "\"dwharness\""
        },
        {
          "displayName": "AppRole.DisplayName",
          "oldValue": null,
          "newValue": "\"dwharness\""
        },
        {
          "displayName": "AppRoleAssignment.CreatedDateTime",
          "oldValue": null,
          "newValue": "\"2026-07-24T03:21:18.1619889Z\""
        },
        {
          "displayName": "AppRoleAssignment.LastModifiedDateTime",
          "oldValue": null,
          "newValue": "\"2026-07-24T03:21:18.1619889Z\""
        },
        {
          "displayName": "User.ObjectID",
          "oldValue": null,
          "newValue": "\"aaaaaaaa-0000-0000-0000-000000000001\""
        },
        {
          "displayName": "User.UPN",
          "oldValue": null,
          "newValue": "\"adminuser@example.onmicrosoft.com\""
        },
        {
          "displayName": "User.PUID",
          "oldValue": null,
          "newValue": "\"1111111111111111\""
        },
        {
          "displayName": "TargetId.ServicePrincipalNames",
          "oldValue": null,
          "newValue": "\"0d810552-12c8-4592-99b8-e4fdc0f04f42\""
        }
      ],
      "administrativeUnits": [],
      "agentType": "notAgentic"
    },
    {
      "id": "aaaaaaaa-0000-0000-0000-000000000001",
      "displayName": null,
      "type": "User",
      "userPrincipalName": "adminuser@example.onmicrosoft.com",
      "modifiedProperties": [],
      "administrativeUnits": [],
      "agentType": "notAgentic"
    }
  ]
}

References #

Add app role assignment to service principal

#
Source
Microsoft Entra ID audit log
Audit Category
ApplicationManagement

Description

An application (app-only) role assignment was granted to a service principal.

Example Audit Log Entry #

{
  "AADOperationType": "Assign",
  "AADTenantId": "11111111-1111-1111-1111-111111111111",
  "ActivityDateTime": "2026-07-24T03:21:22.01158Z",
  "ActivityDisplayName": "Add app role assignment to service principal",
  "AdditionalDetails": [
    {
      "key": "User-Agent",
      "value": "python/3.14.5 (Linux-6.1.0-51-amd64-x86_64-with-glibc2.36) AZURECLI/2.88.0 (DEB)"
    },
    {
      "key": "AppId",
      "value": "0d810552-12c8-4592-99b8-e4fdc0f04f42"
    },
    {
      "key": "ServicePrincipalProvisioningType",
      "value": "Other"
    }
  ],
  "Category": "ApplicationManagement",
  "CorrelationId": "295dedae-6aca-49bb-9fb9-4c84d580049f",
  "DurationMs": "0",
  "Id": "Directory_295dedae-6aca-49bb-9fb9-4c84d580049f_ZY05Q_10597091",
  "InitiatedBy": {
    "user": {
      "id": "aaaaaaaa-0000-0000-0000-000000000001",
      "displayName": null,
      "userPrincipalName": "adminuser@example.onmicrosoft.com",
      "ipAddress": "203.0.113.10",
      "roles": [],
      "agentType": "notAgentic"
    }
  },
  "LoggedByService": "Core Directory",
  "OperationName": "Add app role assignment to service principal",
  "OperationVersion": "1.0",
  "Resource": "Microsoft.aadiam",
  "ResourceGroup": "Microsoft.aadiam",
  "ResourceId": "/tenants/11111111-1111-1111-1111-111111111111/providers/Microsoft.aadiam",
  "Result": "success",
  "ResultSignature": "None",
  "TargetResources": [
    {
      "id": "f543a660-eb12-47b5-9af6-2948b5efb45c",
      "displayName": "dw-harness-ara-cf516524",
      "type": "ServicePrincipal",
      "modifiedProperties": [
        {
          "displayName": "AppRole.Id",
          "oldValue": null,
          "newValue": "\"4fd7fe7b-8dc6-5774-8691-a09576fcb161\""
        },
        {
          "displayName": "AppRole.Value",
          "oldValue": null,
          "newValue": "\"dwharness\""
        },
        {
          "displayName": "AppRole.DisplayName",
          "oldValue": null,
          "newValue": "\"dwharness\""
        },
        {
          "displayName": "AppRoleAssignment.CreatedDateTime",
          "oldValue": null,
          "newValue": "\"2026-07-24T03:21:21.8105676Z\""
        },
        {
          "displayName": "AppRoleAssignment.LastModifiedDateTime",
          "oldValue": null,
          "newValue": "\"2026-07-24T03:21:21.8105676Z\""
        },
        {
          "displayName": "ServicePrincipal.ObjectID",
          "oldValue": null,
          "newValue": "\"f543a660-eb12-47b5-9af6-2948b5efb45c\""
        },
        {
          "displayName": "ServicePrincipal.DisplayName",
          "oldValue": null,
          "newValue": "\"dw-harness-ara-cf516524\""
        },
        {
          "displayName": "ServicePrincipal.AppId",
          "oldValue": null,
          "newValue": "\"0d810552-12c8-4592-99b8-e4fdc0f04f42\""
        },
        {
          "displayName": "ServicePrincipal.Name",
          "oldValue": null,
          "newValue": "\"0d810552-12c8-4592-99b8-e4fdc0f04f42\""
        },
        {
          "displayName": "TargetId.ServicePrincipalNames",
          "oldValue": null,
          "newValue": "\"0d810552-12c8-4592-99b8-e4fdc0f04f42\""
        }
      ],
      "administrativeUnits": [],
      "agentType": "notAgentic"
    },
    {
      "id": "f543a660-eb12-47b5-9af6-2948b5efb45c",
      "displayName": "0d810552-12c8-4592-99b8-e4fdc0f04f42",
      "type": "ServicePrincipal",
      "modifiedProperties": [],
      "administrativeUnits": [],
      "agentType": "notAgentic"
    }
  ]
}

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
PermissionGrant (kusto rule field)containsrolemanagement.readwrite.directory4 ruleskusto
azure_ad::logged_by_service (kusto rule field)eqcore directory4 ruleskusto
AADOperationType (kusto rule field)eqassign2 ruleskusto
PermissionGrant_TimeGenerated (kusto rule field)cross_field_compareRoleAssignment_TimeGenerated2 ruleskusto
RoleAssignment (kusto rule field)containsadmin2 ruleskusto
app (kusto rule field)is_not_null2 ruleskusto
azure_ad::modified_properties_new (kusto rule field)gt02 ruleskusto
displayName (kusto rule field)eqAppRole.Value2 ruleskusto
displayName (kusto rule field)eqserviceprincipal.displayname2 ruleskusto
displayName (kusto rule field)eqserviceprincipal.objectid2 ruleskusto
displayName (kusto rule field)inRole.DisplayName2 ruleskusto
displayName (kusto rule field)inRoleDefinition.DisplayName2 ruleskusto
displayName (kusto rule field)inapprole.value2 ruleskusto
displayName (kusto rule field)indelegatedpermissiongrant.scope2 ruleskusto
displayName (kusto rule field)is_not_null2 ruleskusto

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sigma #

Splunk #

Kusto #

References #

Add application

#
Source
Microsoft Entra ID audit log
Audit Category
ApplicationManagement

Description

An application registration was created.

Example Audit Log Entry #

{
  "AADOperationType": "Add",
  "AADTenantId": "11111111-1111-1111-1111-111111111111",
  "ActivityDateTime": "2026-07-24T03:21:14.5140881Z",
  "ActivityDisplayName": "Add application",
  "AdditionalDetails": [
    {
      "key": "User-Agent",
      "value": "python/3.14.5 (Linux-6.1.0-51-amd64-x86_64-with-glibc2.36) AZURECLI/2.88.0 (DEB)"
    },
    {
      "key": "AppId",
      "value": "0d810552-12c8-4592-99b8-e4fdc0f04f42"
    }
  ],
  "Category": "ApplicationManagement",
  "CorrelationId": "206705f7-3a5d-4fcd-a5e3-3b5bf179ca08",
  "DurationMs": "0",
  "Id": "Directory_206705f7-3a5d-4fcd-a5e3-3b5bf179ca08_YYEKK_10369133",
  "InitiatedBy": {
    "user": {
      "id": "aaaaaaaa-0000-0000-0000-000000000001",
      "displayName": null,
      "userPrincipalName": "adminuser@example.onmicrosoft.com",
      "ipAddress": "203.0.113.10",
      "roles": [],
      "agentType": "notAgentic"
    }
  },
  "LoggedByService": "Core Directory",
  "OperationName": "Add application",
  "OperationVersion": "1.0",
  "Resource": "Microsoft.aadiam",
  "ResourceGroup": "Microsoft.aadiam",
  "ResourceId": "/tenants/11111111-1111-1111-1111-111111111111/providers/Microsoft.aadiam",
  "Result": "success",
  "ResultSignature": "None",
  "TargetResources": [
    {
      "id": "8f6edab2-5e40-49e7-bc95-5d1f4d278db5",
      "displayName": "dw-harness-ara-cf516524",
      "type": "Application",
      "modifiedProperties": [
        {
          "displayName": "AppId",
          "oldValue": [],
          "newValue": [
            "0d810552-12c8-4592-99b8-e4fdc0f04f42"
          ]
        },
        {
          "displayName": "AvailableToOtherTenants",
          "oldValue": [],
          "newValue": [
            false
          ]
        },
        {
          "displayName": "DisplayName",
          "oldValue": [],
          "newValue": [
            "dw-harness-ara-cf516524"
          ]
        },
        {
          "displayName": "Entitlement",
          "oldValue": [],
          "newValue": [
            {
              "EntitlementEncodingVersion": 2,
              "EntitlementId": "4fd7fe7b-8dc6-5774-8691-a09576fcb161",
              "IsDisabled": false,
              "Origin": 0,
              "Name": "dwharness",
              "Description": "detection.wiki harness role",
              "Definition": null,
              "ClaimValue": "dwharness",
              "ResourceScopeType": 0,
              "IsPrivate": false,
              "UserConsentDisplayName": null,
              "UserConsentDescription": null,
              "DirectAccessGrantTypes": [
                20,
                29
              ],
              "ImpersonationAccessGrantTypes": [],
              "EntitlementCategory": 0,
              "DependentMicrosoftGraphPermissions": [],
              "IsPreauthzOnlyDirectAccessGrant": false,
              "IsPreauthzOnlyImpersonationGrant": false,
              "ImpersonationPrivilegeLevel": 0,
              "DirectAccessPrivilegeLevel": 0
            }
          ]
        },
        {
          "displayName": "PublisherDomain",
          "oldValue": [],
          "newValue": [
            "example.onmicrosoft.com"
          ]
        },
        {
          "displayName": "ServicePrincipalLockConfiguration",
          "oldValue": [],
          "newValue": [
            {
              "IsEnabled": true,
              "AllProperties": true,
              "CredentialsWithUsageVerify": null,
              "CredentialsWithUsageSign": null,
              "IdentifierUris": null,
              "TokenEncryptionKeyId": null,
              "ServicePrincipalLockExtension": "AQEAAAA="
            }
          ]
        },
        {
          "displayName": "SignInAudience",
          "oldValue": [],
          "newValue": [
            "AzureADMyOrg"
          ]
        },
        {
          "displayName": "Included Updated Properties",
          "oldValue": null,
          "newValue": "\"AppId, AvailableToOtherTenants, DisplayName, Entitlement, PublisherDomain, ServicePrincipalLockConfiguration, SignInAudience\""
        }
      ],
      "administrativeUnits": [],
      "agentType": "notAgentic"
    }
  ]
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

YARA-L #

  • Entra ID Application Creation source low: Application creation can be legitimate but aren't frequently created. Validating application creation may be appropriate to ensure rogue apps aren't being created.

References #

Add delegated permission grant

#
Source
Microsoft Entra ID audit log
Audit Category
ApplicationManagement

Description

An OAuth2 delegated permission grant was created for an application.

Example Audit Log Entry #

{
  "AADOperationType": "Assign",
  "AADTenantId": "11111111-1111-1111-1111-111111111111",
  "ActivityDateTime": "2026-07-24T03:20:30.2084018Z",
  "ActivityDisplayName": "Add delegated permission grant",
  "AdditionalDetails": [
    {
      "key": "User-Agent",
      "value": "python/3.14.5 (Linux-6.1.0-51-amd64-x86_64-with-glibc2.36) AZURECLI/2.88.0 (DEB)"
    },
    {
      "key": "AppId",
      "value": "00000003-0000-0000-c000-000000000000"
    },
    {
      "key": "ServicePrincipalProvisioningType",
      "value": "Other"
    }
  ],
  "Category": "ApplicationManagement",
  "CorrelationId": "c68a17a1-1dc8-457e-b86c-0dabec606a3f",
  "DurationMs": "0",
  "Id": "Directory_c68a17a1-1dc8-457e-b86c-0dabec606a3f_IXXZ5_10644521",
  "InitiatedBy": {
    "user": {
      "id": "aaaaaaaa-0000-0000-0000-000000000001",
      "displayName": null,
      "userPrincipalName": "adminuser@example.onmicrosoft.com",
      "ipAddress": "203.0.113.10",
      "roles": [],
      "agentType": "notAgentic"
    }
  },
  "LoggedByService": "Core Directory",
  "OperationName": "Add delegated permission grant",
  "OperationVersion": "1.0",
  "Resource": "Microsoft.aadiam",
  "ResourceGroup": "Microsoft.aadiam",
  "ResourceId": "/tenants/11111111-1111-1111-1111-111111111111/providers/Microsoft.aadiam",
  "Result": "success",
  "ResultSignature": "None",
  "TargetResources": [
    {
      "id": "2e5ab30e-ae89-43c2-b130-0022f3d655a7",
      "displayName": "Microsoft Graph",
      "type": "ServicePrincipal",
      "modifiedProperties": [
        {
          "displayName": "DelegatedPermissionGrant.Scope",
          "oldValue": null,
          "newValue": "\"User.Read\""
        },
        {
          "displayName": "DelegatedPermissionGrant.ConsentType",
          "oldValue": null,
          "newValue": "\"Principal\""
        },
        {
          "displayName": "ServicePrincipal.ObjectID",
          "oldValue": null,
          "newValue": "\"af2cee02-3ad4-4486-85a2-e8eafc78cd6e\""
        },
        {
          "displayName": "ServicePrincipal.DisplayName",
          "oldValue": null,
          "newValue": null
        },
        {
          "displayName": "ServicePrincipal.AppId",
          "oldValue": null,
          "newValue": null
        },
        {
          "displayName": "ServicePrincipal.Name",
          "oldValue": null,
          "newValue": null
        },
        {
          "displayName": "TargetId.ServicePrincipalNames",
          "oldValue": null,
          "newValue": "\"00000003-0000-0000-c000-000000000000/ags.windows.net;00000003-0000-0000-c000-000000000000;https://canary.graph.microsoft.com;https://graph.microsoft.com;https://ags.windows.net;https://graph.microsoft.us;https://graph.microsoft.com/;https://dod-graph.microsoft.us;https://canary.graph.microsoft.com/;https://graph.microsoft.us/;https://dod-graph.microsoft.us/\""
        }
      ],
      "administrativeUnits": [],
      "agentType": "notAgentic"
    },
    {
      "id": "af2cee02-3ad4-4486-85a2-e8eafc78cd6e",
      "displayName": null,
      "type": "ServicePrincipal",
      "modifiedProperties": [],
      "administrativeUnits": [],
      "agentType": "notAgentic"
    }
  ]
}

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
azure_ad::logged_by_service (kusto rule field)eqcore directory5 ruleskusto
azure_ad::modified_properties_new (kusto rule field)containsaddresstype3 ruleskusto
azure_ad::modified_properties_new (kusto rule field)gt05 ruleskusto
displayName (kusto rule field)eqappaddress3 ruleskusto
displayName (kusto rule field)eqconsentaction.permissions3 ruleskusto
displayName (kusto rule field)is_not_null5 ruleskusto
type (kusto rule field)eqserviceprincipal5 ruleskusto
GrantConsentType (kusto rule field)neAllPrincipals3 ruleskusto
ConsentFull (kusto rule field)containsfiles.read2 ruleskusto
ConsentFull (kusto rule field)containsfiles.read.all2 ruleskusto
ConsentFull (kusto rule field)containsmail.read2 ruleskusto
ConsentFull (kusto rule field)containsmail.send2 ruleskusto
ConsentFull (kusto rule field)containsoffline_access2 ruleskusto
ConsentFull (kusto rule field)containsuser.read2 ruleskusto
PermissionGrant (kusto rule field)containsrolemanagement.readwrite.directory2 ruleskusto

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sigma #

Kusto #

References #

Add OAuth2PermissionGrant

#
Source
Microsoft Entra ID audit log
Audit Category
ApplicationManagement

Description

An OAuth2 delegated permission grant was created.

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
GrantConsentType (kusto rule field)neAllPrincipals3 ruleskusto
azure_ad::logged_by_service (kusto rule field)eqcore directory3 ruleskusto
azure_ad::modified_properties_new (kusto rule field)containsaddresstype3 ruleskusto
azure_ad::modified_properties_new (kusto rule field)gt03 ruleskusto
displayName (kusto rule field)eqappaddress3 ruleskusto
displayName (kusto rule field)eqconsentaction.permissions3 ruleskusto
displayName (kusto rule field)is_not_null3 ruleskusto
type (kusto rule field)eqserviceprincipal3 ruleskusto
ConsentFull (kusto rule field)containsfiles.read2 ruleskusto
ConsentFull (kusto rule field)containsfiles.read.all2 ruleskusto
ConsentFull (kusto rule field)containsmail.read2 ruleskusto
ConsentFull (kusto rule field)containsmail.send2 ruleskusto
ConsentFull (kusto rule field)containsoffline_access2 ruleskusto
ConsentFull (kusto rule field)containsuser.read2 ruleskusto
azure_ad::target_resources (kusto rule field)containsoffline2 ruleskusto

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Kusto #

References #

Add owner to application

#
Source
Microsoft Entra ID audit log
Audit Category
ApplicationManagement

Description

An owner was added to an application registration.

Example Audit Log Entry #

{
  "AADOperationType": "Assign",
  "AADTenantId": "11111111-1111-1111-1111-111111111111",
  "ActivityDateTime": "2026-07-24T03:20:08.5025607Z",
  "ActivityDisplayName": "Add owner to application",
  "AdditionalDetails": [
    {
      "key": "User-Agent",
      "value": "python/3.14.5 (Linux-6.1.0-51-amd64-x86_64-with-glibc2.36) AZURECLI/2.88.0 (DEB)"
    }
  ],
  "Category": "ApplicationManagement",
  "CorrelationId": "81f6cc99-b0f6-4a94-ac78-043f6ed5e439",
  "DurationMs": "0",
  "Id": "Directory_81f6cc99-b0f6-4a94-ac78-043f6ed5e439_FROXF_10026633",
  "InitiatedBy": {
    "user": {
      "id": "aaaaaaaa-0000-0000-0000-000000000001",
      "displayName": null,
      "userPrincipalName": "adminuser@example.onmicrosoft.com",
      "ipAddress": "203.0.113.10",
      "roles": [],
      "agentType": "notAgentic"
    }
  },
  "LoggedByService": "Core Directory",
  "OperationName": "Add owner to application",
  "OperationVersion": "1.0",
  "Resource": "Microsoft.aadiam",
  "ResourceGroup": "Microsoft.aadiam",
  "ResourceId": "/tenants/11111111-1111-1111-1111-111111111111/providers/Microsoft.aadiam",
  "Result": "success",
  "ResultSignature": "None",
  "TargetResources": [
    {
      "id": "aaaaaaaa-0000-0000-0000-000000000001",
      "displayName": null,
      "type": "User",
      "userPrincipalName": "adminuser@example.onmicrosoft.com",
      "modifiedProperties": [
        {
          "displayName": "Application.ObjectID",
          "oldValue": null,
          "newValue": "\"d5dcc899-cc10-4152-93d9-ecaa990c016e\""
        },
        {
          "displayName": "Application.DisplayName",
          "oldValue": null,
          "newValue": "\"dw-harness-owner-cf516524\""
        },
        {
          "displayName": "Application.AppId",
          "oldValue": null,
          "newValue": "\"af83d2a0-7c27-4e07-849a-41886ab13674\""
        }
      ],
      "administrativeUnits": [],
      "agentType": "notAgentic"
    },
    {
      "id": "d5dcc899-cc10-4152-93d9-ecaa990c016e",
      "displayName": null,
      "type": "Application",
      "modifiedProperties": [],
      "administrativeUnits": [],
      "agentType": "notAgentic"
    }
  ]
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sigma #

  • Added Owner To Application source medium: Detects when a new owner is added to an application. This gives that account privileges to make modifications and configuration changes to the application.T1552

Elastic #

Splunk #

  • Azure AD Service Principal Owner Added source: The following analytic detects the addition of a new owner to a Service Principal within an Azure AD tenant. It leverages Azure Active Directory events from the AuditLog log category to identify this activity. This behavior is significant…T1098

Kusto #

References #

Add owner to service principal

#
Source
Microsoft Entra ID audit log
Audit Category
ApplicationManagement

Description

An owner was added to a service principal.

Example Audit Log Entry #

{
  "AADOperationType": "Assign",
  "AADTenantId": "11111111-1111-1111-1111-111111111111",
  "ActivityDateTime": "2026-07-24T03:20:11.7100237Z",
  "ActivityDisplayName": "Add owner to service principal",
  "AdditionalDetails": [
    {
      "key": "User-Agent",
      "value": "python/3.14.5 (Linux-6.1.0-51-amd64-x86_64-with-glibc2.36) AZURECLI/2.88.0 (DEB)"
    }
  ],
  "Category": "ApplicationManagement",
  "CorrelationId": "0a53d892-9443-4659-8928-0e04bcc4f75d",
  "DurationMs": "0",
  "Id": "Directory_0a53d892-9443-4659-8928-0e04bcc4f75d_ZY05Q_10589172",
  "InitiatedBy": {
    "user": {
      "id": "aaaaaaaa-0000-0000-0000-000000000001",
      "displayName": null,
      "userPrincipalName": "adminuser@example.onmicrosoft.com",
      "ipAddress": "203.0.113.10",
      "roles": [],
      "agentType": "notAgentic"
    }
  },
  "LoggedByService": "Core Directory",
  "OperationName": "Add owner to service principal",
  "OperationVersion": "1.0",
  "Resource": "Microsoft.aadiam",
  "ResourceGroup": "Microsoft.aadiam",
  "ResourceId": "/tenants/11111111-1111-1111-1111-111111111111/providers/Microsoft.aadiam",
  "Result": "success",
  "ResultSignature": "None",
  "TargetResources": [
    {
      "id": "aaaaaaaa-0000-0000-0000-000000000001",
      "displayName": null,
      "type": "User",
      "userPrincipalName": "adminuser@example.onmicrosoft.com",
      "modifiedProperties": [
        {
          "displayName": "ServicePrincipal.ObjectID",
          "oldValue": null,
          "newValue": "\"11c4b230-304b-422e-b8fb-a2b507982bd6\""
        },
        {
          "displayName": "ServicePrincipal.DisplayName",
          "oldValue": null,
          "newValue": "\"dw-harness-owner-cf516524\""
        },
        {
          "displayName": "ServicePrincipal.AppId",
          "oldValue": null,
          "newValue": "\"af83d2a0-7c27-4e07-849a-41886ab13674\""
        },
        {
          "displayName": "ServicePrincipal.Name",
          "oldValue": null,
          "newValue": "\"af83d2a0-7c27-4e07-849a-41886ab13674\""
        }
      ],
      "administrativeUnits": [],
      "agentType": "notAgentic"
    },
    {
      "id": "11c4b230-304b-422e-b8fb-a2b507982bd6",
      "displayName": "af83d2a0-7c27-4e07-849a-41886ab13674",
      "type": "ServicePrincipal",
      "modifiedProperties": [],
      "administrativeUnits": [],
      "agentType": "notAgentic"
    }
  ]
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

  • Entra ID User Added as Service Principal Owner source low: Identifies when a user is added as an owner for an Azure service principal. The service principal object defines what the application can do in the specific tenant, who can access the application, and what resources the app can access. A service principal object is created when an application is given permission to access resources in a tenant. An adversary may add a user account as an owner for a service principal and use that account in order to define what an application can do in the Azure AD tenant.T1078, T1078.004, T1098

References #

Add service principal

#
Source
Microsoft Entra ID audit log
Audit Category
ApplicationManagement

Description

A service principal (enterprise application instance) was created.

Example Audit Log Entry #

{
  "AADOperationType": "Add",
  "AADTenantId": "11111111-1111-1111-1111-111111111111",
  "ActivityDateTime": "2026-07-24T03:21:15.7048858Z",
  "ActivityDisplayName": "Add service principal",
  "AdditionalDetails": [
    {
      "key": "User-Agent",
      "value": "python/3.14.5 (Linux-6.1.0-51-amd64-x86_64-with-glibc2.36) AZURECLI/2.88.0 (DEB)"
    },
    {
      "key": "AppId",
      "value": "0d810552-12c8-4592-99b8-e4fdc0f04f42"
    },
    {
      "key": "AppOwnerOrganizationId",
      "value": "11111111-1111-1111-1111-111111111111"
    },
    {
      "key": "ServicePrincipalProvisioningType",
      "value": "Other"
    }
  ],
  "Category": "ApplicationManagement",
  "CorrelationId": "29b3975e-a3b7-4fcb-9e4a-b7b42a68af39",
  "DurationMs": "0",
  "Id": "Directory_29b3975e-a3b7-4fcb-9e4a-b7b42a68af39_LCVO1_10003939",
  "InitiatedBy": {
    "user": {
      "id": "aaaaaaaa-0000-0000-0000-000000000001",
      "displayName": null,
      "userPrincipalName": "adminuser@example.onmicrosoft.com",
      "ipAddress": "203.0.113.10",
      "roles": [],
      "agentType": "notAgentic"
    }
  },
  "LoggedByService": "Core Directory",
  "OperationName": "Add service principal",
  "OperationVersion": "1.0",
  "Resource": "Microsoft.aadiam",
  "ResourceGroup": "Microsoft.aadiam",
  "ResourceId": "/tenants/11111111-1111-1111-1111-111111111111/providers/Microsoft.aadiam",
  "Result": "success",
  "ResultSignature": "None",
  "TargetResources": [
    {
      "id": "f543a660-eb12-47b5-9af6-2948b5efb45c",
      "displayName": "dw-harness-ara-cf516524",
      "type": "ServicePrincipal",
      "modifiedProperties": [
        {
          "displayName": "AccountEnabled",
          "oldValue": [],
          "newValue": [
            true
          ]
        },
        {
          "displayName": "AppPrincipalId",
          "oldValue": [],
          "newValue": [
            "0d810552-12c8-4592-99b8-e4fdc0f04f42"
          ]
        },
        {
          "displayName": "DisplayName",
          "oldValue": [],
          "newValue": [
            "dw-harness-ara-cf516524"
          ]
        },
        {
          "displayName": "ServicePrincipalName",
          "oldValue": [],
          "newValue": [
            "0d810552-12c8-4592-99b8-e4fdc0f04f42"
          ]
        },
        {
          "displayName": "Credential",
          "oldValue": [],
          "newValue": [
            {
              "CredentialType": 2,
              "KeyStoreId": "291154f0-a9f5-45bb-87be-9c8ee5b6d62c",
              "KeyGroupId": "291154f0-a9f5-45bb-87be-9c8ee5b6d62c"
            }
          ]
        },
        {
          "displayName": "Included Updated Properties",
          "oldValue": null,
          "newValue": "\"AccountEnabled, AppPrincipalId, DisplayName, ServicePrincipalName, Credential\""
        }
      ],
      "administrativeUnits": [],
      "agentType": "notAgentic"
    }
  ]
}

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
GrantConsentType (kusto rule field)neAllPrincipals3 ruleskusto
azure_ad::logged_by_service (kusto rule field)eqcore directory3 ruleskusto
azure_ad::modified_properties_new (kusto rule field)containsaddresstype3 ruleskusto
azure_ad::modified_properties_new (kusto rule field)gt03 ruleskusto
displayName (kusto rule field)eqappaddress3 ruleskusto
displayName (kusto rule field)eqconsentaction.permissions3 ruleskusto
displayName (kusto rule field)is_not_null3 ruleskusto
type (kusto rule field)eqserviceprincipal3 ruleskusto
ConsentFull (kusto rule field)containsfiles.read2 ruleskusto
ConsentFull (kusto rule field)containsfiles.read.all2 ruleskusto
ConsentFull (kusto rule field)containsmail.read2 ruleskusto
ConsentFull (kusto rule field)containsmail.send2 ruleskusto
ConsentFull (kusto rule field)containsoffline_access2 ruleskusto
ConsentFull (kusto rule field)containsuser.read2 ruleskusto
azure_ad::target_resources (kusto rule field)containsoffline2 ruleskusto

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sigma #

Elastic #

  • Entra ID Service Principal Created source low: Identifies when a new service principal is added in Microsoft Entra ID. An application, hosted service, or automated tool that accesses or modifies resources needs an identity created. This identity is known as a service principal. For security reasons, it's always recommended to use service principals with automated tools rather than allowing them to log in with a user identity.T1136, T1136.003

Splunk #

Kusto #

References #

Add service principal credentials

#
Source
Microsoft Entra ID audit log
Audit Category
ApplicationManagement

Description

Credentials were added to a service principal (common persistence technique).

Example Audit Log Entry #

{
  "AADOperationType": "Update",
  "AADTenantId": "11111111-1111-1111-1111-111111111111",
  "ActivityDateTime": "2026-07-24T03:20:02.9311374Z",
  "ActivityDisplayName": "Add service principal credentials",
  "AdditionalDetails": [
    {
      "key": "User-Agent",
      "value": "python/3.14.5 (Linux-6.1.0-51-amd64-x86_64-with-glibc2.36) AZURECLI/2.88.0 (DEB)"
    },
    {
      "key": "AppId",
      "value": "0880df21-e1b6-42e5-b399-8840779d78c4"
    },
    {
      "key": "AppOwnerOrganizationId",
      "value": "11111111-1111-1111-1111-111111111111"
    },
    {
      "key": "ServicePrincipalProvisioningType",
      "value": "Other"
    }
  ],
  "Category": "ApplicationManagement",
  "CorrelationId": "feb89f71-6257-416b-afb4-fe5bf7a11b78",
  "DurationMs": "0",
  "Id": "Directory_feb89f71-6257-416b-afb4-fe5bf7a11b78_4OTNI_10119999",
  "InitiatedBy": {
    "user": {
      "id": "aaaaaaaa-0000-0000-0000-000000000001",
      "displayName": null,
      "userPrincipalName": "adminuser@example.onmicrosoft.com",
      "ipAddress": "203.0.113.10",
      "roles": [],
      "agentType": "notAgentic"
    }
  },
  "LoggedByService": "Core Directory",
  "OperationName": "Add service principal credentials",
  "OperationVersion": "1.0",
  "Resource": "Microsoft.aadiam",
  "ResourceGroup": "Microsoft.aadiam",
  "ResourceId": "/tenants/11111111-1111-1111-1111-111111111111/providers/Microsoft.aadiam",
  "Result": "success",
  "ResultSignature": "None",
  "TargetResources": [
    {
      "id": "e637b633-f84a-4e3a-9e92-1dda38b7daa0",
      "displayName": "dw-harness-credential-cf516524",
      "type": "ServicePrincipal",
      "modifiedProperties": [
        {
          "displayName": "KeyDescription",
          "oldValue": [],
          "newValue": [
            "[KeyIdentifier=384afc65-9185-49a9-b690-8d4a75bd5609,KeyType=Password,KeyUsage=Verify,DisplayName=dw-harness]"
          ]
        },
        {
          "displayName": "Included Updated Properties",
          "oldValue": null,
          "newValue": "\"KeyDescription\""
        }
      ],
      "administrativeUnits": [],
      "agentType": "notAgentic"
    }
  ]
}

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
displayName (kusto rule field)eqconsentaction.permissions1 rulekusto
displayName (kusto rule field)eqconsentcontext.isadminconsent1 rulekusto
displayName (kusto rule field)eqincluded updated properties1 rulekusto
displayName (kusto rule field)eqkeydescription1 rulekusto
displayName (kusto rule field)eqtargetid.serviceprincipalnames1 rulekusto
type (kusto rule field)eqserviceprincipal1 rulekusto

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

  • Entra ID Service Principal Credentials Created by Unusual User source medium: Identifies when new Service Principal credentials have been added in Microsoft Entra ID. In most organizations, credentials will be added to service principals infrequently. Hijacking an application (by adding a rogue secret or certificate) with granted permissions will allow the attacker to access data that is normally protected by MFA requirements.T1098, T1098.001

Kusto #

References #

Consent to application

#
Source
Microsoft Entra ID audit log
Audit Category
ApplicationManagement

Delete application

#
Source
Microsoft Entra ID audit log
Audit Category
ApplicationManagement

Description

An application registration was deleted.

Example Audit Log Entry #

{
  "AADOperationType": "Delete",
  "AADTenantId": "11111111-1111-1111-1111-111111111111",
  "ActivityDateTime": "2026-07-24T03:21:26.0289117Z",
  "ActivityDisplayName": "Delete application",
  "AdditionalDetails": [
    {
      "key": "User-Agent",
      "value": "python/3.14.5 (Linux-6.1.0-51-amd64-x86_64-with-glibc2.36) AZURECLI/2.88.0 (DEB)"
    },
    {
      "key": "AppId",
      "value": "0d810552-12c8-4592-99b8-e4fdc0f04f42"
    }
  ],
  "Category": "ApplicationManagement",
  "CorrelationId": "7c7a7ae6-bc89-4dd8-9da1-a0445ee147de",
  "DurationMs": "0",
  "Id": "Directory_7c7a7ae6-bc89-4dd8-9da1-a0445ee147de_0KIMT_10479137",
  "InitiatedBy": {
    "user": {
      "id": "aaaaaaaa-0000-0000-0000-000000000001",
      "displayName": null,
      "userPrincipalName": "adminuser@example.onmicrosoft.com",
      "ipAddress": "203.0.113.10",
      "roles": [],
      "agentType": "notAgentic"
    }
  },
  "LoggedByService": "Core Directory",
  "OperationName": "Delete application",
  "OperationVersion": "1.0",
  "Resource": "Microsoft.aadiam",
  "ResourceGroup": "Microsoft.aadiam",
  "ResourceId": "/tenants/11111111-1111-1111-1111-111111111111/providers/Microsoft.aadiam",
  "Result": "success",
  "ResultSignature": "None",
  "TargetResources": [
    {
      "id": "8f6edab2-5e40-49e7-bc95-5d1f4d278db5",
      "displayName": "dw-harness-ara-cf516524",
      "type": "Application",
      "modifiedProperties": [],
      "administrativeUnits": [],
      "agentType": "notAgentic"
    }
  ]
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sigma #

YARA-L #

References #

Hard Delete application

#
Source
Microsoft Entra ID audit log
Audit Category
ApplicationManagement

Description

An application registration was permanently deleted (purged from the deleted-items store, not recoverable).

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sigma #

YARA-L #

References #

Remove service principal

#
Source
Microsoft Entra ID audit log
Audit Category
ApplicationManagement

Description

A service principal was removed.

Example Audit Log Entry #

{
  "AADOperationType": "Delete",
  "AADTenantId": "11111111-1111-1111-1111-111111111111",
  "ActivityDateTime": "2026-07-24T03:21:25.1551267Z",
  "ActivityDisplayName": "Remove service principal",
  "AdditionalDetails": [
    {
      "key": "User-Agent",
      "value": "python/3.14.5 (Linux-6.1.0-51-amd64-x86_64-with-glibc2.36) AZURECLI/2.88.0 (DEB)"
    },
    {
      "key": "AppId",
      "value": "0d810552-12c8-4592-99b8-e4fdc0f04f42"
    },
    {
      "key": "AppOwnerOrganizationId",
      "value": "11111111-1111-1111-1111-111111111111"
    },
    {
      "key": "ServicePrincipalProvisioningType",
      "value": "Other"
    }
  ],
  "Category": "ApplicationManagement",
  "CorrelationId": "e26b3bd2-a159-46d2-a187-afd1ebd1b642",
  "DurationMs": "0",
  "Id": "Directory_e26b3bd2-a159-46d2-a187-afd1ebd1b642_H7NJ3_572113",
  "InitiatedBy": {
    "user": {
      "id": "aaaaaaaa-0000-0000-0000-000000000001",
      "displayName": null,
      "userPrincipalName": "adminuser@example.onmicrosoft.com",
      "ipAddress": "203.0.113.10",
      "roles": [],
      "agentType": "notAgentic"
    }
  },
  "LoggedByService": "Core Directory",
  "OperationName": "Remove service principal",
  "OperationVersion": "1.0",
  "Resource": "Microsoft.aadiam",
  "ResourceGroup": "Microsoft.aadiam",
  "ResourceId": "/tenants/11111111-1111-1111-1111-111111111111/providers/Microsoft.aadiam",
  "Result": "success",
  "ResultSignature": "None",
  "TargetResources": [
    {
      "id": "f543a660-eb12-47b5-9af6-2948b5efb45c",
      "displayName": "dw-harness-ara-cf516524",
      "type": "ServicePrincipal",
      "modifiedProperties": [],
      "administrativeUnits": [],
      "agentType": "notAgentic"
    }
  ]
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sigma #

Kusto #

References #

Remove service principal credentials

#
Source
Microsoft Entra ID audit log
Audit Category
ApplicationManagement

Description

Credentials were removed from a service principal.

Example Audit Log Entry #

{
  "AADOperationType": "Update",
  "AADTenantId": "11111111-1111-1111-1111-111111111111",
  "ActivityDateTime": "2026-07-24T03:20:03.90873Z",
  "ActivityDisplayName": "Remove service principal credentials",
  "AdditionalDetails": [
    {
      "key": "User-Agent",
      "value": "python/3.14.5 (Linux-6.1.0-51-amd64-x86_64-with-glibc2.36) AZURECLI/2.88.0 (DEB)"
    },
    {
      "key": "AppId",
      "value": "0880df21-e1b6-42e5-b399-8840779d78c4"
    },
    {
      "key": "AppOwnerOrganizationId",
      "value": "11111111-1111-1111-1111-111111111111"
    },
    {
      "key": "ServicePrincipalProvisioningType",
      "value": "Other"
    }
  ],
  "Category": "ApplicationManagement",
  "CorrelationId": "479c6b41-32ab-4a83-b02e-2193b98b3452",
  "DurationMs": "0",
  "Id": "Directory_479c6b41-32ab-4a83-b02e-2193b98b3452_BOAS4_10216774",
  "InitiatedBy": {
    "user": {
      "id": "aaaaaaaa-0000-0000-0000-000000000001",
      "displayName": null,
      "userPrincipalName": "adminuser@example.onmicrosoft.com",
      "ipAddress": "203.0.113.10",
      "roles": [],
      "agentType": "notAgentic"
    }
  },
  "LoggedByService": "Core Directory",
  "OperationName": "Remove service principal credentials",
  "OperationVersion": "1.0",
  "Resource": "Microsoft.aadiam",
  "ResourceGroup": "Microsoft.aadiam",
  "ResourceId": "/tenants/11111111-1111-1111-1111-111111111111/providers/Microsoft.aadiam",
  "Result": "success",
  "ResultSignature": "None",
  "TargetResources": [
    {
      "id": "e637b633-f84a-4e3a-9e92-1dda38b7daa0",
      "displayName": "dw-harness-credential-cf516524",
      "type": "ServicePrincipal",
      "modifiedProperties": [
        {
          "displayName": "KeyDescription",
          "oldValue": [
            "[KeyIdentifier=384afc65-9185-49a9-b690-8d4a75bd5609,KeyType=Password,KeyUsage=Verify,DisplayName=dw-harness]"
          ],
          "newValue": []
        },
        {
          "displayName": "Included Updated Properties",
          "oldValue": null,
          "newValue": "\"KeyDescription\""
        }
      ],
      "administrativeUnits": [],
      "agentType": "notAgentic"
    }
  ]
}

References #

Restore application

#
Source
Microsoft Entra ID audit log
Audit Category
ApplicationManagement

Description

A soft-deleted application registration was restored.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

YARA-L #

References #

Update application

#
Source
Microsoft Entra ID audit log
Audit Category
ApplicationManagement

Description

An application registration was modified.

Example Audit Log Entry #

{
  "AADOperationType": "Update",
  "AADTenantId": "11111111-1111-1111-1111-111111111111",
  "ActivityDateTime": "2026-07-24T03:20:17.2567244Z",
  "ActivityDisplayName": "Update application",
  "AdditionalDetails": [
    {
      "key": "User-Agent",
      "value": "python/3.14.5 (Linux-6.1.0-51-amd64-x86_64-with-glibc2.36) AZURECLI/2.88.0 (DEB)"
    },
    {
      "key": "AppId",
      "value": "fa629f38-1390-4d23-a30d-3fcbacadb9d7"
    }
  ],
  "Category": "ApplicationManagement",
  "CorrelationId": "a4ba2b50-7ea5-4cd1-8e91-3ed4e6bc6d4e",
  "DurationMs": "0",
  "Id": "Directory_a4ba2b50-7ea5-4cd1-8e91-3ed4e6bc6d4e_48KOK_10607842",
  "InitiatedBy": {
    "user": {
      "id": "aaaaaaaa-0000-0000-0000-000000000001",
      "displayName": null,
      "userPrincipalName": "adminuser@example.onmicrosoft.com",
      "ipAddress": "203.0.113.10",
      "roles": [],
      "agentType": "notAgentic"
    }
  },
  "LoggedByService": "Core Directory",
  "OperationName": "Update application",
  "OperationVersion": "1.0",
  "Resource": "Microsoft.aadiam",
  "ResourceGroup": "Microsoft.aadiam",
  "ResourceId": "/tenants/11111111-1111-1111-1111-111111111111/providers/Microsoft.aadiam",
  "Result": "success",
  "ResultSignature": "None",
  "TargetResources": [
    {
      "id": "640d643e-4dab-40d1-a674-1d9d715eb1e1",
      "displayName": "dw-harness-extension-cf516524",
      "type": "Application",
      "modifiedProperties": [
        {
          "displayName": "Included Updated Properties",
          "oldValue": null,
          "newValue": "\"\""
        }
      ],
      "administrativeUnits": [],
      "agentType": "notAgentic"
    }
  ]
}

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
AddedUrls (kusto rule field)gt02 ruleskusto
Details (kusto rule field)is_not_null2 ruleskusto
Key (kusto rule field)is_not_null2 ruleskusto
Result (kusto rule field)eqsuccess2 ruleskusto
category (splunk rule field)eqauditlogs2 rulessplunk
displayName (kusto rule field)eqappaddress2 ruleskusto
Domain (kusto rule field)is_not_null1 rulekusto
EntityName (kusto rule field)eqsystemuser1 rulekusto
Message (kusto rule field)eqCreate1 rulekusto
{}.RequiredAppPermissions{}.EntitlementId (splunk rule field)eq06b708a9-e830-4db3-a914-8e69da51d44f1 rulesplunk
{}.RequiredAppPermissions{}.EntitlementId (splunk rule field)eq9e3f62cf-ca93-4989-b6ce-bf83c28f9fe81 rulesplunk
{}.RequiredAppPermissions{}.EntitlementId (splunk rule field)eqdc890d15-9560-4a4c-9b7f-a736ec74ec401 rulesplunk
{}.ResourceAppId (splunk rule field)eq00000002-0000-0ff1-ce00-0000000000001 rulesplunk

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sigma #

Elastic #

  • Entra ID OAuth Application Redirect URI Modified source high: Identifies modifications to OAuth application redirect URIs (ReplyUrls) in Entra ID. Adding an attacker-controlled redirect URI to an existing trusted application allows interception of OAuth authorization codes when users authenticate through that application's normal login flow, enabling token theft without requiring a new application registration or consent event.T1528, T1556
  • Entra ID Federated Identity Credential Issuer Modified source high: Detects when the issuer URL of a federated identity credential is changed on an Entra ID application. Adversaries may modify the issuer to point to an attacker-controlled identity provider, enabling them to authenticate as the application's service principal and gain persistent access to Azure resources. This technique allows bypassing traditional authentication controls by federating trust with a malicious external identity provider.T1098, T1098.001, T1484, T1484.002

Splunk #

Kusto #

YARA-L #

References #

Update application – Certificates and secrets management

#
Source
Microsoft Entra ID audit log
Audit Category
ApplicationManagement

Description

Credentials (certificate or client secret) were added or changed on an application.

Example Audit Log Entry #

{
  "AADOperationType": "Update",
  "AADTenantId": "11111111-1111-1111-1111-111111111111",
  "ActivityDateTime": "2026-07-24T03:20:00.9665677Z",
  "ActivityDisplayName": "Update application – Certificates and secrets management ",
  "AdditionalDetails": [
    {
      "key": "User-Agent",
      "value": "python/3.14.5 (Linux-6.1.0-51-amd64-x86_64-with-glibc2.36) AZURECLI/2.88.0 (DEB)"
    },
    {
      "key": "AppId",
      "value": "0880df21-e1b6-42e5-b399-8840779d78c4"
    }
  ],
  "Category": "ApplicationManagement",
  "CorrelationId": "f9015dc5-d0c5-41e6-974e-ae79e56ddebf",
  "DurationMs": "0",
  "Id": "Directory_f9015dc5-d0c5-41e6-974e-ae79e56ddebf_4Q5OQ_10498338",
  "InitiatedBy": {
    "user": {
      "id": "aaaaaaaa-0000-0000-0000-000000000001",
      "displayName": null,
      "userPrincipalName": "adminuser@example.onmicrosoft.com",
      "ipAddress": "203.0.113.10",
      "roles": [],
      "agentType": "notAgentic"
    }
  },
  "LoggedByService": "Core Directory",
  "OperationName": "Update application – Certificates and secrets management ",
  "OperationVersion": "1.0",
  "Resource": "Microsoft.aadiam",
  "ResourceGroup": "Microsoft.aadiam",
  "ResourceId": "/tenants/11111111-1111-1111-1111-111111111111/providers/Microsoft.aadiam",
  "Result": "success",
  "ResultSignature": "None",
  "TargetResources": [
    {
      "id": "88f127f9-3564-40c4-a3c6-201e448f5d3a",
      "displayName": "dw-harness-credential-cf516524",
      "type": "Application",
      "modifiedProperties": [
        {
          "displayName": "KeyDescription",
          "oldValue": [
            "[KeyIdentifier=d0b56347-2d3a-4658-814d-dde322b4a3a3,KeyType=Password,KeyUsage=Verify,DisplayName=dw-harness]"
          ],
          "newValue": []
        },
        {
          "displayName": "Included Updated Properties",
          "oldValue": null,
          "newValue": "\"KeyDescription\""
        }
      ],
      "administrativeUnits": [],
      "agentType": "notAgentic"
    }
  ]
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sigma #

Elastic #

  • Entra ID Application Credential Modified source medium: Identifies when a new credential is added to an application in Azure. An application may use a certificate or secret string to prove its identity when requesting a token. Multiple certificates and secrets can be added for an application and an adversary may abuse this by creating an additional authentication method to evade defenses or persist in an environment.T1098, T1098.001

References #

Add member to role approval requested (PIM activation)

#
Source
Microsoft Entra ID audit log
Audit Category
ApplicationManagement

Description

A user requested activation of an eligible Microsoft Entra role through Privileged Identity Management, and because the role's settings require approval, an approval was requested from the designated approvers. Detection relevance: PIM activations are just-in-time privilege elevations and warrant monitoring for privilege escalation.

References #

Add member to role in PIM requested (timebound)

#
Source
Microsoft Entra ID audit log
Audit Category
ApplicationManagement

Description

A request was submitted through Privileged Identity Management to create a time-bound (expiring) Microsoft Entra role assignment.

References #

Add policy to application

#
Source
Microsoft Entra ID audit log
Audit Category
ApplicationManagement

Description

Records the assignment of a directory policy (for example a token lifetime, claims-mapping, or home realm discovery policy) to an application object. Attaching a claims-mapping or home-realm-discovery policy to an application can alter that app's issued token claims or federated authentication behavior.

References #

Add policy to service principal

#
Source
Microsoft Entra ID audit log
Audit Category
ApplicationManagement

Description

Records the assignment of a directory policy object to a service principal. Assignable policies include token lifetime, token issuance, claims-mapping, home realm discovery, and app management policies; changes that extend token lifetimes or alter claims or home-realm behavior can support persistence or token manipulation, making this relevant to service-principal abuse monitoring.

References #

Approve request - direct role assignment

#
Source
Microsoft Entra ID audit log
Audit Category
ApplicationManagement

Description

Records an approver approving a Privileged Identity Management request whose outcome is a direct Microsoft Entra role assignment for the requester. Approval of privileged-role requests is directly relevant to privilege-escalation monitoring.

References #

Assign Hardware Oath Token

#
Source
Microsoft Entra ID audit log
Audit Category
ApplicationManagement

Description

Records the assignment of a hardware OATH token (a physical OATH-TOTP code-generating device) to a user as an authentication method. Adding or changing a user's MFA methods is relevant to account-persistence and takeover monitoring, since an attacker-controlled token could be registered to maintain access.

References #

Authentication Methods Policy Reset

#
Source
Microsoft Entra ID audit log
Audit Category
ApplicationManagement

Description

Records a reset of the tenant Authentication methods policy, which governs which authentication and MFA methods users may register and use. The precise scope of the reset was not confirmed by a retrieved Microsoft Learn doc, so the description is held to the operation name, category, and service.

References #

Authentication Strength Combination Configuration Create

#
Source
Microsoft Entra ID audit log
Audit Category
ApplicationManagement

Description

Records the creation of a combination configuration within a custom authentication strength policy, such as restricting allowed FIDO2 security keys by AAGUID or constraining certificate-based methods by issuer or policy OID. Changes to authentication strength enforcement are relevant to monitoring for weakened or altered MFA requirements.

References #

Authentication Strength Combination Configuration Delete

#
Source
Microsoft Entra ID audit log
Audit Category
ApplicationManagement

Description

Records the deletion of a combination configuration from a custom authentication strength policy, for example removing a FIDO2 AAGUID restriction or a certificate issuer/policy-OID constraint. Removing such restrictions can relax which methods satisfy the policy, which is relevant to defense-evasion monitoring.

References #

Authentication Strength Combination Configuration Update

#
Source
Microsoft Entra ID audit log
Audit Category
ApplicationManagement

Description

Records an update to the combination configurations of a Conditional Access authentication strength: the advanced restrictions that limit which credentials satisfy an allowed method combination, such as permitted FIDO2 passkey AAGUIDs or the certificate issuer SKIs and policy OIDs for certificate-based authentication. Loosening these restrictions can weaken an enforced MFA grant control (defense evasion).

References #

Authentication Strength Policy Create

#
Source
Microsoft Entra ID audit log
Audit Category
ApplicationManagement

Description

Records creation of a custom Conditional Access authentication strength policy: a named, admin-defined set of allowed authentication-method combinations that a Conditional Access grant control can require for access to a resource.

References #

Authentication Strength Policy Delete

#
Source
Microsoft Entra ID audit log
Audit Category
ApplicationManagement

Description

Records deletion of a custom Conditional Access authentication strength policy. A strength still referenced by a Conditional Access policy cannot be deleted; removing one that gated access can weaken authentication requirements (defense evasion).

References #

Authentication Strength Policy Update

#
Source
Microsoft Entra ID audit log
Audit Category
ApplicationManagement

Description

Records a modification to an existing custom Conditional Access authentication strength policy, such as changing its name, description, or the set of allowed authentication-method combinations.

References #

Bulk upload Hardware Oath Token

#
Source
Microsoft Entra ID audit log
Audit Category
ApplicationManagement

Description

Records a bulk upload of hardware OATH tokens from a CSV (containing values such as UPN, serial number, and secret key) into Microsoft Entra ID. Registering attacker-controlled OATH tokens can establish multifactor-authentication persistence or enable account takeover.

References #

Cancel application update with safe rollout

#
Source
Microsoft Entra ID audit log
Audit Category
ApplicationManagement

Description

A staged ("safe rollout") update to an application object in the directory was cancelled before it completed. This activity is part of the Core Directory safe-rollout update sequence, alongside the sibling activities "Update application with safe rollout" and "Complete application update after safe rollout".

References #

Complete application update after safe rollout

#
Source
Microsoft Entra ID audit log
Audit Category
ApplicationManagement

Description

A staged ("safe rollout") update to an application object in the directory was finalized and applied. This activity completes the Core Directory safe-rollout update sequence (begun by "Update application with safe rollout").

References #

Create application collection

#
Source
Microsoft Entra ID audit log
Audit Category
ApplicationManagement

Description

An application collection was created on the My Apps portal, grouping selected enterprise applications into a named tab shown to the assigned users and groups. A collection applies a filter to applications a user can already access, so it organizes the end-user app launcher and does not itself grant access to the underlying apps.

References #

Create Certificate

#
Source
Microsoft Entra ID audit log
Audit Category
ApplicationManagement

Description

A certificate was created within Microsoft Entra Global Secure Access. The specific certificate this operation provisions is not confirmed from documentation; one documented use of certificates in Global Secure Access is the intermediate certificate authority that TLS (Transport Layer Security) inspection uses to issue per-site leaf certificates.

References #

Create Hardware Oath Token

#
Source
Microsoft Entra ID audit log
Audit Category
ApplicationManagement

Description

A hardware OATH TOTP token was created (registered) in the tenant for use as a multifactor authentication method. Registration or change of authentication methods is relevant to monitoring for MFA manipulation and persistence.

References #

Delete application collection

#
Source
Microsoft Entra ID audit log
Audit Category
ApplicationManagement

Description

A My Apps collection was deleted. Collections are admin-curated groupings that organize applications into separate tabs on the My Apps portal, so deleting one removes that grouping without changing users' underlying access to the applications.

References #

Delete Certificate

#
Source
Microsoft Entra ID audit log
Audit Category
ApplicationManagement

Description

Records the deletion of a certificate used by Global Secure Access Transport Layer Security (TLS) inspection. This is the certificate Global Secure Access uses to break and inspect encrypted TLS traffic for Microsoft Entra Internet Access; removing it disables or interrupts TLS inspection and the security controls that depend on it.

References #

Delete Hardware Oath Token

#
Source
Microsoft Entra ID audit log
Audit Category
ApplicationManagement

Description

A hardware OATH token was deleted. Hardware OATH tokens are physical OATH-TOTP devices registered as a Microsoft Entra authentication method (currently in preview), so removing one deletes one of a user's MFA methods, which is relevant to MFA tampering and authentication-method weakening.

References #

Hard delete service principal

#
Source
Microsoft Entra ID audit log
Audit Category
ApplicationManagement

Description

Records the permanent, non-recoverable removal of a service principal object from the tenant, either an administrator purging a soft-deleted service principal or the automatic purge after the 30-day soft-delete window. Hard deletion blocks restoration and erases an application's identity, which can be cleanup of an attacker-created or abused app (defense evasion).

References #

MFA Service Policy Update

#
Source
Microsoft Entra ID audit log
Audit Category
ApplicationManagement

Description

Records an update to the tenant's multifactor authentication service policy/settings, logged by the Authentication Methods service. Changes to MFA policy configuration are security-sensitive because they can strengthen or weaken authentication requirements, with relaxed settings being relevant to defense evasion.

References #

PATCH UserAuthMethod.PatchSignInPreferencesAsync

#
Source
Microsoft Entra ID audit log
Audit Category
ApplicationManagement

Description

Records an update (PATCH) to a user's authentication sign-in preferences in Microsoft Entra ID, such as the per-user system-preferred multifactor authentication setting or preferred secondary authentication method. Changes that disable or weaken a user's preferred MFA can be relevant to authentication-control tampering.

References #

PATCH UserAuthMethod.ResetQRPinAsync

#
Source
Microsoft Entra ID audit log
Audit Category
ApplicationManagement

Description

Records an administrator-initiated reset of the PIN for a user's QR code authentication method, which generates a new temporary PIN that the user must change at next sign-in. QR code with PIN is a frontline-worker sign-in method, so resetting another user's PIN is an account-access change worth monitoring.

References #

PATCH UserAuthMethod.UpdateQRPinAsync

#
Source
Microsoft Entra ID audit log
Audit Category
ApplicationManagement

Description

Records an update to the PIN of a user's QR code authentication method, the updatePin operation that changes the current PIN to a new value (used when a user changes their PIN, including the forced change after a reset). QR code with PIN is a frontline-worker authentication method.

References #

PIM activation request expired

#
Source
Microsoft Entra ID audit log
Audit Category
ApplicationManagement

Description

Records that a Privileged Identity Management role-activation request expired before it was completed, for example because a required approval was not granted within the (fixed 24-hour) approval window. The eligible role was therefore not activated.

References #

PIM policy removed

#
Source
Microsoft Entra ID audit log
Audit Category
ApplicationManagement

Description

Records removal of a Privileged Identity Management policy, the role-settings/assignment policy that governs activation requirements (such as MFA on activation, approval, justification, and maximum activation duration) for a role. Removing or weakening PIM policies reduces safeguards around privileged-role activation and is relevant to privilege escalation and defense evasion.

References #

POST UserAuthMethod.SoftwareOathProofupRegistration

#
Source
Microsoft Entra ID audit log
Audit Category
ApplicationManagement

Description

Records the registration (proof-up) of a software OATH (TOTP) token as a multifactor authentication method for a user. Newly registered MFA methods are a known persistence and account-takeover signal, where an actor enrolls their own authenticator to retain access.

References #

Remove app role assignment from service principal

#
Source
Microsoft Entra ID audit log
Audit Category
ApplicationManagement

Description

An app role assignment was removed from a service principal, revoking an application's granted app role (such as an application permission to another resource or API). Removal of app role grants is relevant to monitoring application-permission and consent changes.

Example Audit Log Entry #

{
  "AADOperationType": "Unassign",
  "AADTenantId": "11111111-1111-1111-1111-111111111111",
  "ActivityDateTime": "2026-07-24T03:21:23.1198548Z",
  "ActivityDisplayName": "Remove app role assignment from service principal",
  "AdditionalDetails": [
    {
      "key": "User-Agent",
      "value": "python/3.14.5 (Linux-6.1.0-51-amd64-x86_64-with-glibc2.36) AZURECLI/2.88.0 (DEB)"
    },
    {
      "key": "AppId",
      "value": "0d810552-12c8-4592-99b8-e4fdc0f04f42"
    },
    {
      "key": "ServicePrincipalProvisioningType",
      "value": "Other"
    }
  ],
  "Category": "ApplicationManagement",
  "CorrelationId": "cedd6f16-52c8-4041-8b57-c621c98aa297",
  "DurationMs": "0",
  "Id": "Directory_cedd6f16-52c8-4041-8b57-c621c98aa297_0KIMT_10478958",
  "InitiatedBy": {
    "user": {
      "id": "aaaaaaaa-0000-0000-0000-000000000001",
      "displayName": null,
      "userPrincipalName": "adminuser@example.onmicrosoft.com",
      "ipAddress": "203.0.113.10",
      "roles": [],
      "agentType": "notAgentic"
    }
  },
  "LoggedByService": "Core Directory",
  "OperationName": "Remove app role assignment from service principal",
  "OperationVersion": "1.0",
  "Resource": "Microsoft.aadiam",
  "ResourceGroup": "Microsoft.aadiam",
  "ResourceId": "/tenants/11111111-1111-1111-1111-111111111111/providers/Microsoft.aadiam",
  "Result": "success",
  "ResultSignature": "None",
  "TargetResources": [
    {
      "id": "f543a660-eb12-47b5-9af6-2948b5efb45c",
      "displayName": "dw-harness-ara-cf516524",
      "type": "ServicePrincipal",
      "modifiedProperties": [
        {
          "displayName": "AppRole.Id",
          "oldValue": "\"4fd7fe7b-8dc6-5774-8691-a09576fcb161\"",
          "newValue": null
        },
        {
          "displayName": "AppRole.Value",
          "oldValue": null,
          "newValue": null
        },
        {
          "displayName": "AppRole.DisplayName",
          "oldValue": null,
          "newValue": null
        },
        {
          "displayName": "AppRoleAssignment.CreatedDateTime",
          "oldValue": "\"2026-07-24T03:21:21.8105676Z\"",
          "newValue": null
        },
        {
          "displayName": "AppRoleAssignment.LastModifiedDateTime",
          "oldValue": "\"2026-07-24T03:21:21.8105676Z\"",
          "newValue": null
        },
        {
          "displayName": "ServicePrincipal.ObjectID",
          "oldValue": "\"f543a660-eb12-47b5-9af6-2948b5efb45c\"",
          "newValue": null
        },
        {
          "displayName": "ServicePrincipal.DisplayName",
          "oldValue": "\"dw-harness-ara-cf516524\"",
          "newValue": null
        },
        {
          "displayName": "ServicePrincipal.AppId",
          "oldValue": null,
          "newValue": "\"0d810552-12c8-4592-99b8-e4fdc0f04f42\""
        },
        {
          "displayName": "ServicePrincipal.Name",
          "oldValue": null,
          "newValue": "\"0d810552-12c8-4592-99b8-e4fdc0f04f42\""
        },
        {
          "displayName": "TargetId.ServicePrincipalNames",
          "oldValue": null,
          "newValue": "\"0d810552-12c8-4592-99b8-e4fdc0f04f42\""
        }
      ],
      "administrativeUnits": [],
      "agentType": "notAgentic"
    },
    {
      "id": "f543a660-eb12-47b5-9af6-2948b5efb45c",
      "displayName": "0d810552-12c8-4592-99b8-e4fdc0f04f42",
      "type": "ServicePrincipal",
      "modifiedProperties": [],
      "administrativeUnits": [],
      "agentType": "notAgentic"
    }
  ]
}

References #

Remove delegated permission grant

#
Source
Microsoft Entra ID audit log
Audit Category
ApplicationManagement

Description

An OAuth2 delegated permission grant was deleted, revoking the delegated API permissions it had granted to an application; existing access tokens stay valid until they expire but no new tokens are issued for those scopes. Tracking grant removals supports OAuth consent-grant and application-permission auditing.

Example Audit Log Entry #

{
  "AADOperationType": "Unassign",
  "AADTenantId": "11111111-1111-1111-1111-111111111111",
  "ActivityDateTime": "2026-07-24T03:20:31.0771685Z",
  "ActivityDisplayName": "Remove delegated permission grant",
  "AdditionalDetails": [
    {
      "key": "User-Agent",
      "value": "python/3.14.5 (Linux-6.1.0-51-amd64-x86_64-with-glibc2.36) AZURECLI/2.88.0 (DEB)"
    },
    {
      "key": "AppId",
      "value": "00000003-0000-0000-c000-000000000000"
    },
    {
      "key": "ServicePrincipalProvisioningType",
      "value": "Other"
    }
  ],
  "Category": "ApplicationManagement",
  "CorrelationId": "66b9b854-394f-4097-8771-7d4663a4a169",
  "DurationMs": "0",
  "Id": "Directory_66b9b854-394f-4097-8771-7d4663a4a169_1PR04_10689729",
  "InitiatedBy": {
    "user": {
      "id": "aaaaaaaa-0000-0000-0000-000000000001",
      "displayName": null,
      "userPrincipalName": "adminuser@example.onmicrosoft.com",
      "ipAddress": "203.0.113.10",
      "roles": [],
      "agentType": "notAgentic"
    }
  },
  "LoggedByService": "Core Directory",
  "OperationName": "Remove delegated permission grant",
  "OperationVersion": "1.0",
  "Resource": "Microsoft.aadiam",
  "ResourceGroup": "Microsoft.aadiam",
  "ResourceId": "/tenants/11111111-1111-1111-1111-111111111111/providers/Microsoft.aadiam",
  "Result": "success",
  "ResultSignature": "None",
  "TargetResources": [
    {
      "id": "2e5ab30e-ae89-43c2-b130-0022f3d655a7",
      "displayName": "Microsoft Graph",
      "type": "ServicePrincipal",
      "modifiedProperties": [
        {
          "displayName": "DelegatedPermissionGrant.Scope",
          "oldValue": "\"User.Read\"",
          "newValue": null
        },
        {
          "displayName": "DelegatedPermissionGrant.ConsentType",
          "oldValue": "\"Principal\"",
          "newValue": null
        },
        {
          "displayName": "ServicePrincipal.ObjectID",
          "oldValue": "\"af2cee02-3ad4-4486-85a2-e8eafc78cd6e\"",
          "newValue": null
        },
        {
          "displayName": "ServicePrincipal.DisplayName",
          "oldValue": null,
          "newValue": null
        },
        {
          "displayName": "ServicePrincipal.AppId",
          "oldValue": null,
          "newValue": null
        },
        {
          "displayName": "ServicePrincipal.Name",
          "oldValue": null,
          "newValue": null
        },
        {
          "displayName": "TargetId.ServicePrincipalNames",
          "oldValue": null,
          "newValue": "\"00000003-0000-0000-c000-000000000000/ags.windows.net;00000003-0000-0000-c000-000000000000;https://canary.graph.microsoft.com;https://graph.microsoft.com;https://ags.windows.net;https://graph.microsoft.us;https://graph.microsoft.com/;https://dod-graph.microsoft.us;https://canary.graph.microsoft.com/;https://graph.microsoft.us/;https://dod-graph.microsoft.us/\""
        }
      ],
      "administrativeUnits": [],
      "agentType": "notAgentic"
    },
    {
      "id": "af2cee02-3ad4-4486-85a2-e8eafc78cd6e",
      "displayName": null,
      "type": "ServicePrincipal",
      "modifiedProperties": [],
      "administrativeUnits": [],
      "agentType": "notAgentic"
    }
  ]
}

References #

Remove member from role in PIM completed (timebound)

#
Source
Microsoft Entra ID audit log
Audit Category
ApplicationManagement

Description

Records Privileged Identity Management completing removal of a member's time-bound (expiring) role assignment. It pairs with the corresponding 'requested' entry for the same change.

References #

Remove owner from application

#
Source
Microsoft Entra ID audit log
Audit Category
ApplicationManagement

Description

Records removal of an owner from an application in Microsoft Entra ID. An application owner can manage the app's organization-specific configuration (such as single sign-on, provisioning, and user assignment) and can add or remove other owners, so ownership changes affect who controls the application; monitor to avoid ownerless apps and loss of accountability.

Example Audit Log Entry #

{
  "AADOperationType": "Unassign",
  "AADTenantId": "11111111-1111-1111-1111-111111111111",
  "ActivityDateTime": "2026-07-24T03:20:09.3763462Z",
  "ActivityDisplayName": "Remove owner from application",
  "AdditionalDetails": [
    {
      "key": "User-Agent",
      "value": "python/3.14.5 (Linux-6.1.0-51-amd64-x86_64-with-glibc2.36) AZURECLI/2.88.0 (DEB)"
    }
  ],
  "Category": "ApplicationManagement",
  "CorrelationId": "2111c558-893f-4cba-b426-959c7f9c95d8",
  "DurationMs": "0",
  "Id": "Directory_2111c558-893f-4cba-b426-959c7f9c95d8_A2Q6L_10306340",
  "InitiatedBy": {
    "user": {
      "id": "aaaaaaaa-0000-0000-0000-000000000001",
      "displayName": null,
      "userPrincipalName": "adminuser@example.onmicrosoft.com",
      "ipAddress": "203.0.113.10",
      "roles": [],
      "agentType": "notAgentic"
    }
  },
  "LoggedByService": "Core Directory",
  "OperationName": "Remove owner from application",
  "OperationVersion": "1.0",
  "Resource": "Microsoft.aadiam",
  "ResourceGroup": "Microsoft.aadiam",
  "ResourceId": "/tenants/11111111-1111-1111-1111-111111111111/providers/Microsoft.aadiam",
  "Result": "success",
  "ResultSignature": "None",
  "TargetResources": [
    {
      "id": "aaaaaaaa-0000-0000-0000-000000000001",
      "displayName": null,
      "type": "User",
      "userPrincipalName": "adminuser@example.onmicrosoft.com",
      "modifiedProperties": [
        {
          "displayName": "Application.ObjectID",
          "oldValue": "\"d5dcc899-cc10-4152-93d9-ecaa990c016e\"",
          "newValue": null
        },
        {
          "displayName": "Application.DisplayName",
          "oldValue": "\"dw-harness-owner-cf516524\"",
          "newValue": null
        },
        {
          "displayName": "Application.AppId",
          "oldValue": null,
          "newValue": "\"af83d2a0-7c27-4e07-849a-41886ab13674\""
        }
      ],
      "administrativeUnits": [],
      "agentType": "notAgentic"
    },
    {
      "id": "d5dcc899-cc10-4152-93d9-ecaa990c016e",
      "displayName": null,
      "type": "Application",
      "modifiedProperties": [],
      "administrativeUnits": [],
      "agentType": "notAgentic"
    }
  ]
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sigma #

References #

Remove owner from service principal

#
Source
Microsoft Entra ID audit log
Audit Category
ApplicationManagement

Description

Records that an owner was removed from a service principal (enterprise application), revoking that principal's ability to manage the application's configuration and credentials. Because service principal owners can add credentials, ownership changes are relevant to application persistence and privilege monitoring.

Example Audit Log Entry #

{
  "AADOperationType": "Unassign",
  "AADTenantId": "11111111-1111-1111-1111-111111111111",
  "ActivityDateTime": "2026-07-24T03:20:12.7447299Z",
  "ActivityDisplayName": "Remove owner from service principal",
  "AdditionalDetails": [
    {
      "key": "User-Agent",
      "value": "python/3.14.5 (Linux-6.1.0-51-amd64-x86_64-with-glibc2.36) AZURECLI/2.88.0 (DEB)"
    }
  ],
  "Category": "ApplicationManagement",
  "CorrelationId": "4094afcb-147b-4a94-b658-61a8b89c9b9a",
  "DurationMs": "0",
  "Id": "Directory_4094afcb-147b-4a94-b658-61a8b89c9b9a_H7NJ3_564939",
  "InitiatedBy": {
    "user": {
      "id": "aaaaaaaa-0000-0000-0000-000000000001",
      "displayName": null,
      "userPrincipalName": "adminuser@example.onmicrosoft.com",
      "ipAddress": "203.0.113.10",
      "roles": [],
      "agentType": "notAgentic"
    }
  },
  "LoggedByService": "Core Directory",
  "OperationName": "Remove owner from service principal",
  "OperationVersion": "1.0",
  "Resource": "Microsoft.aadiam",
  "ResourceGroup": "Microsoft.aadiam",
  "ResourceId": "/tenants/11111111-1111-1111-1111-111111111111/providers/Microsoft.aadiam",
  "Result": "success",
  "ResultSignature": "None",
  "TargetResources": [
    {
      "id": "aaaaaaaa-0000-0000-0000-000000000001",
      "displayName": null,
      "type": "User",
      "userPrincipalName": "adminuser@example.onmicrosoft.com",
      "modifiedProperties": [
        {
          "displayName": "ServicePrincipal.ObjectID",
          "oldValue": "\"11c4b230-304b-422e-b8fb-a2b507982bd6\"",
          "newValue": null
        },
        {
          "displayName": "ServicePrincipal.DisplayName",
          "oldValue": "\"dw-harness-owner-cf516524\"",
          "newValue": null
        },
        {
          "displayName": "ServicePrincipal.AppId",
          "oldValue": null,
          "newValue": "\"af83d2a0-7c27-4e07-849a-41886ab13674\""
        },
        {
          "displayName": "ServicePrincipal.Name",
          "oldValue": null,
          "newValue": "\"af83d2a0-7c27-4e07-849a-41886ab13674\""
        }
      ],
      "administrativeUnits": [],
      "agentType": "notAgentic"
    },
    {
      "id": "11c4b230-304b-422e-b8fb-a2b507982bd6",
      "displayName": "af83d2a0-7c27-4e07-849a-41886ab13674",
      "type": "ServicePrincipal",
      "modifiedProperties": [],
      "administrativeUnits": [],
      "agentType": "notAgentic"
    }
  ]
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sigma #

References #

Remove policy from application

#
Source
Microsoft Entra ID audit log
Audit Category
ApplicationManagement

Description

Records that a policy (such as a token lifetime, claims-mapping, or home-realm-discovery policy) was detached from an application object, removing that policy's enforcement for the application.

References #

Remove policy from service principal

#
Source
Microsoft Entra ID audit log
Audit Category
ApplicationManagement

Description

Records that a policy (such as a token lifetime, claims-mapping, or home-realm-discovery policy) was detached from a service principal, removing that policy's enforcement for the enterprise application.

References #

Remove request

#
Source
Microsoft Entra ID audit log
Audit Category
ApplicationManagement

Description

Records that a pending Privileged Identity Management assignment request was removed (canceled) before completion.

References #

Restore consent

#
Source
Microsoft Entra ID audit log
Audit Category
ApplicationManagement

Restore service principal

#
Source
Microsoft Entra ID audit log
Audit Category
ApplicationManagement

Description

A soft-deleted service principal (enterprise application) was restored from the directory recycle bin within the 30-day recovery window, recovering its prior configuration except policies such as Conditional Access. Restoring an application identity can re-establish access or persistence and is relevant to defense-evasion monitoring.

References #

Role definition created

#
Source
Microsoft Entra ID audit log
Audit Category
ApplicationManagement

Description

A role definition (typically a custom role) was created in Privileged Identity Management, defining a role and the permissions it grants. Creating a role definition with elevated permissions is relevant to privilege-escalation and persistence monitoring.

References #

Set verified publisher

#
Source
Microsoft Entra ID audit log
Audit Category
ApplicationManagement

Description

An application registration was marked with a verified publisher, associating a verified Microsoft partner (Partner ID / MPN) with the app. The verified-publisher status lends legitimacy in consent prompts, so unexpected changes are relevant to consent-phishing and app-impersonation monitoring.

References #

Unset verified publisher

#
Source
Microsoft Entra ID audit log
Audit Category
ApplicationManagement

Description

Records that the verified-publisher status (the Microsoft AI Cloud Partner Program, formerly Microsoft Partner Network/MPN, association) was removed from an app registration, clearing its publisher-verified indication. Because verified-publisher status shapes user and admin trust during consent, removing it or its presence on a malicious app is relevant to illicit-consent and app-impersonation analysis.

References #

Update application collection

#
Source
Microsoft Entra ID audit log
Audit Category
ApplicationManagement

Description

Records modification of an application collection on the My Apps portal, a grouping of applications presented to users on a separate tab. A collection filters the apps a user already has access to, so the change affects presentation rather than granting access.

References #

Update application collection order

#
Source
Microsoft Entra ID audit log
Audit Category
ApplicationManagement

Description

Records a change to the display order of application collections shown to users in the Microsoft Entra My Apps portal. Collections group related applications onto separate tabs in that portal; this operation records a change to the order in which the collections are presented.

References #

Update application with safe rollout

#
Source
Microsoft Entra ID audit log
Audit Category
ApplicationManagement

Description

Records an update to an application object in the directory that is applied through a safe (staged) rollout mechanism. The audit name does not by itself identify which application properties changed.

References #

Update Certificate

#
Source
Microsoft Entra ID audit log
Audit Category
ApplicationManagement

Description

Records an update to a certificate associated with a Microsoft Entra Global Secure Access configuration. Global Secure Access writes configuration changes to the Entra audit logs, so this entry supports monitoring of certificate changes within a Global Secure Access deployment. The specific certificate object is not named in current Global Secure Access documentation.

References #

Update external secrets

#
Source
Microsoft Entra ID audit log
Audit Category
ApplicationManagement

Description

The external secrets tied to an application or service principal were updated. These are credential secrets an application uses to authenticate to an external system (for example, the synchronization secrets configured for Microsoft Entra application provisioning), so the event can indicate routine credential rotation or, if unexpected, a path to persistence or data access through a connected system.

References #

Update Hardware Oath Token

#
Source
Microsoft Entra ID audit log
Audit Category
ApplicationManagement

Description

Records a change to a hardware OATH token (a physical device that generates time-based one-time passcodes) used as a Microsoft Entra MFA method, such as assigning, activating, or modifying the token for a user under the Authentication methods policy. Tampering with a user's registered authentication methods can indicate MFA manipulation for account persistence.

References #

Update preview settings

#
Source
Microsoft Entra ID audit log
Audit Category
ApplicationManagement

Description

My Apps portal preview settings were updated, opting the tenant in or out of preview features for the app-launcher end-user experience.

References #

Update service principal

#
Source
Microsoft Entra ID audit log
Audit Category
ApplicationManagement

Description

A service principal (the tenant-local representation of an application) was modified, such as a change to its properties, credentials, or tags. Adding credentials to a service principal is a recognized persistence and privilege-escalation technique, so these changes warrant review.

Example Audit Log Entry #

{
  "AADOperationType": "Update",
  "AADTenantId": "11111111-1111-1111-1111-111111111111",
  "ActivityDateTime": "2026-07-24T03:20:12.6857283Z",
  "ActivityDisplayName": "Update service principal",
  "AdditionalDetails": [
    {
      "key": "User-Agent",
      "value": "python/3.14.5 (Linux-6.1.0-51-amd64-x86_64-with-glibc2.36) AZURECLI/2.88.0 (DEB)"
    },
    {
      "key": "AppId",
      "value": "af83d2a0-7c27-4e07-849a-41886ab13674"
    },
    {
      "key": "AppOwnerOrganizationId",
      "value": "11111111-1111-1111-1111-111111111111"
    },
    {
      "key": "ServicePrincipalProvisioningType",
      "value": "Other"
    }
  ],
  "Category": "ApplicationManagement",
  "CorrelationId": "4094afcb-147b-4a94-b658-61a8b89c9b9a",
  "DurationMs": "0",
  "Id": "Directory_4094afcb-147b-4a94-b658-61a8b89c9b9a_H7NJ3_564904",
  "InitiatedBy": {
    "user": {
      "id": "aaaaaaaa-0000-0000-0000-000000000001",
      "displayName": null,
      "userPrincipalName": "adminuser@example.onmicrosoft.com",
      "ipAddress": "203.0.113.10",
      "roles": [],
      "agentType": "notAgentic"
    }
  },
  "LoggedByService": "Core Directory",
  "OperationName": "Update service principal",
  "OperationVersion": "1.0",
  "Resource": "Microsoft.aadiam",
  "ResourceGroup": "Microsoft.aadiam",
  "ResourceId": "/tenants/11111111-1111-1111-1111-111111111111/providers/Microsoft.aadiam",
  "Result": "success",
  "ResultSignature": "None",
  "TargetResources": [
    {
      "id": "11c4b230-304b-422e-b8fb-a2b507982bd6",
      "displayName": "dw-harness-owner-cf516524",
      "type": "ServicePrincipal",
      "modifiedProperties": [
        {
          "displayName": "Included Updated Properties",
          "oldValue": null,
          "newValue": "\"\""
        }
      ],
      "administrativeUnits": [],
      "agentType": "notAgentic"
    }
  ]
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sigma #

References #

Create application – Certificates and secrets management

#
Source
Microsoft Entra ID audit log
Audit Category
ApplicationManagement

Description

A certificate or client-secret credential was added to an application via the Certificates & secrets blade (the add counterpart of the Update form on event 12000073).

Example Audit Log Entry #

{
  "AADOperationType": "Add",
  "AADTenantId": "11111111-1111-1111-1111-111111111111",
  "ActivityDateTime": "2026-07-24T03:21:14.4410905Z",
  "ActivityDisplayName": "Create application – Certificates and secrets management ",
  "AdditionalDetails": [
    {
      "key": "User-Agent",
      "value": "python/3.14.5 (Linux-6.1.0-51-amd64-x86_64-with-glibc2.36) AZURECLI/2.88.0 (DEB)"
    },
    {
      "key": "AppId",
      "value": "0d810552-12c8-4592-99b8-e4fdc0f04f42"
    }
  ],
  "Category": "ApplicationManagement",
  "CorrelationId": "206705f7-3a5d-4fcd-a5e3-3b5bf179ca08",
  "DurationMs": "0",
  "Id": "Directory_206705f7-3a5d-4fcd-a5e3-3b5bf179ca08_YYEKK_10369120",
  "InitiatedBy": {
    "user": {
      "id": "aaaaaaaa-0000-0000-0000-000000000001",
      "displayName": null,
      "userPrincipalName": "adminuser@example.onmicrosoft.com",
      "ipAddress": "203.0.113.10",
      "roles": [],
      "agentType": "notAgentic"
    }
  },
  "LoggedByService": "Core Directory",
  "OperationName": "Create application – Certificates and secrets management ",
  "OperationVersion": "1.0",
  "Resource": "Microsoft.aadiam",
  "ResourceGroup": "Microsoft.aadiam",
  "ResourceId": "/tenants/11111111-1111-1111-1111-111111111111/providers/Microsoft.aadiam",
  "Result": "success",
  "ResultSignature": "None",
  "TargetResources": [
    {
      "id": "8f6edab2-5e40-49e7-bc95-5d1f4d278db5",
      "displayName": "dw-harness-ara-cf516524",
      "type": "Application",
      "modifiedProperties": [
        {
          "displayName": "KeyDescription",
          "oldValue": [],
          "newValue": []
        },
        {
          "displayName": "Included Updated Properties",
          "oldValue": null,
          "newValue": "\"KeyDescription\""
        }
      ],
      "administrativeUnits": [],
      "agentType": "notAgentic"
    }
  ]
}

References #

Rules often query computed field names, not native AuditLogs columns #

Many Entra detection rules pivot on field names that are not columns in this table but KQL projections the rule author computes from two dynamic columns. Searching the field list for those names finds nothing; use the canonical paths instead.

  • InitiatingUserPrincipalName (and sibling Initiating* names) is not a column. Rules project it from InitiatedBy, for example extend InitiatingUserPrincipalName = tostring(InitiatedBy.user.userPrincipalName). The native paths are InitiatedBy.user.userPrincipalName, InitiatedBy.user.displayName, and InitiatedBy.user.id for user actors, and InitiatedBy.app.displayName / InitiatedBy.app.appId for application or service-principal actors.
  • What changed lives in TargetResources, a dynamic array. Expand it before filtering on the change: AuditLogs | mv-expand TargetResources | extend props = TargetResources.modifiedProperties, then read props[].displayName, props[].oldValue, and props[].newValue.

Column shapes per the AuditLogs table reference and the Graph directoryAudit resource.