Audit Logs / Microsoft Entra ID AuditLogs category

Audit Logs: RoleManagement

OperationNameDescriptionSampleRule
Add eligible member (eligible)A principal was assigned eligible for a role through PIM.NY
Add eligible member (permanent)A principal was assigned a permanent eligible role through PIM.NY
Add eligible member to roleA principal was made eligible for a directory role via PIM.NY
Add eligible member to role in PIM completed (permanent)A permanent PIM role-eligibility assignment completed.NY
Add member to roleA principal was added as a permanent member of a directory role (privileged role assignment).YY
Add member to role completed (PIM activation)A PIM-eligible role activation completed, granting the role for the activation window.NY
Add member to role in PIM completed (timebound)A time-bound PIM role assignment completed.NY
Add member to role in PIM requested (permanent)A permanent PIM role assignment was requested.NY
Add member to role outside of PIM (permanent)A permanent directory-role assignment was made directly, bypassing PIM (no just-in-time activation).NY
Add member to role request denied (PIM activation)A PIM role activation request was denied.NY
Add role definitionA custom directory role definition was created.YN
Remove member from roleA principal was removed from a directory role.YN
Update role definitionA custom directory role definition was modified.YN
Update role setting in PIMPIM role settings (activation duration, approval, MFA requirement) were changed.NY
Add EligibleRoleAssignment to RoleDefinitionAn eligible role assignment was added to a Microsoft Entra role definition (a principal made eligible for a directory role).NN
Add member to role scoped over Restricted Management Administrative UnitA directory role was assigned with scope over a restricted management administrative unit (RMAU).NN
Add role assignment to role definitionCreates an Entra role assignment binding a principal to a role definition, granting that role's permissions.NN
Add role from templateActivates a built-in directory role in the tenant from its role template, making the role assignable.YN
Add scoped member to roleAdds a member to a directory role scoped to an administrative unit (scopedRoleMembership).NY
Delete role definitionDeletion of a Microsoft Entra (RBAC) role definition: a collection of directory permissions.YN
Refresh PIM alertA Privileged Identity Management security alert was refreshed, re-evaluating it against current role state.NN
Remove eligible member from roleA principal's eligible assignment to a Microsoft Entra directory role (PIM) was removed.NN
Remove EligibleRoleAssignment from RoleDefinitionAn eligible role assignment was removed from a Microsoft Entra role definition (PIM eligibility).NN
Remove member from role scoped over Restricted Management Administrative UnitRemoval of a role assignment scoped to a restricted management administrative unit, changing who can manage its protected objects.NN
Remove role assignment from role definitionA role assignment was removed from a Microsoft Entra role definition, revoking the principal's directory role.NN
Remove scoped member from roleA scoped (administrative-unit) role member was removed from a Microsoft Entra role, revoking the principal's scoped role.NN
Update PIM alert settingA PIM security-alert setting for Microsoft Entra roles was updated.NN
Update roleA directory role object was updated (role definition or properties changed).YN

Add eligible member (eligible)

#
Source
Microsoft Entra ID audit log
Audit Category
RoleManagement

Description

A principal was assigned eligible for a role through PIM.

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
RoleName (kusto rule field)containsadmin1 rulekusto
displayName (kusto rule field)eqrole.displayname1 rulekusto

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sigma #

Kusto #

References #

Add eligible member (permanent)

#
Source
Microsoft Entra ID audit log
Audit Category
RoleManagement

Description

A principal was assigned a permanent eligible role through PIM.

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
RoleName (kusto rule field)containsadmin1 rulekusto
displayName (kusto rule field)eqrole.displayname1 rulekusto

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sigma #

Kusto #

References #

Add eligible member to role

#
Source
Microsoft Entra ID audit log
Audit Category
RoleManagement

Description

A principal was made eligible for a directory role via PIM.

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
GroupName (kusto rule field)inprivilegedauthenticationadmins2 ruleskusto
GroupName (kusto rule field)inprivilegedroleadmins2 ruleskusto
GroupName (kusto rule field)intenantadmins2 ruleskusto
GroupName (kusto rule field)inuseraccountadmins2 ruleskusto
displayName (kusto rule field)eqrole.wellknownobjectname2 ruleskusto

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sigma #

Kusto #

References #

Add eligible member to role in PIM completed (permanent)

#
Source
Microsoft Entra ID audit log
Audit Category
RoleManagement

Description

A permanent PIM role-eligibility assignment completed.

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
azure.auditlogs.properties.category (elastic rule field)eqrolemanagement1 ruleelastic

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

References #

Add member to role

#
Source
Microsoft Entra ID audit log
Audit Category
RoleManagement

Description

A principal was added as a permanent member of a directory role (privileged role assignment).

Example Audit Log Entry #

{
  "AADOperationType": "Assign",
  "AADTenantId": "11111111-1111-1111-1111-111111111111",
  "ActivityDateTime": "2026-07-24T03:20:25.4700984Z",
  "ActivityDisplayName": "Add member to role",
  "AdditionalDetails": [
    {
      "key": "User-Agent",
      "value": "python/3.14.5 (Linux-6.1.0-51-amd64-x86_64-with-glibc2.36) AZURECLI/2.88.0 (DEB)"
    }
  ],
  "Category": "RoleManagement",
  "CorrelationId": "d4fbecff-ca91-4e4f-bee6-d3544d0f7ec5",
  "DurationMs": "0",
  "Id": "Directory_d4fbecff-ca91-4e4f-bee6-d3544d0f7ec5_ATINI_154963444",
  "InitiatedBy": {
    "user": {
      "id": "aaaaaaaa-0000-0000-0000-000000000001",
      "displayName": null,
      "userPrincipalName": "adminuser@example.onmicrosoft.com",
      "ipAddress": "203.0.113.10",
      "roles": [],
      "agentType": "notAgentic"
    }
  },
  "LoggedByService": "Core Directory",
  "OperationName": "Add member to role",
  "OperationVersion": "1.0",
  "Resource": "Microsoft.aadiam",
  "ResourceGroup": "Microsoft.aadiam",
  "ResourceId": "/tenants/11111111-1111-1111-1111-111111111111/providers/Microsoft.aadiam",
  "Result": "success",
  "ResultSignature": "None",
  "TargetResources": [
    {
      "id": "aaaaaaaa-0000-0000-0000-000000000001",
      "displayName": null,
      "type": "User",
      "userPrincipalName": "adminuser@example.onmicrosoft.com",
      "modifiedProperties": [
        {
          "displayName": "Role.ObjectID",
          "oldValue": null,
          "newValue": "\"ba4b3989-6c3a-4095-bec6-a973070cfa28\""
        },
        {
          "displayName": "Role.DisplayName",
          "oldValue": null,
          "newValue": "\"Directory Readers\""
        },
        {
          "displayName": "Role.TemplateId",
          "oldValue": null,
          "newValue": "\"88d8e3e3-8f55-4a1e-953a-9b9898b8876b\""
        },
        {
          "displayName": "Role.WellKnownObjectName",
          "oldValue": null,
          "newValue": "\"DirectoryReaders\""
        }
      ],
      "administrativeUnits": [],
      "agentType": "notAgentic"
    },
    {
      "id": "ba4b3989-6c3a-4095-bec6-a973070cfa28",
      "displayName": null,
      "type": "Role",
      "modifiedProperties": [],
      "administrativeUnits": [],
      "agentType": "notAgentic"
    }
  ]
}

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
type (kusto rule field)equser5 ruleskusto
GroupName (kusto rule field)inprivilegedroleadmins3 ruleskusto
GroupName (kusto rule field)intenantadmins3 ruleskusto
GroupName (kusto rule field)inuseraccountadmins3 ruleskusto
GroupName (kusto rule field)inprivilegedauthenticationadmins2 ruleskusto
displayName (kusto rule field)eqrole.wellknownobjectname3 ruleskusto
displayName (kusto rule field)eqrole.displayname1 rulekusto
Identity (kusto rule field)neMS-PIM2 ruleskusto
Identity (kusto rule field)neMS-PIM-Fairfax2 ruleskusto
azure_ad::logged_by_service (kusto rule field)eqcore directory2 ruleskusto
isprvilegedadrole (splunk rule field)eqtrue2 rulessplunk
RoleName (kusto rule field)containsadmin1 rulekusto
azure.auditlogs.properties.category (elastic rule field)eqrolemanagement1 ruleelastic

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sigma #

Elastic #

  • Entra ID Global Administrator Role Assigned source high: In Microsoft Entra ID, permissions to manage resources are assigned using roles. The Global Administrator is a role that enables users to have access to all administrative features in Microsoft Entra ID and services that use Microsoft Entra ID identities like the Microsoft 365 Defender portal, the Microsoft 365 compliance center, Exchange, SharePoint Online, and Skype for Business Online. Attackers can add users as Global Administrators to maintain access and manage all subscriptions and their settings and resources. They can also elevate privilege to User Access Administrator to pivot into Azure resources.T1098, T1098.003

Splunk #

Kusto #

YARA-L #

References #

Add member to role completed (PIM activation)

#
Source
Microsoft Entra ID audit log
Audit Category
RoleManagement

Description

A PIM-eligible role activation completed, granting the role for the activation window.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Splunk #

  • Azure AD PIM Role Assignment Activated source: The following analytic detects the activation of an Azure AD Privileged Identity Management (PIM) role. It leverages Azure Active Directory events to identify when a user activates a PIM role assignment, indicated by the "Add member to…T1098, T1098.003

Kusto #

References #

Add member to role in PIM completed (timebound)

#
Source
Microsoft Entra ID audit log
Audit Category
RoleManagement

Description

A time-bound PIM role assignment completed.

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
azure.auditlogs.properties.category (elastic rule field)eqrolemanagement1 ruleelastic

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

References #

Add member to role in PIM requested (permanent)

#
Source
Microsoft Entra ID audit log
Audit Category
RoleManagement

Description

A permanent PIM role assignment was requested.

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
GroupName (kusto rule field)inprivilegedroleadmins1 rulekusto
GroupName (kusto rule field)intenantadmins1 rulekusto
GroupName (kusto rule field)inuseraccountadmins1 rulekusto
displayName (kusto rule field)eqrole.wellknownobjectname1 rulekusto

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Kusto #

References #

Add member to role outside of PIM (permanent)

#
Source
Microsoft Entra ID audit log
Audit Category
RoleManagement

Description

A permanent directory-role assignment was made directly, bypassing PIM (no just-in-time activation).

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

YARA-L #

References #

Add member to role request denied (PIM activation)

#
Source
Microsoft Entra ID audit log
Audit Category
RoleManagement

Description

A PIM role activation request was denied.

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
type (kusto rule field)eqrole3 ruleskusto
user (kusto rule field)is_not_null3 ruleskusto

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Kusto #

References #

Add role definition

#
Source
Microsoft Entra ID audit log
Audit Category
RoleManagement

Description

A custom directory role definition was created.

Example Audit Log Entry #

{
  "AADOperationType": "Add",
  "AADTenantId": "11111111-1111-1111-1111-111111111111",
  "ActivityDateTime": "2026-07-24T03:20:51.283922Z",
  "ActivityDisplayName": "Add role definition",
  "AdditionalDetails": [
    {
      "key": "User-Agent",
      "value": "python/3.14.5 (Linux-6.1.0-51-amd64-x86_64-with-glibc2.36) AZURECLI/2.88.0 (DEB)"
    }
  ],
  "Category": "RoleManagement",
  "CorrelationId": "a377d513-0a87-4e77-bb23-7def95c95ad9",
  "DurationMs": "0",
  "Id": "Directory_a377d513-0a87-4e77-bb23-7def95c95ad9_V8SQ4_147870800",
  "InitiatedBy": {
    "user": {
      "id": "aaaaaaaa-0000-0000-0000-000000000001",
      "displayName": null,
      "userPrincipalName": "adminuser@example.onmicrosoft.com",
      "ipAddress": "203.0.113.10",
      "roles": [],
      "agentType": "notAgentic"
    }
  },
  "LoggedByService": "Core Directory",
  "OperationName": "Add role definition",
  "OperationVersion": "1.0",
  "Resource": "Microsoft.aadiam",
  "ResourceGroup": "Microsoft.aadiam",
  "ResourceId": "/tenants/11111111-1111-1111-1111-111111111111/providers/Microsoft.aadiam",
  "Result": "success",
  "ResultSignature": "None",
  "TargetResources": [
    {
      "id": "ff657eed-4940-4bcf-96ac-79e9076c4914",
      "displayName": "dw-harness-role-cf516524",
      "type": "Other",
      "modifiedProperties": [
        {
          "displayName": "DisplayName",
          "oldValue": [],
          "newValue": [
            "dw-harness-role-cf516524"
          ]
        },
        {
          "displayName": "GrantedPermissions",
          "oldValue": [],
          "newValue": [
            {
              "Actions": [
                {
                  "ResourceCategory": "AadDirectory",
                  "ResourceType": "Group",
                  "TaskType": "Read",
                  "ReadPropertySet": "Basic",
                  "WritePropertySet": "None",
                  "TaskTypeSubsetName": null
                }
              ],
              "Condition": null,
              "ScopeConstraints": [],
              "IsPrivileged": false
            }
          ]
        },
        {
          "displayName": "Included Updated Properties",
          "oldValue": null,
          "newValue": "\"DisplayName, GrantedPermissions\""
        }
      ],
      "administrativeUnits": [],
      "agentType": "notAgentic"
    }
  ]
}

References #

Remove member from role

#
Source
Microsoft Entra ID audit log
Audit Category
RoleManagement

Description

A principal was removed from a directory role.

Example Audit Log Entry #

{
  "AADOperationType": "Unassign",
  "AADTenantId": "11111111-1111-1111-1111-111111111111",
  "ActivityDateTime": "2026-07-24T03:20:26.5914353Z",
  "ActivityDisplayName": "Remove member from role",
  "AdditionalDetails": [
    {
      "key": "User-Agent",
      "value": "python/3.14.5 (Linux-6.1.0-51-amd64-x86_64-with-glibc2.36) AZURECLI/2.88.0 (DEB)"
    }
  ],
  "Category": "RoleManagement",
  "CorrelationId": "af76e9f3-236c-4363-b45a-6adfeea779be",
  "DurationMs": "0",
  "Id": "Directory_af76e9f3-236c-4363-b45a-6adfeea779be_A7FWW_151245055",
  "InitiatedBy": {
    "user": {
      "id": "aaaaaaaa-0000-0000-0000-000000000001",
      "displayName": null,
      "userPrincipalName": "adminuser@example.onmicrosoft.com",
      "ipAddress": "203.0.113.10",
      "roles": [],
      "agentType": "notAgentic"
    }
  },
  "LoggedByService": "Core Directory",
  "OperationName": "Remove member from role",
  "OperationVersion": "1.0",
  "Resource": "Microsoft.aadiam",
  "ResourceGroup": "Microsoft.aadiam",
  "ResourceId": "/tenants/11111111-1111-1111-1111-111111111111/providers/Microsoft.aadiam",
  "Result": "success",
  "ResultSignature": "None",
  "TargetResources": [
    {
      "id": "aaaaaaaa-0000-0000-0000-000000000001",
      "displayName": null,
      "type": "User",
      "userPrincipalName": "adminuser@example.onmicrosoft.com",
      "modifiedProperties": [
        {
          "displayName": "Role.ObjectID",
          "oldValue": "\"ba4b3989-6c3a-4095-bec6-a973070cfa28\"",
          "newValue": null
        },
        {
          "displayName": "Role.DisplayName",
          "oldValue": "\"Directory Readers\"",
          "newValue": null
        },
        {
          "displayName": "Role.TemplateId",
          "oldValue": "\"88d8e3e3-8f55-4a1e-953a-9b9898b8876b\"",
          "newValue": null
        },
        {
          "displayName": "Role.WellKnownObjectName",
          "oldValue": "\"DirectoryReaders\"",
          "newValue": null
        }
      ],
      "administrativeUnits": [],
      "agentType": "notAgentic"
    },
    {
      "id": "ba4b3989-6c3a-4095-bec6-a973070cfa28",
      "displayName": null,
      "type": "Role",
      "modifiedProperties": [],
      "administrativeUnits": [],
      "agentType": "notAgentic"
    }
  ]
}

References #

Update role definition

#
Source
Microsoft Entra ID audit log
Audit Category
RoleManagement

Description

A custom directory role definition was modified.

Example Audit Log Entry #

{
  "AADOperationType": "Update",
  "AADTenantId": "11111111-1111-1111-1111-111111111111",
  "ActivityDateTime": "2026-07-24T03:20:52.1117475Z",
  "ActivityDisplayName": "Update role definition",
  "AdditionalDetails": [
    {
      "key": "User-Agent",
      "value": "python/3.14.5 (Linux-6.1.0-51-amd64-x86_64-with-glibc2.36) AZURECLI/2.88.0 (DEB)"
    }
  ],
  "Category": "RoleManagement",
  "CorrelationId": "1b09278d-6791-4e2f-b1c0-d3a6e7965676",
  "DurationMs": "0",
  "Id": "Directory_1b09278d-6791-4e2f-b1c0-d3a6e7965676_KR8EX_154762087",
  "InitiatedBy": {
    "user": {
      "id": "aaaaaaaa-0000-0000-0000-000000000001",
      "displayName": null,
      "userPrincipalName": "adminuser@example.onmicrosoft.com",
      "ipAddress": "203.0.113.10",
      "roles": [],
      "agentType": "notAgentic"
    }
  },
  "LoggedByService": "Core Directory",
  "OperationName": "Update role definition",
  "OperationVersion": "1.0",
  "Resource": "Microsoft.aadiam",
  "ResourceGroup": "Microsoft.aadiam",
  "ResourceId": "/tenants/11111111-1111-1111-1111-111111111111/providers/Microsoft.aadiam",
  "Result": "success",
  "ResultSignature": "None",
  "TargetResources": [
    {
      "id": "ff657eed-4940-4bcf-96ac-79e9076c4914",
      "displayName": "dw-harness-role-cf516524",
      "type": "Other",
      "modifiedProperties": [
        {
          "displayName": "Included Updated Properties",
          "oldValue": null,
          "newValue": "\"\""
        }
      ],
      "administrativeUnits": [],
      "agentType": "notAgentic"
    }
  ]
}

References #

Update role setting in PIM

#
Source
Microsoft Entra ID audit log
Audit Category
RoleManagement

Description

PIM role settings (activation duration, approval, MFA requirement) were changed.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sigma #

Elastic #

  • Entra ID Privileged Identity Management (PIM) Role Modified source medium: Azure Active Directory (AD) Privileged Identity Management (PIM) is a service that enables you to manage, control, and monitor access to important resources in an organization. PIM can be used to manage the built-in Azure resource roles such as Global Administrator and Application Administrator. An adversary may add a user to a PIM role in order to maintain persistence in their target's environment or modify a PIM role to weaken their target's security controls.T1078, T1098, T1098.003

References #

Add EligibleRoleAssignment to RoleDefinition

#
Source
Microsoft Entra ID audit log
Audit Category
RoleManagement

Description

An eligible role assignment was added to a Microsoft Entra role definition, making a principal eligible for that directory role. Eligible assignments require activation (typically through Privileged Identity Management) before the role's privileges apply, and granting eligibility to a privileged role is a privilege-escalation and persistence vector.

References #

Add member to role scoped over Restricted Management Administrative Unit

#
Source
Microsoft Entra ID audit log
Audit Category
RoleManagement

Description

Records a directory role assignment granted with scope over a restricted management administrative unit (RMAU), giving the assigned principal management rights over the objects in that unit. Because RMAUs shield their members from tenant-level administrators, a scoped role grant over an RMAU widens who can manage otherwise-protected accounts and warrants review.

References #

Add role assignment to role definition

#
Source
Microsoft Entra ID audit log
Audit Category
RoleManagement

Description

Records creation of a Microsoft Entra role assignment that binds a principal (user, group, or service principal) to a role definition, granting that role's permissions. New assignments to privileged roles are a primary privilege-escalation and persistence signal.

References #

Add role from template

#
Source
Microsoft Entra ID audit log
Audit Category
RoleManagement

Description

Records activation of a built-in directory (administrator) role in the tenant from its directoryRoleTemplate, which makes the role available so that members can be assigned to it. Only Company Administrator is active by default, so activating other privileged role templates can precede privilege escalation.

Example Audit Log Entry #

{
  "AADOperationType": "Add",
  "AADTenantId": "11111111-1111-1111-1111-111111111111",
  "ActivityDateTime": "2026-06-29T17:56:22.1017155Z",
  "ActivityDisplayName": "Add role from template",
  "AdditionalDetails": [
    {
      "key": "User-Agent",
      "value": "python/3.13.9 (Linux-6.1.0-41-amd64-x86_64-with-glibc2.36) AZURECLI/2.82.0 (DEB)"
    }
  ],
  "Category": "RoleManagement",
  "CorrelationId": "bb4cb77c-88d0-40a9-9155-55b9ed0df680",
  "DurationMs": "0",
  "Id": "Directory_bb4cb77c-88d0-40a9-9155-55b9ed0df680_PUEU2_136849831",
  "Identity": "",
  "InitiatedBy": {
    "user": {
      "displayName": null,
      "agentType": "notAgentic",
      "id": "aaaaaaaa-0000-0000-0000-000000000001",
      "userPrincipalName": "adminuser@example.onmicrosoft.com",
      "ipAddress": "203.0.113.10",
      "roles": []
    }
  },
  "Level": "",
  "Location": "",
  "LoggedByService": "Core Directory",
  "OperationName": "Add role from template",
  "OperationVersion": "1.0",
  "Resource": "Microsoft.aadiam",
  "ResourceGroup": "Microsoft.aadiam",
  "ResourceId": "/tenants/11111111-1111-1111-1111-111111111111/providers/Microsoft.aadiam",
  "ResourceProvider": "",
  "Result": "success",
  "ResultDescription": "",
  "ResultReason": "",
  "ResultSignature": "None",
  "ResultType": "",
  "SourceSystem": "Azure AD",
  "TargetResources": [
    {
      "id": "d0d8ab1f-38e0-4911-96ba-2a01f139862b",
      "displayName": "User",
      "type": "Role",
      "modifiedProperties": [
        {
          "displayName": "TargetId.RoleTemplateId",
          "oldValue": null,
          "newValue": "\"a0b1b346-4d3e-4e8b-98f8-753987be4970\""
        },
        {
          "displayName": "TargetId.RoleWellKnownObjectName",
          "oldValue": null,
          "newValue": "\"Users\""
        }
      ],
      "administrativeUnits": [],
      "agentType": "notAgentic"
    }
  ],
  "TenantId": "00000000-0000-0000-0000-000000000000",
  "TimeGenerated": "2026-06-29T17:56:22.1017155Z",
  "Type": "AuditLogs"
}

References #

Add scoped member to role

#
Source
Microsoft Entra ID audit log
Audit Category
RoleManagement

Description

Records the addition of a principal as a member of a directory role scoped to an administrative unit (a scopedRoleMembership), granting that role's permissions only over the members of that administrative unit. Scoped administrator grants are privilege-escalation relevant within the unit.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sigma #

References #

Delete role definition

#
Source
Microsoft Entra ID audit log
Audit Category
RoleManagement

Description

Records the deletion of a Microsoft Entra role definition, a named collection of directory permissions; custom role definitions can be deleted. Changes to RBAC role definitions are security-relevant to privilege management.

Example Audit Log Entry #

{
  "AADOperationType": "Delete",
  "AADTenantId": "11111111-1111-1111-1111-111111111111",
  "ActivityDateTime": "2026-07-24T03:20:53.0227512Z",
  "ActivityDisplayName": "Delete role definition",
  "AdditionalDetails": [
    {
      "key": "User-Agent",
      "value": "python/3.14.5 (Linux-6.1.0-51-amd64-x86_64-with-glibc2.36) AZURECLI/2.88.0 (DEB)"
    }
  ],
  "Category": "RoleManagement",
  "CorrelationId": "70b23317-c794-4d65-84a2-54d22425695b",
  "DurationMs": "0",
  "Id": "Directory_70b23317-c794-4d65-84a2-54d22425695b_708EK_122407154",
  "InitiatedBy": {
    "user": {
      "id": "aaaaaaaa-0000-0000-0000-000000000001",
      "displayName": null,
      "userPrincipalName": "adminuser@example.onmicrosoft.com",
      "ipAddress": "203.0.113.10",
      "roles": [],
      "agentType": "notAgentic"
    }
  },
  "LoggedByService": "Core Directory",
  "OperationName": "Delete role definition",
  "OperationVersion": "1.0",
  "Resource": "Microsoft.aadiam",
  "ResourceGroup": "Microsoft.aadiam",
  "ResourceId": "/tenants/11111111-1111-1111-1111-111111111111/providers/Microsoft.aadiam",
  "Result": "success",
  "ResultSignature": "None",
  "TargetResources": [
    {
      "id": "ff657eed-4940-4bcf-96ac-79e9076c4914",
      "displayName": "dw-harness-role-cf516524",
      "type": "Other",
      "modifiedProperties": [
        {
          "displayName": "Included Updated Properties",
          "oldValue": null,
          "newValue": "\"\""
        }
      ],
      "administrativeUnits": [],
      "agentType": "notAgentic"
    }
  ]
}

References #

Refresh PIM alert

#
Source
Microsoft Entra ID audit log
Audit Category
RoleManagement

Description

A Privileged Identity Management security alert was refreshed, prompting PIM to re-evaluate the alert and update its results against the current state of Microsoft Entra role assignments and activity. It is a routine PIM alert-management operation, not a role or privilege change.

References #

Remove eligible member from role

#
Source
Microsoft Entra ID audit log
Audit Category
RoleManagement

Description

Records removal of a principal's eligible assignment to a Microsoft Entra directory role, the PIM eligibility that lets the principal activate the role when needed instead of holding it permanently. Changes to eligible role assignments are privilege-relevant.

References #

Remove EligibleRoleAssignment from RoleDefinition

#
Source
Microsoft Entra ID audit log
Audit Category
RoleManagement

Description

Records removal of an eligible role assignment associated with a Microsoft Entra role definition, the directory-side record of deleting a PIM eligibility for that role. Eligible role assignments let a principal activate the role rather than hold it standing.

References #

Remove member from role scoped over Restricted Management Administrative Unit

#
Source
Microsoft Entra ID audit log
Audit Category
RoleManagement

Description

Records removal of a Microsoft Entra role assignment that was scoped to a restricted management administrative unit (RoleManagement category). Because only administrators explicitly assigned at that scope can manage the unit's protected objects, removing such an assignment changes who is able to administer those sensitive objects.

References #

Remove role assignment from role definition

#
Source
Microsoft Entra ID audit log
Audit Category
RoleManagement

Description

A role assignment linking a principal to a Microsoft Entra role definition was removed, revoking that principal's directory role at the assigned scope. Removal of privileged role assignments is relevant to monitoring directory privilege changes and to spotting an actor de-provisioning roles to cover tracks after misuse.

References #

Remove scoped member from role

#
Source
Microsoft Entra ID audit log
Audit Category
RoleManagement

Description

A scoped role member was removed from a Microsoft Entra role whose assignment was scoped to an administrative unit, revoking that principal's administrative-unit-scoped role. Changes to scoped role membership are relevant to tracking delegated administrative privilege confined to specific administrative units.

References #

Update PIM alert setting

#
Source
Microsoft Entra ID audit log
Audit Category
RoleManagement

Description

A Privileged Identity Management security-alert setting for Microsoft Entra roles was updated. Disabling or weakening a PIM alert reduces monitoring of suspicious privileged-role activity (defense evasion).

References #

Update role

#
Source
Microsoft Entra ID audit log
Audit Category
RoleManagement

Description

A directory role object was updated, such as a change to a role definition's properties or permissions in the Core Directory. Modifications to privileged roles are relevant to detecting privilege escalation and unauthorized administrative tampering.

Example Audit Log Entry #

{
  "AADOperationType": "Update",
  "AADTenantId": "11111111-1111-1111-1111-111111111111",
  "ActivityDateTime": "2026-07-24T03:20:42.7822092Z",
  "ActivityDisplayName": "Update role",
  "AdditionalDetails": [
    {
      "key": "User-Agent",
      "value": "python/3.14.5 (Linux-6.1.0-51-amd64-x86_64-with-glibc2.36) AZURECLI/2.88.0 (DEB)"
    }
  ],
  "Category": "RoleManagement",
  "CorrelationId": "eb2285f2-995b-4971-b6f8-b6aed5198e07",
  "DurationMs": "0",
  "Id": "Directory_eb2285f2-995b-4971-b6f8-b6aed5198e07_H2DJ9_135895596",
  "InitiatedBy": {
    "user": {
      "id": "aaaaaaaa-0000-0000-0000-000000000001",
      "displayName": null,
      "userPrincipalName": "adminuser@example.onmicrosoft.com",
      "ipAddress": "203.0.113.10",
      "roles": [],
      "agentType": "notAgentic"
    }
  },
  "LoggedByService": "Core Directory",
  "OperationName": "Update role",
  "OperationVersion": "1.0",
  "Resource": "Microsoft.aadiam",
  "ResourceGroup": "Microsoft.aadiam",
  "ResourceId": "/tenants/11111111-1111-1111-1111-111111111111/providers/Microsoft.aadiam",
  "Result": "success",
  "ResultSignature": "None",
  "TargetResources": [
    {
      "id": "d0d8ab1f-38e0-4911-96ba-2a01f139862b",
      "displayName": "User",
      "type": "Role",
      "modifiedProperties": [
        {
          "displayName": "Included Updated Properties",
          "oldValue": null,
          "newValue": "\"\""
        },
        {
          "displayName": "TargetId.RoleTemplateId",
          "oldValue": null,
          "newValue": "\"a0b1b346-4d3e-4e8b-98f8-753987be4970\""
        },
        {
          "displayName": "TargetId.RoleWellKnownObjectName",
          "oldValue": null,
          "newValue": "\"Users\""
        }
      ],
      "administrativeUnits": [],
      "agentType": "notAgentic"
    }
  ]
}

References #

Rules often query computed field names, not native AuditLogs columns #

Many Entra detection rules pivot on field names that are not columns in this table but KQL projections the rule author computes from two dynamic columns. Searching the field list for those names finds nothing; use the canonical paths instead.

  • InitiatingUserPrincipalName (and sibling Initiating* names) is not a column. Rules project it from InitiatedBy, for example extend InitiatingUserPrincipalName = tostring(InitiatedBy.user.userPrincipalName). The native paths are InitiatedBy.user.userPrincipalName, InitiatedBy.user.displayName, and InitiatedBy.user.id for user actors, and InitiatedBy.app.displayName / InitiatedBy.app.appId for application or service-principal actors.
  • What changed lives in TargetResources, a dynamic array. Expand it before filtering on the change: AuditLogs | mv-expand TargetResources | extend props = TargetResources.modifiedProperties, then read props[].displayName, props[].oldValue, and props[].newValue.

Column shapes per the AuditLogs table reference and the Graph directoryAudit resource.