Azure Active Directory / Entra ID events

OperationDescriptionSampleRule
anyCatch-all for M365-AzureActiveDirectory rules matching the RecordType but no specific Operation.NY
Add a partner to cross-tenant access setting.Microsoft Entra ID (Azure Active Directory) audit activity in the CrossTenantAccessSettings category, recorded in the Office 365 Unified Audit Log.YY
Add administrative unit.Add administrative unit. activity in Microsoft Entra ID, recorded in the Unified Audit Log (observed in first-party capture).YN
Add app role assignment grant to user.An app role assignment was granted to a user in Microsoft Entra ID (an enterprise application role assigned to a user account). A directory operation, so it carries RecordType AzureActiveDirectory (8) like its documented siblings (Add/Remove app role assignment to service principal / from user).YY
Add app role assignment to service principal.Microsoft Entra ID (Azure Active Directory) audit activity in the ApplicationManagement category, recorded in the Office 365 Unified Audit Log.YY
Add application.An application registration was created in Azure Active Directory (the UAL operation string includes a trailing period).YY
Add delegated permission grant.An OAuth2 delegated permission grant was created for an application.YY
Add eligible member to role.Microsoft Entra ID (Azure Active Directory) audit activity in the RoleManagement category, recorded in the Office 365 Unified Audit Log.NY
Add group.A group was created in Azure Active Directory (the UAL operation string includes a trailing period).YY
Add label.Add label. activity in Microsoft Entra ID, recorded in the Unified Audit Log (observed in first-party capture).YN
Add member to administrative unit.Add member to administrative unit. activity in Microsoft Entra ID, recorded in the Unified Audit Log (observed in first-party capture).YN
Add member to group.A principal was added to a group in Azure Active Directory (the UAL operation string includes a trailing period).YY
Add member to role.A principal was added to an Azure Active Directory directory role (the UAL operation string includes a trailing period).YY
Add owner to application.Microsoft Entra ID (Azure Active Directory) audit activity in the ApplicationManagement category, recorded in the Office 365 Unified Audit Log.YY
Add owner to group.An owner was added to a group.YN
Add permission grant policy.Add permission grant policy. activity in Microsoft Entra ID, recorded in the Unified Audit Log (observed in first-party capture).YN
Add policy.A directory policy object was created.YN
Add registered users to device.Registered users were added to a device object in Azure Active Directory (the UAL operation string includes a trailing period).NY
Add role definition.Add role definition. activity in Microsoft Entra ID, recorded in the Unified Audit Log (observed in first-party capture).YN
Add service principal credentials.Credentials were added to a service principal (common persistence technique).YN
Add service principal.Microsoft Entra ID (Azure Active Directory) audit activity in the ApplicationManagement category, recorded in the Office 365 Unified Audit Log.YY
Add unverified domain.An unverified custom domain was added to the tenant.YN
Add user.A new user account was created in the directory.YY
Change user license.Microsoft Entra ID (Azure Active Directory) audit activity in the UserManagement category, recorded in the Office 365 Unified Audit Log.YY
Change user password.A user changed their own password.YN
Consent to application.Admin or user consent was granted to an application in Azure Active Directory (the UAL operation string includes a trailing period).YY
Create application password for user.An app password was created for a user, letting a legacy client sign in without completing MFA.YN
Create application – Certificates and secrets management Create application – Certificates and secrets management activity in Microsoft Entra ID, recorded in the Unified Audit Log (observed in first-party capture).YN
Create company settingsCreate company settings activity in Microsoft Entra ID, recorded in the Unified Audit Log (observed in first-party capture).YN
Delete administrative unit.Delete administrative unit. activity in Microsoft Entra ID, recorded in the Unified Audit Log (observed in first-party capture).YN
Delete application password for user.An app-password credential was deleted for a user, revoking a legacy non-MFA sign-in credential.YN
Delete application.An application registration was deleted.YN
Delete company settingsDelete company settings activity in Microsoft Entra ID, recorded in the Unified Audit Log (observed in first-party capture).YN
Delete group.A group was deleted in Azure Active Directory (the UAL operation string includes a trailing period).YY
Delete label.Delete label. activity in Microsoft Entra ID, recorded in the Unified Audit Log (observed in first-party capture).YN
Delete partner specific cross-tenant access setting.Microsoft Entra ID (Azure Active Directory) audit activity in the CrossTenantAccessSettings category, recorded in the Office 365 Unified Audit Log.YY
Delete permission grant policy.Delete permission grant policy. activity in Microsoft Entra ID, recorded in the Unified Audit Log (observed in first-party capture).YN
Delete policy.Delete policy. activity in Microsoft Entra ID, recorded in the Unified Audit Log (observed in first-party capture).YN
Delete role definition.Delete role definition. activity in Microsoft Entra ID, recorded in the Unified Audit Log (observed in first-party capture).YN
Delete user.A user account was deleted.YN
Disable Strong Authentication.Microsoft Entra ID (Azure Active Directory) audit activity in the UserManagement category, recorded in the Office 365 Unified Audit Log.YY
Enable Strong Authentication.Records strong authentication (multifactor authentication) being enabled for a directory user.YN
Remove app role assignment from service principal.An app role assignment was removed from a service principal, revoking an application's granted app role.YN
Remove delegated permission grant.An OAuth2 delegated permission grant was deleted, revoking the delegated API permissions granted to an application.YN
Remove member from administrative unit.Remove member from administrative unit. activity in Microsoft Entra ID, recorded in the Unified Audit Log (observed in first-party capture).YN
Remove member from group.A principal was removed from a group in Azure Active Directory (the UAL operation string includes a trailing period).YY
Remove member from role.A principal was removed from a directory role.YN
Remove service principal.A service principal was removed.YN
Reset user password.An administrator reset a user's password.YN
Set Company Information.Microsoft Entra ID (Azure Active Directory) audit activity in the DirectoryManagement category, recorded in the Office 365 Unified Audit Log.YY
Set-MsolDomainFederationSettingsFederation settings for a domain were changed via the MSOnline module (a directory operation, not an Exchange cmdlet); abused to add a backdoor federation trust.NY
Update administrative unit.Update administrative unit. activity in Microsoft Entra ID, recorded in the Unified Audit Log (observed in first-party capture).YN
Update application – Certificates and secrets management Update application – Certificates and secrets management activity in Microsoft Entra ID, recorded in the Unified Audit Log (observed in first-party capture).YY
Update application.An application registration was modified in Azure Active Directory (the UAL operation string includes a trailing period).YY
Update authorization policy.Microsoft Entra ID (Azure Active Directory) audit activity in the AuthorizationPolicy category, recorded in the Office 365 Unified Audit Log.YY
Update company settingsUpdate company settings activity in Microsoft Entra ID, recorded in the Unified Audit Log (observed in first-party capture).YN
Update device.Update device. activity in Microsoft Entra ID, recorded in the Unified Audit Log (observed in first-party capture).YN
Update group.Update group. activity in Microsoft Entra ID, recorded in the Unified Audit Log (observed in first-party capture).YN
Update PasswordProfile.Update Password Profile. activity in Microsoft Entra ID, recorded in the Unified Audit Log (observed in first-party capture).YN
Update policy.Microsoft Entra ID (Azure Active Directory) audit activity in the Policy category, recorded in the Office 365 Unified Audit Log.YY
Update role definition.Update role definition. activity in Microsoft Entra ID, recorded in the Unified Audit Log (observed in first-party capture).YN
Update role.Update role. activity in Microsoft Entra ID, recorded in the Unified Audit Log (observed in first-party capture).YN
Update service principal.A service principal object was modified (properties, credentials, or tags).YN
Update StsRefreshTokenValidFrom Timestamp.A user's refresh tokens were invalidated (revoke sessions); also set silently by some attacks.YN
Update user.Microsoft Entra ID (Azure Active Directory) audit activity in the UserManagement category, recorded in the Office 365 Unified Audit Log.YY

any: Azure Active Directory / Entra ID events (catch-all)

#
RecordType
AzureActiveDirectory

Description

Catch-all for M365-AzureActiveDirectory rules matching the RecordType but no specific Operation.

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
action (splunk rule field)eqcreated1 rulesplunk
csUserAgent (kusto rule field)is_not_null1 rulekusto

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Splunk #

  • O365 Added Service Principal source: The following analytic detects the addition of new service principal accounts in O365 tenants. It leverages data from the o365_management_activity dataset, specifically monitoring for operations related to adding or creating service…T1136, T1136.003

Kusto #

  • Malformed user agent source medium: Malware authors will sometimes hardcode user agent string values when writing the network communication component of their malware. Malformed user agents can be an indication of such malware.T1071, T1189, T1203

References #

Add a partner to cross-tenant access setting.

#
RecordType
AzureActiveDirectory

Description

Microsoft Entra ID (Azure Active Directory) audit activity in the CrossTenantAccessSettings category, recorded in the Office 365 Unified Audit Log.

Example Audit Record #

{
  "Actor": [
    {
      "ID": "Malicious Service Principal",
      "Type": 1
    },
    {
      "ID": "b39d63e7-7fa3-4b2b-94ea-ee256fdb8c2f",
      "Type": 2
    },
    {
      "ID": "ServicePrincipal_ff45cda2-75e3-4be8-84b7-f5720d42b5b0",
      "Type": 2
    },
    {
      "ID": "ff45cda2-75e3-4be8-84b7-f5720d42b5b0",
      "Type": 2
    },
    {
      "ID": "ServicePrincipal",
      "Type": 2
    }
  ],
  "ActorContextId": "6915b1e0-b081-4829-8866-f1a3e883a9ae",
  "ActorIpAddress": "52.224.85.250",
  "AzureActiveDirectoryEventType": 1,
  "ClientIP": "52.224.85.250",
  "CreationTime": "2024-03-20T07:51:02",
  "ExtendedProperties": [
    {
      "Name": "additionalDetails",
      "Value": {}
    },
    {
      "Name": "extendedAuditEventCategory",
      "Value": "CrossTenantAccessSettings"
    }
  ],
  "Id": "4923abb2-609c-411e-a685-0c4f0c53ecfb",
  "InterSystemsId": "f76baa3e-1207-41fb-b5df-631ceccb9b2e",
  "IntraSystemId": "b5ea04c4-e89f-45d6-ad54-9d8ba882e701",
  "ModifiedProperties": [
    {
      "Name": "tenantId",
      "NewValue": "141e07d1-6f28-4169-b951-316d5a941d88",
      "OldValue": ""
    }
  ],
  "ObjectId": "Policy_17c7001d-3a4d-4bf7-9cc6-ee0e40f665da",
  "Operation": "Add a partner to cross-tenant access setting.",
  "OrganizationId": "6915b1e0-b081-4829-8866-f1a3e883a9ae",
  "RecordType": 8,
  "ResultStatus": "Success",
  "Target": [
    {
      "ID": "Policy_17c7001d-3a4d-4bf7-9cc6-ee0e40f665da",
      "Type": 2
    },
    {
      "ID": "17c7001d-3a4d-4bf7-9cc6-ee0e40f665da",
      "Type": 2
    },
    {
      "ID": "Policy",
      "Type": 2
    },
    {
      "ID": "CrossTenantAccessPolicy for 6915b1e0-b081-4829-8866-f1a3e883a9ae",
      "Type": 1
    }
  ],
  "TargetContextId": "6915b1e0-b081-4829-8866-f1a3e883a9ae",
  "UserId": "ServicePrincipal_ff45cda2-75e3-4be8-84b7-f5720d42b5b0",
  "UserKey": "Not Available",
  "UserType": 4,
  "Version": 1,
  "Workload": "AzureActiveDirectory"
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Splunk #

References #

Add administrative unit.

#
RecordType
AzureActiveDirectory

Description

Add administrative unit. activity in Microsoft Entra ID, recorded in the Unified Audit Log (observed in first-party capture).

Example Audit Record #

{
  "Actor": [
    {
      "ID": "adminuser@example.onmicrosoft.com",
      "Type": 5
    },
    {
      "ID": 1111111111111111,
      "Type": 3
    },
    {
      "ID": "User_aaaaaaaa-0000-0000-0000-000000000001",
      "Type": 2
    },
    {
      "ID": "aaaaaaaa-0000-0000-0000-000000000001",
      "Type": 2
    },
    {
      "ID": "User",
      "Type": 2
    },
    {
      "ID": "NotAgentic",
      "Type": 2
    }
  ],
  "ActorContextId": "11111111-1111-1111-1111-111111111111",
  "AzureActiveDirectoryEventType": 1,
  "CreationDate": "2026-07-03T03:23:03",
  "CreationTime": "2026-07-03T03:23:03",
  "ExtendedProperties": [
    {
      "Name": "additionalDetails",
      "Value": {
        "User-Agent": "python/3.13.9 (Linux-6.1.0-41-amd64-x86_64-with-glibc2.36) AZURECLI/2.82.0 (DEB)"
      }
    },
    {
      "Name": "extendedAuditEventCategory",
      "Value": "AdministrativeUnit"
    }
  ],
  "Id": "78414ede-98e9-417b-acf7-70adc580b052",
  "InterSystemsId": "4268eb2a-8263-400f-874c-31ef4dbdf000",
  "IntraSystemId": "ac85b254-d400-4f9c-af7a-80f0e1ae6bfd",
  "ModifiedProperties": [
    {
      "Name": "DisplayName",
      "NewValue": [
        "dw-harness-aum-2fe5ab51"
      ],
      "OldValue": []
    },
    {
      "Name": "Included Updated Properties",
      "NewValue": "DisplayName",
      "OldValue": ""
    }
  ],
  "ObjectId": "AdministrativeUnit_78e00ff9-4f90-4a2d-ba46-416e73ce7793",
  "Operation": "Add administrative unit.",
  "Operations": "Add administrative unit.",
  "OrganizationId": "11111111-1111-1111-1111-111111111111",
  "RecordType": "AzureActiveDirectory",
  "ResultStatus": "Success",
  "Target": [
    {
      "ID": "AdministrativeUnit_78e00ff9-4f90-4a2d-ba46-416e73ce7793",
      "Type": 2
    },
    {
      "ID": "78e00ff9-4f90-4a2d-ba46-416e73ce7793",
      "Type": 2
    },
    {
      "ID": "Manager",
      "Type": 2
    },
    {
      "ID": "dw-harness-aum-2fe5ab51",
      "Type": 1
    }
  ],
  "TargetContextId": "11111111-1111-1111-1111-111111111111",
  "UserId": "adminuser@example.onmicrosoft.com",
  "UserKey": "1111111111111111@example.onmicrosoft.com",
  "UserType": "Regular",
  "Version": 1,
  "Workload": "AzureActiveDirectory"
}

References #

Add app role assignment grant to user.

#
RecordType
AzureActiveDirectory

Description

An app role assignment was granted to a user in Microsoft Entra ID (an enterprise application role assigned to a user account). A directory operation, so it carries RecordType AzureActiveDirectory (8) like its documented siblings (Add/Remove app role assignment to service principal / from user).

Example Audit Record #

{
  "Actor": [
    {
      "ID": "rodsoto@rodsoto.onmicrosoft.com",
      "Type": 5
    },
    {
      "ID": "10037FFEA938FB92",
      "Type": 3
    },
    {
      "ID": "74658136-14ec-4630-ad9b-26e160ff0fc6",
      "Type": 2
    },
    {
      "ID": "User_bfb8c366-0406-41a5-b3e3-328f4a3b4484",
      "Type": 2
    },
    {
      "ID": "bfb8c366-0406-41a5-b3e3-328f4a3b4484",
      "Type": 2
    },
    {
      "ID": "User",
      "Type": 2
    }
  ],
  "ActorContextId": "0e8108b1-18e9-41a4-961b-dfcddf92ef08",
  "ActorIpAddress": "40.124.84.4",
  "AzureActiveDirectoryEventType": 1,
  "ClientIP": "40.124.84.4",
  "CreationTime": "2021-01-19T22:21:39",
  "ExtendedProperties": [
    {
      "Name": "additionalDetails",
      "Value": {}
    },
    {
      "Name": "extendedAuditEventCategory",
      "Value": "User"
    }
  ],
  "Id": "8b9e5417-c310-4382-89da-c0f25c5c0576",
  "InterSystemsId": "85c80877-c529-4487-8f44-48760767cc6c",
  "IntraSystemId": "6fc81447-9c94-4734-8bd7-307bb699c04e",
  "ModifiedProperties": [
    {
      "Name": "AppRole.Id",
      "NewValue": "97edced9-9f34-4eef-9b49-84a5ebcd5167",
      "OldValue": ""
    },
    {
      "Name": "AppRole.Value",
      "NewValue": "arn:aws:iam::111111111111:role/rodonmicrotestrole,arn:aws:iam::111111111111:saml-provider/rodsotoonmicrosoft",
      "OldValue": ""
    },
    {
      "Name": "AppRole.DisplayName",
      "NewValue": "rodonmicrotestrole,rodsotoonmicrosoft",
      "OldValue": ""
    },
    {
      "Name": "User.ObjectID",
      "NewValue": "7646f1a9-620c-4630-b5e4-b02838be5562",
      "OldValue": ""
    },
    {
      "Name": "User.UPN",
      "NewValue": "vagrant@rodsoto.onmicrosoft.com",
      "OldValue": ""
    },
    {
      "Name": "User.PUID",
      "NewValue": "100320010972E450",
      "OldValue": ""
    },
    {
      "Name": "TargetId.ServicePrincipalNames",
      "NewValue": "https://signin.aws.amazon.com/saml;3e71560f-3e31-45ab-b439-46328fe55b88",
      "OldValue": ""
    }
  ],
  "ObjectId": "https://signin.aws.amazon.com/saml;3e71560f-3e31-45ab-b439-46328fe55b88",
  "Operation": "Add app role assignment grant to user.",
  "OrganizationId": "0e8108b1-18e9-41a4-961b-dfcddf92ef08",
  "RecordType": 8,
  "ResultStatus": "Success",
  "Target": [
    {
      "ID": "ServicePrincipal_9fd10db9-dfe2-4d74-a724-c837eb8764d9",
      "Type": 2
    },
    {
      "ID": "9fd10db9-dfe2-4d74-a724-c837eb8764d9",
      "Type": 2
    },
    {
      "ID": "ServicePrincipal",
      "Type": 2
    },
    {
      "ID": "Amazon Web Services (AWS)",
      "Type": 1
    },
    {
      "ID": "3e71560f-3e31-45ab-b439-46328fe55b88",
      "Type": 2
    },
    {
      "ID": "https://signin.aws.amazon.com/saml;3e71560f-3e31-45ab-b439-46328fe55b88",
      "Type": 4
    }
  ],
  "TargetContextId": "0e8108b1-18e9-41a4-961b-dfcddf92ef08",
  "UserId": "rodsoto@rodsoto.onmicrosoft.com",
  "UserKey": "10037FFEA938FB92@rodsoto.onmicrosoft.com",
  "UserType": 0,
  "Version": 1,
  "Workload": "AzureActiveDirectory"
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Splunk #

  • O365 Add App Role Assignment Grant User source: The following analytic detects the addition of an application role assignment grant to a user in Office 365. It leverages data from the o365_management_activity dataset, specifically monitoring the "Add app role assignment grant to user"…T1136, T1136.003

References #

Add app role assignment to service principal.

#
RecordType
AzureActiveDirectory

Description

Microsoft Entra ID (Azure Active Directory) audit activity in the ApplicationManagement category, recorded in the Office 365 Unified Audit Log.

Example Audit Record #

{
  "CreationTime": "2024-04-30T08:22:50",
  "Id": "5fd0f419-722d-4fe3-86cd-ce261f32fca7",
  "Operation": "Add app role assignment to service principal.",
  "OrganizationId": "225e05a1-5914-4688-a404-7030e60f3143",
  "RecordType": 8,
  "ResultStatus": "Success",
  "UserKey": "Not Available",
  "UserType": 4,
  "Version": 1,
  "Workload": "AzureActiveDirectory",
  "ObjectId": "https://canary.graph.microsoft.com/;https://graph.microsoft.us/;https://dod-graph.microsoft.us/;https://dod-graph.microsoft.us;https://graph.microsoft.com/;https://graph.microsoft.us;https://canary.graph.microsoft.com;https://graph.microsoft.com;https://ags.windows.net;00000003-0000-0000-c000-000000000000/ags.windows.net;00000003-0000-0000-c000-000000000000",
  "UserId": "ServicePrincipal_ffa25d34-fbae-42ec-aa48-bc7e4ff8bf66",
  "AzureActiveDirectoryEventType": 1,
  "ExtendedProperties": [
    {
      "Name": "additionalDetails",
      "Value": {
        "User-Agent": "Mozilla/5.0 (Windows NT 10.0; Microsoft Windows 10.0.19045; en-AU) PowerShell/5.1.19041.4291",
        "AppId": "00000003-0000-0000-c000-000000000000"
      }
    },
    {
      "Name": "extendedAuditEventCategory",
      "Value": "ServicePrincipal"
    }
  ],
  "ModifiedProperties": [
    {
      "Name": "AppRole.Id",
      "NewValue": "9e3f62cf-ca93-4989-b6ce-bf83c28f9fe8",
      "OldValue": ""
    },
    {
      "Name": "AppRole.Value",
      "NewValue": "RoleManagement.ReadWrite.Directory",
      "OldValue": ""
    },
    {
      "Name": "AppRole.DisplayName",
      "NewValue": "Read and write all directory RBAC settings",
      "OldValue": ""
    },
    {
      "Name": "AppRoleAssignment.CreatedDateTime",
      "NewValue": "4/30/2024 8:22:50 AM",
      "OldValue": ""
    },
    {
      "Name": "AppRoleAssignment.LastModifiedDateTime",
      "NewValue": "4/30/2024 8:22:50 AM",
      "OldValue": ""
    },
    {
      "Name": "ServicePrincipal.ObjectID",
      "NewValue": "ffa25d34-fbae-42ec-aa48-bc7e4ff8bf66",
      "OldValue": ""
    },
    {
      "Name": "ServicePrincipal.DisplayName",
      "NewValue": "MashAuthTest",
      "OldValue": ""
    },
    {
      "Name": "ServicePrincipal.AppId",
      "NewValue": "7889f28d-ad42-441e-b1f6-1ad8da2f13e8",
      "OldValue": ""
    },
    {
      "Name": "ServicePrincipal.Name",
      "NewValue": "7889f28d-ad42-441e-b1f6-1ad8da2f13e8",
      "OldValue": ""
    },
    {
      "Name": "TargetId.ServicePrincipalNames",
      "NewValue": "https://canary.graph.microsoft.com/;https://graph.microsoft.us/;https://dod-graph.microsoft.us/;https://dod-graph.microsoft.us;https://graph.microsoft.com/;https://graph.microsoft.us;https://canary.graph.microsoft.com;https://graph.microsoft.com;https://ags.windows.net;00000003-0000-0000-c000-000000000000/ags.windows.net;00000003-0000-0000-c000-000000000000",
      "OldValue": ""
    }
  ],
  "Actor": [
    {
      "ID": "MashAuthTest",
      "Type": 1
    },
    {
      "ID": "7889f28d-ad42-441e-b1f6-1ad8da2f13e8",
      "Type": 2
    },
    {
      "ID": "ServicePrincipal_ffa25d34-fbae-42ec-aa48-bc7e4ff8bf66",
      "Type": 2
    },
    {
      "ID": "ffa25d34-fbae-42ec-aa48-bc7e4ff8bf66",
      "Type": 2
    },
    {
      "ID": "ServicePrincipal",
      "Type": 2
    }
  ],
  "ActorContextId": "225e05a1-5914-4688-a404-7030e60f3143",
  "InterSystemsId": "c967e3a4-9afd-49ee-a68c-bc465aaef2b3",
  "IntraSystemId": "00000000-0000-0000-0000-000000000000",
  "Target": [
    {
      "ID": "ServicePrincipal_58c0347e-8f51-49e5-a4db-8b1b857a7ddf",
      "Type": 2
    },
    {
      "ID": "58c0347e-8f51-49e5-a4db-8b1b857a7ddf",
      "Type": 2
    },
    {
      "ID": "ServicePrincipal",
      "Type": 2
    },
    {
      "ID": "Microsoft Graph",
      "Type": 1
    },
    {
      "ID": "00000003-0000-0000-c000-000000000000",
      "Type": 2
    },
    {
      "ID": "https://canary.graph.microsoft.com/;https://graph.microsoft.us/;https://dod-graph.microsoft.us/;https://dod-graph.microsoft.us;https://graph.microsoft.com/;https://graph.microsoft.us;https://canary.graph.microsoft.com;https://graph.microsoft.com;https://ags.windows.net;00000003-0000-0000-c000-000000000000/ags.windows.net;00000003-0000-0000-c000-000000000000",
      "Type": 4
    }
  ],
  "TargetContextId": "225e05a1-5914-4688-a404-7030e60f3143"
}

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
ResultStatus (splunk rule field)eqsuccess1 rulesplunk
servicePrincipal (splunk rule field)cross_field_comparetargetServicePrincipal1 rulesplunk
userType (splunk rule field)eqserviceprincipal1 rulesplunk

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Splunk #

References #

Add application.

#
RecordType
AzureActiveDirectory

Description

An application registration was created in Azure Active Directory (the UAL operation string includes a trailing period).

Example Audit Record #

{
  "CreationTime": "2024-02-07T22:31:14",
  "Id": "b47e890a-5bc1-4ebd-a8d5-2f4796de80d6",
  "Operation": "Add application.",
  "OrganizationId": "75243ab2-44f8-435c-a7a6-b479385df6d4",
  "RecordType": 8,
  "ResultStatus": "Success",
  "UserKey": "1003BFFD98415B4E@splunkresearch.onmicrosoft.com",
  "UserType": 0,
  "Version": 1,
  "Workload": "AzureActiveDirectory",
  "ObjectId": "Application_aef7a9a6-428e-4f0f-ab09-b0f10b21bda6",
  "UserId": "user30@splunkresearch.onmicrosoft.com",
  "AzureActiveDirectoryEventType": 1,
  "ExtendedProperties": [
    {
      "Name": "additionalDetails",
      "Value": {
        "User-Agent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/121.0.0.0 Safari/537.36",
        "AppId": "e06366ca-8489-4748-b6a2-d7e4332f45c1"
      }
    },
    {
      "Name": "extendedAuditEventCategory",
      "Value": "Application"
    }
  ],
  "ModifiedProperties": [
    {
      "Name": "AppId",
      "NewValue": [
        "e06366ca-8489-4748-b6a2-d7e4332f45c1"
      ],
      "OldValue": []
    },
    {
      "Name": "AvailableToOtherTenants",
      "NewValue": [
        false
      ],
      "OldValue": []
    },
    {
      "Name": "DisplayName",
      "NewValue": [
        "Malicious11"
      ],
      "OldValue": []
    },
    {
      "Name": "RequiredResourceAccess",
      "NewValue": [
        {
          "ResourceAppId": "00000003-0000-0000-c000-000000000000",
          "RequiredAppPermissions": [
            {
              "EntitlementId": "e1fe6dd8-ba31-4d61-89e7-88639da4683d",
              "DirectAccessGrant": false,
              "ImpersonationAccessGrants": [
                20
              ]
            }
          ],
          "EncodingVersion": 1
        }
      ],
      "OldValue": []
    },
    {
      "Name": "PublisherDomain",
      "NewValue": [
        "splunkresearch.onmicrosoft.com"
      ],
      "OldValue": []
    },
    {
      "Name": "ServicePrincipalLockConfiguration",
      "NewValue": [
        {
          "IsEnabled": true,
          "AllProperties": true,
          "CredentialsWithUsageVerify": true,
          "CredentialsWithUsageSign": true,
          "IdentifierUris": false,
          "TokenEncryptionKeyId": true
        }
      ],
      "OldValue": []
    },
    {
      "Name": "Included Updated Properties",
      "NewValue": "AppId, AvailableToOtherTenants, DisplayName, RequiredResourceAccess, PublisherDomain, ServicePrincipalLockConfiguration",
      "OldValue": ""
    }
  ],
  "Actor": [
    {
      "ID": "user30@splunkresearch.onmicrosoft.com",
      "Type": 5
    },
    {
      "ID": "1003BFFD98415B4E",
      "Type": 3
    },
    {
      "ID": "18ed3507-a475-4ccb-b669-d66bc9f2a36e",
      "Type": 2
    },
    {
      "ID": "User_e4c722ac-3b83-478d-8f52-c388885dc30f",
      "Type": 2
    },
    {
      "ID": "e4c722ac-3b83-478d-8f52-c388885dc30f",
      "Type": 2
    },
    {
      "ID": "User",
      "Type": 2
    }
  ],
  "ActorContextId": "75243ab2-44f8-435c-a7a6-b479385df6d4",
  "InterSystemsId": "9a0d48df-8083-4c2a-9095-5475289fb512",
  "IntraSystemId": "00000000-0000-0000-0000-000000000000",
  "Target": [
    {
      "ID": "Application_aef7a9a6-428e-4f0f-ab09-b0f10b21bda6",
      "Type": 2
    },
    {
      "ID": "aef7a9a6-428e-4f0f-ab09-b0f10b21bda6",
      "Type": 2
    },
    {
      "ID": "Application",
      "Type": 2
    },
    {
      "ID": "Malicious11",
      "Type": 1
    },
    {
      "ID": "e06366ca-8489-4748-b6a2-d7e4332f45c1",
      "Type": 2
    }
  ],
  "TargetContextId": "75243ab2-44f8-435c-a7a6-b479385df6d4"
}

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
target.resource.product_object_id (Chronicle)eq1b730954-1685-4b74-9bfd-dac224a7b8941 rulechronicle

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Splunk #

YARA-L #

References #

Add delegated permission grant.

#
RecordType
AzureActiveDirectory

Description

An OAuth2 delegated permission grant was created for an application.

Example Audit Record #

{
  "Actor": [
    {
      "ID": "adminuser@example.onmicrosoft.com",
      "Type": 5
    },
    {
      "ID": "10000000AAAAAAAA",
      "Type": 3
    },
    {
      "ID": "User_11111111-1111-1111-1111-111111111111",
      "Type": 2
    },
    {
      "ID": "11111111-1111-1111-1111-111111111111",
      "Type": 2
    },
    {
      "ID": "User",
      "Type": 2
    },
    {
      "ID": "NotAgentic",
      "Type": 2
    }
  ],
  "ActorContextId": "00000000-0000-0000-0000-000000000001",
  "AzureActiveDirectoryEventType": 1,
  "CreationTime": "2026-07-02T15:30:12Z",
  "ExtendedProperties": [
    {
      "Name": "additionalDetails",
      "Value": {
        "User-Agent": "python/3.13.9 (Linux-6.1.0-41-amd64-x86_64-with-glibc2.36) AZURECLI/2.82.0 (DEB)",
        "AppId": "00000003-0000-0000-c000-000000000000",
        "ServicePrincipalProvisioningType": "Other"
      }
    },
    {
      "Name": "extendedAuditEventCategory",
      "Value": "ServicePrincipal"
    }
  ],
  "Id": "f2665a07-1a1b-4857-a283-f0b4841b7b00",
  "InterSystemsId": "08dc6a80-0279-49c9-bf3d-bf9574f77337",
  "IntraSystemId": "00000000-0000-0000-0000-000000000000",
  "ModifiedProperties": [
    {
      "Name": "DelegatedPermissionGrant.Scope",
      "NewValue": "User.Read"
    },
    {
      "Name": "DelegatedPermissionGrant.ConsentType",
      "NewValue": "Principal"
    },
    {
      "Name": "ServicePrincipal.ObjectID",
      "NewValue": "af2cee02-3ad4-4486-85a2-e8eafc78cd6e"
    },
    {
      "Name": "ServicePrincipal.DisplayName"
    },
    {
      "Name": "ServicePrincipal.AppId"
    },
    {
      "Name": "ServicePrincipal.Name"
    },
    {
      "Name": "TargetId.ServicePrincipalNames",
      "NewValue": "00000003-0000-0000-c000-000000000000/ags.windows.net;00000003-0000-0000-c000-000000000000;https://canary.graph.microsoft.com;https://graph.microsoft.com;https://ags.windows.net;https://graph.microsoft.us;https://graph.microsoft.com/;https://dod-graph.microsoft.us;https://canary.graph.microsoft.com/;https://graph.microsoft.us/;https://dod-graph.microsoft.us/"
    }
  ],
  "ObjectId": "00000003-0000-0000-c000-000000000000/ags.windows.net;00000003-0000-0000-c000-000000000000;https://canary.graph.microsoft.com;https://graph.microsoft.com;https://ags.windows.net;https://graph.microsoft.us;https://graph.microsoft.com/;https://dod-graph.microsoft.us;https://canary.graph.microsoft.com/;https://graph.microsoft.us/;https://dod-graph.microsoft.us/",
  "Operation": "Add delegated permission grant.",
  "OrganizationId": "00000000-0000-0000-0000-000000000001",
  "RecordType": 8,
  "ResultStatus": "Success",
  "Target": [
    {
      "ID": "ServicePrincipal_2e5ab30e-ae89-43c2-b130-0022f3d655a7",
      "Type": 2
    },
    {
      "ID": "2e5ab30e-ae89-43c2-b130-0022f3d655a7",
      "Type": 2
    },
    {
      "ID": "ServicePrincipal",
      "Type": 2
    },
    {
      "ID": "NotAgentic",
      "Type": 2
    },
    {
      "ID": "Microsoft Graph",
      "Type": 1
    },
    {
      "ID": "00000003-0000-0000-c000-000000000000",
      "Type": 2
    },
    {
      "ID": "00000003-0000-0000-c000-000000000000/ags.windows.net;00000003-0000-0000-c000-000000000000;https://canary.graph.microsoft.com;https://graph.microsoft.com;https://ags.windows.net;https://graph.microsoft.us;https://graph.microsoft.com/;https://dod-graph.microsoft.us;https://canary.graph.microsoft.com/;https://graph.microsoft.us/;https://dod-graph.microsoft.us/",
      "Type": 4
    },
    {
      "ID": "Other",
      "Type": 2
    }
  ],
  "TargetContextId": "00000000-0000-0000-0000-000000000001",
  "UserId": "adminuser@example.onmicrosoft.com",
  "UserKey": "10000000AAAAAAAA@example.onmicrosoft.com",
  "UserType": 0,
  "Version": 1,
  "Workload": "AzureActiveDirectory"
}

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
target.resource.product_object_id (Chronicle)eq1b730954-1685-4b74-9bfd-dac224a7b8941 rulechronicle

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

YARA-L #

References #

Add eligible member to role.

#
RecordType
AzureActiveDirectory

Description

Microsoft Entra ID (Azure Active Directory) audit activity in the RoleManagement category, recorded in the Office 365 Unified Audit Log.

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
isprvilegedadrole (splunk rule field)eqtrue2 rulessplunk

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Splunk #

References #

Add group.

#
RecordType
AzureActiveDirectory

Description

A group was created in Azure Active Directory (the UAL operation string includes a trailing period).

Example Audit Record #

{
  "Actor": [
    {
      "ID": "adminuser@example.onmicrosoft.com",
      "Type": 5
    },
    {
      "ID": 1111111111111111,
      "Type": 3
    },
    {
      "ID": "User_11111111-1111-1111-1111-111111111111",
      "Type": 2
    },
    {
      "ID": "11111111-1111-1111-1111-111111111111",
      "Type": 2
    },
    {
      "ID": "User",
      "Type": 2
    },
    {
      "ID": "NotAgentic",
      "Type": 2
    }
  ],
  "ActorContextId": "00000000-0000-0000-0000-000000000001",
  "AzureActiveDirectoryEventType": 1,
  "CreationTime": "2026-07-03T01:52:29Z",
  "ExtendedProperties": [
    {
      "Name": "additionalDetails",
      "Value": {
        "User-Agent": "python/3.13.9 (Linux-6.1.0-41-amd64-x86_64-with-glibc2.36) AZURECLI/2.82.0 (DEB)"
      }
    },
    {
      "Name": "extendedAuditEventCategory",
      "Value": "Group"
    }
  ],
  "Id": "3892d90d-6864-4119-bc44-d3905cdc6ff8",
  "InterSystemsId": "402aaf03-a057-42a7-a135-7fb5edc20afc",
  "IntraSystemId": "e369da91-5836-470b-85bc-3f07c1f2416b",
  "ModifiedProperties": [
    {
      "Name": "DisplayName",
      "NewValue": [
        "dw-harness-78619d48"
      ],
      "OldValue": []
    },
    {
      "Name": "MailEnabled",
      "NewValue": [
        false
      ],
      "OldValue": []
    },
    {
      "Name": "MailNickname",
      "NewValue": [
        "dwharn78619d48"
      ],
      "OldValue": []
    },
    {
      "Name": "RenewedDateTime",
      "NewValue": [
        "2026-07-03T01:52:29Z"
      ],
      "OldValue": []
    },
    {
      "Name": "SecurityEnabled",
      "NewValue": [
        true
      ],
      "OldValue": []
    },
    {
      "Name": "Included Updated Properties",
      "NewValue": "DisplayName, MailEnabled, MailNickname, RenewedDateTime, SecurityEnabled",
      "OldValue": ""
    }
  ],
  "ObjectId": "Group_60a4e99d-f269-49b2-9b9c-b4fc0d4e7f69",
  "Operation": "Add group.",
  "OrganizationId": "00000000-0000-0000-0000-000000000001",
  "RecordType": 8,
  "ResultStatus": "Success",
  "Target": [
    {
      "ID": "Group_60a4e99d-f269-49b2-9b9c-b4fc0d4e7f69",
      "Type": 2
    },
    {
      "ID": "60a4e99d-f269-49b2-9b9c-b4fc0d4e7f69",
      "Type": 2
    },
    {
      "ID": "Group",
      "Type": 2
    },
    {
      "ID": "dw-harness-78619d48",
      "Type": 1
    }
  ],
  "TargetContextId": "00000000-0000-0000-0000-000000000001",
  "UserId": "adminuser@example.onmicrosoft.com",
  "UserKey": "1111111111111111@example.onmicrosoft.com",
  "UserType": 0,
  "Version": 1,
  "Workload": "AzureActiveDirectory"
}

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
security_result.action (Chronicle)eqBLOCK1 rulechronicle

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

YARA-L #

References #

Add label.

#
RecordType
AzureActiveDirectory

Description

Add label. activity in Microsoft Entra ID, recorded in the Unified Audit Log (observed in first-party capture).

Example Audit Record #

{
  "Actor": [
    {
      "ID": "Microsoft Exchange Online Protection",
      "Type": 1
    },
    {
      "ID": "00000007-0000-0ff1-ce00-000000000000",
      "Type": 2
    },
    {
      "ID": "ServicePrincipal_7346eb28-2787-4db2-8f6e-a9ebdeec5988",
      "Type": 2
    },
    {
      "ID": "7346eb28-2787-4db2-8f6e-a9ebdeec5988",
      "Type": 2
    },
    {
      "ID": "ServicePrincipal",
      "Type": 2
    },
    {
      "ID": "NotAgentic",
      "Type": 2
    }
  ],
  "ActorContextId": "11111111-1111-1111-1111-111111111111",
  "AzureActiveDirectoryEventType": 1,
  "CreationDate": "2026-07-03T06:00:18",
  "CreationTime": "2026-07-03T06:00:18",
  "ExtendedProperties": [
    {
      "Name": "additionalDetails",
      "Value": {}
    },
    {
      "Name": "extendedAuditEventCategory",
      "Value": "Label"
    }
  ],
  "Id": "0416eba4-a275-4388-a69e-cf02ac17b390",
  "InterSystemsId": "ce4fbd01-9437-4653-b3e8-e3e160c50f11",
  "IntraSystemId": "00000000-0000-0000-0000-000000000000",
  "ModifiedProperties": [
    {
      "Name": "DisplayName",
      "NewValue": [
        "dwharnee8749b4 label"
      ],
      "OldValue": []
    },
    {
      "Name": "LabelId",
      "NewValue": [
        "93b80c3d-9d7c-459f-9ff8-53a551853113"
      ],
      "OldValue": []
    },
    {
      "Name": "Included Updated Properties",
      "NewValue": "DisplayName, LabelId",
      "OldValue": ""
    }
  ],
  "ObjectId": "Label_9ce4f699-9b6f-466b-a698-9da68b7a45b3",
  "Operation": "Add label.",
  "Operations": "Add label.",
  "OrganizationId": "11111111-1111-1111-1111-111111111111",
  "RecordType": "AzureActiveDirectory",
  "ResultStatus": "Success",
  "Target": [
    {
      "ID": "Label_9ce4f699-9b6f-466b-a698-9da68b7a45b3",
      "Type": 2
    },
    {
      "ID": "9ce4f699-9b6f-466b-a698-9da68b7a45b3",
      "Type": 2
    },
    {
      "ID": "Other",
      "Type": 2
    },
    {
      "ID": "dwharnee8749b4 label",
      "Type": 1
    }
  ],
  "TargetContextId": "11111111-1111-1111-1111-111111111111",
  "UserId": "ServicePrincipal_7346eb28-2787-4db2-8f6e-a9ebdeec5988",
  "UserKey": "Not Available",
  "UserType": "System",
  "Version": 1,
  "Workload": "AzureActiveDirectory"
}

References #

Add member to administrative unit.

#
RecordType
AzureActiveDirectory

Description

Add member to administrative unit. activity in Microsoft Entra ID, recorded in the Unified Audit Log (observed in first-party capture).

Example Audit Record #

{
  "Actor": [
    {
      "ID": "adminuser@example.onmicrosoft.com",
      "Type": 5
    },
    {
      "ID": 1111111111111111,
      "Type": 3
    },
    {
      "ID": "User_aaaaaaaa-0000-0000-0000-000000000001",
      "Type": 2
    },
    {
      "ID": "aaaaaaaa-0000-0000-0000-000000000001",
      "Type": 2
    },
    {
      "ID": "User",
      "Type": 2
    },
    {
      "ID": "NotAgentic",
      "Type": 2
    }
  ],
  "ActorContextId": "11111111-1111-1111-1111-111111111111",
  "AzureActiveDirectoryEventType": 1,
  "CreationDate": "2026-07-03T03:23:05",
  "CreationTime": "2026-07-03T03:23:05",
  "ExtendedProperties": [
    {
      "Name": "additionalDetails",
      "Value": {
        "User-Agent": "python/3.13.9 (Linux-6.1.0-41-amd64-x86_64-with-glibc2.36) AZURECLI/2.82.0 (DEB)"
      }
    },
    {
      "Name": "extendedAuditEventCategory",
      "Value": "AdministrativeUnit"
    }
  ],
  "Id": "78072ba4-e967-4c5e-a116-05bdb3e17fd7",
  "InterSystemsId": "25def137-b2ec-414d-94fa-5bc7746bdf42",
  "IntraSystemId": "c6d22437-2973-4763-910d-5c99181df2ee",
  "ModifiedProperties": [
    {
      "Name": "AdministrativeUnit.ObjectID",
      "NewValue": "78e00ff9-4f90-4a2d-ba46-416e73ce7793",
      "OldValue": ""
    },
    {
      "Name": "AdministrativeUnit.DisplayName",
      "NewValue": "dw-harness-aum-2fe5ab51",
      "OldValue": ""
    }
  ],
  "ObjectId": "adminuser@example.onmicrosoft.com",
  "Operation": "Add member to administrative unit.",
  "Operations": "Add member to administrative unit.",
  "OrganizationId": "11111111-1111-1111-1111-111111111111",
  "RecordType": "AzureActiveDirectory",
  "ResultStatus": "Success",
  "Target": [
    {
      "ID": "User_aaaaaaaa-0000-0000-0000-000000000001",
      "Type": 2
    },
    {
      "ID": "aaaaaaaa-0000-0000-0000-000000000001",
      "Type": 2
    },
    {
      "ID": "User",
      "Type": 2
    },
    {
      "ID": "NotAgentic",
      "Type": 2
    },
    {
      "ID": "adminuser@example.onmicrosoft.com",
      "Type": 5
    },
    {
      "ID": 1111111111111111,
      "Type": 3
    }
  ],
  "TargetContextId": "11111111-1111-1111-1111-111111111111",
  "UserId": "adminuser@example.onmicrosoft.com",
  "UserKey": "1111111111111111@example.onmicrosoft.com",
  "UserType": "Regular",
  "Version": 1,
  "Workload": "AzureActiveDirectory"
}

References #

Add member to group.

#
RecordType
AzureActiveDirectory

Description

A principal was added to a group in Azure Active Directory (the UAL operation string includes a trailing period).

Example Audit Record #

{
  "Actor": [
    {
      "ID": "adminuser@example.onmicrosoft.com",
      "Type": 5
    },
    {
      "ID": 1111111111111111,
      "Type": 3
    },
    {
      "ID": "User_11111111-1111-1111-1111-111111111111",
      "Type": 2
    },
    {
      "ID": "11111111-1111-1111-1111-111111111111",
      "Type": 2
    },
    {
      "ID": "User",
      "Type": 2
    },
    {
      "ID": "NotAgentic",
      "Type": 2
    }
  ],
  "ActorContextId": "00000000-0000-0000-0000-000000000001",
  "AzureActiveDirectoryEventType": 1,
  "CreationTime": "2026-07-03T03:22:09Z",
  "ExtendedProperties": [
    {
      "Name": "additionalDetails",
      "Value": {
        "User-Agent": "python/3.13.9 (Linux-6.1.0-41-amd64-x86_64-with-glibc2.36) AZURECLI/2.82.0 (DEB)"
      }
    },
    {
      "Name": "extendedAuditEventCategory",
      "Value": "Group"
    }
  ],
  "Id": "ffe7bece-d342-4429-9a9a-65dc80a52de5",
  "InterSystemsId": "a1a73bd6-8cca-4d59-b646-1608ac944b41",
  "IntraSystemId": "00000000-0000-0000-0000-000000000000",
  "ModifiedProperties": [
    {
      "Name": "Group.ObjectID",
      "NewValue": "6b01a770-1193-453a-b3f4-d9a24a6e7060",
      "OldValue": ""
    },
    {
      "Name": "Group.DisplayName",
      "NewValue": "dw-harness-2fe5ab51",
      "OldValue": ""
    }
  ],
  "ObjectId": "adminuser@example.onmicrosoft.com",
  "Operation": "Add member to group.",
  "OrganizationId": "00000000-0000-0000-0000-000000000001",
  "RecordType": 8,
  "ResultStatus": "Success",
  "Target": [
    {
      "ID": "User_11111111-1111-1111-1111-111111111111",
      "Type": 2
    },
    {
      "ID": "11111111-1111-1111-1111-111111111111",
      "Type": 2
    },
    {
      "ID": "User",
      "Type": 2
    },
    {
      "ID": "NotAgentic",
      "Type": 2
    },
    {
      "ID": "adminuser@example.onmicrosoft.com",
      "Type": 5
    },
    {
      "ID": 1111111111111111,
      "Type": 3
    }
  ],
  "TargetContextId": "00000000-0000-0000-0000-000000000001",
  "UserId": "adminuser@example.onmicrosoft.com",
  "UserKey": "1111111111111111@example.onmicrosoft.com",
  "UserType": 0,
  "Version": 1,
  "Workload": "AzureActiveDirectory"
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

YARA-L #

References #

Add member to role.

#

Equivalent operation in the other pipeline: Add member to role (Entra ID directory audit)

RecordType
AzureActiveDirectory

Description

A principal was added to an Azure Active Directory directory role (the UAL operation string includes a trailing period).

Example Audit Record #

{
  "Actor": [
    {
      "ID": "MS-PIM",
      "Type": 1
    },
    {
      "ID": "01fc33a7-78ba-4d2f-a4b7-768e336e890e",
      "Type": 2
    },
    {
      "ID": "ServicePrincipal_34d49b97-725f-480d-8971-89b92df5ca70",
      "Type": 2
    },
    {
      "ID": "34d49b97-725f-480d-8971-89b92df5ca70",
      "Type": 2
    },
    {
      "ID": "ServicePrincipal",
      "Type": 2
    }
  ],
  "ActorContextId": "6915b1e0-b081-4829-8866-f1a3e883a9ae",
  "ActorIpAddress": "172.170.254.43",
  "AzureActiveDirectoryEventType": 1,
  "ClientIP": "172.170.254.43",
  "CreationTime": "2024-03-21T13:08:48",
  "ExtendedProperties": [
    {
      "Name": "additionalDetails",
      "Value": {}
    },
    {
      "Name": "extendedAuditEventCategory",
      "Value": "Role"
    }
  ],
  "Id": "0bc79ad5-7c63-44ab-9495-f9e08d315e8e",
  "InterSystemsId": "636a211d-7b24-448c-b618-04975c7fb2e4",
  "IntraSystemId": "3921fc01-d201-471f-baf4-a0becf9257c7",
  "ModifiedProperties": [
    {
      "Name": "Role.ObjectID",
      "NewValue": "dc6acb7b-951e-489c-92d5-5b4686ad47d2",
      "OldValue": ""
    },
    {
      "Name": "Role.DisplayName",
      "NewValue": "Privileged Role Administrator",
      "OldValue": ""
    },
    {
      "Name": "Role.TemplateId",
      "NewValue": "e8611ab8-c189-46e8-94e1-60213ab1f814",
      "OldValue": ""
    },
    {
      "Name": "Role.WellKnownObjectName",
      "NewValue": "PrivilegedRoleAdmins",
      "OldValue": ""
    }
  ],
  "ObjectId": "attacker@attack_range.lan",
  "Operation": "Add member to role.",
  "OrganizationId": "6915b1e0-b081-4829-8866-f1a3e883a9ae",
  "RecordType": 8,
  "ResultStatus": "Success",
  "Target": [
    {
      "ID": "User_3921fc01-d201-471f-baf4-a0becf9257c7",
      "Type": 2
    },
    {
      "ID": "3921fc01-d201-471f-baf4-a0becf9257c7",
      "Type": 2
    },
    {
      "ID": "User",
      "Type": 2
    },
    {
      "ID": "attacker_persistence@attack_range",
      "Type": 5
    },
    {
      "ID": "10032001C7E04175",
      "Type": 3
    }
  ],
  "TargetContextId": "6915b1e0-b081-4829-8866-f1a3e883a9ae",
  "UserId": "ServicePrincipal_34d49b97-725f-480d-8971-89b92df5ca70",
  "UserKey": "Not Available",
  "UserType": 4,
  "Version": 1,
  "Workload": "AzureActiveDirectory"
}

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
isprvilegedadrole (splunk rule field)eqtrue2 rulessplunk

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

  • M365 Identity Global Administrator Role Assigned source medium: Identifies when the Microsoft 365 Global Administrator or Company Administrator role is assigned to a user or service principal. The Global Administrator role has extensive privileges across Entra ID and Microsoft 365 services, making it a high-value target for adversaries seeking persistent access. Successful assignments of this role may indicate potential privilege escalation or unauthorized access attempts, especially if performed by accounts that do not typically manage high-privilege roles.T1098, T1098.003

Splunk #

YARA-L #

References #

Add owner to application.

#
RecordType
AzureActiveDirectory

Description

Microsoft Entra ID (Azure Active Directory) audit activity in the ApplicationManagement category, recorded in the Office 365 Unified Audit Log.

Example Audit Record #

{
  "CreationTime": "2023-09-07T13:42:04",
  "Id": "6e2c723b-8f6e-47f4-8c60-fa23ef3fccee",
  "Operation": "Add owner to application.",
  "OrganizationId": "48203edf-5d2c-45f2-8123-a368cc8b0e51",
  "RecordType": 8,
  "ResultStatus": "Success",
  "UserKey": "1003BFFD98415B4E@contoso.onmicrosoft.com",
  "UserType": 0,
  "Version": 1,
  "Workload": "AzureActiveDirectory",
  "ObjectId": "user2@contoso.onmicrosoft.com",
  "UserId": "user@contoso.onmicrosoft.com",
  "AzureActiveDirectoryEventType": 1,
  "ExtendedProperties": [
    {
      "Name": "additionalDetails",
      "Value": {
        "User-Agent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Safari/537.36"
      }
    },
    {
      "Name": "extendedAuditEventCategory",
      "Value": "Application"
    }
  ],
  "ModifiedProperties": [
    {
      "Name": "Application.ObjectID",
      "NewValue": "a2d68f8b-ab9f-47ac-934f-b966c3ac134f",
      "OldValue": ""
    },
    {
      "Name": "Application.DisplayName",
      "NewValue": "TestApp2",
      "OldValue": ""
    },
    {
      "Name": "Application.AppId",
      "NewValue": "95106c0e-3519-450e-8e38-7f326d873454",
      "OldValue": ""
    }
  ],
  "Actor": [
    {
      "ID": "user@contoso.onmicrosoft.com",
      "Type": 5
    },
    {
      "ID": "1003BFFD98415B4E",
      "Type": 3
    },
    {
      "ID": "18ed3507-a475-4ccb-b669-d66bc9f2a36e",
      "Type": 2
    },
    {
      "ID": "User_e4c722ac-3b83-478d-8f52-c388885dc30f",
      "Type": 2
    },
    {
      "ID": "e4c722ac-3b83-478d-8f52-c388885dc30f",
      "Type": 2
    },
    {
      "ID": "User",
      "Type": 2
    }
  ],
  "ActorContextId": "48203edf-5d2c-45f2-8123-a368cc8b0e51",
  "InterSystemsId": "3f6a58c5-2fba-401d-b137-82b860830213",
  "IntraSystemId": "e8034ddc-0ca3-4aca-996c-1dc6dee48679",
  "Target": [
    {
      "ID": "User_57e4bd36-9722-4a4a-9729-7203d8e00b72",
      "Type": 2
    },
    {
      "ID": "57e4bd36-9722-4a4a-9729-7203d8e00b72",
      "Type": 2
    },
    {
      "ID": "User",
      "Type": 2
    },
    {
      "ID": "user2@contoso.onmicrosoft.com",
      "Type": 5
    },
    {
      "ID": "10032002CC029AE9",
      "Type": 3
    }
  ],
  "TargetContextId": "48203edf-5d2c-45f2-8123-a368cc8b0e51"
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Splunk #

  • O365 Application Registration Owner Added source: The following analytic identifies instances where a new owner is assigned to an application registration within an Azure AD and Office 365 tenant. It leverages O365 audit logs, specifically events related to changes in owner assignments…T1098

References #

Add owner to group.

#
RecordType
AzureActiveDirectory

Description

An owner was added to a group.

Example Audit Record #

{
  "Actor": [
    {
      "ID": "adminuser@example.onmicrosoft.com",
      "Type": 5
    },
    {
      "ID": 1111111111111111,
      "Type": 3
    },
    {
      "ID": "Microsoft Teams Services",
      "Type": 1
    },
    {
      "ID": "cc15fd57-2c6c-4117-a88c-83b1d56b4bbe",
      "Type": 2
    },
    {
      "ID": "User_11111111-1111-1111-1111-111111111111",
      "Type": 2
    },
    {
      "ID": "11111111-1111-1111-1111-111111111111",
      "Type": 2
    },
    {
      "ID": "User",
      "Type": 2
    },
    {
      "ID": "NotAgentic",
      "Type": 2
    }
  ],
  "ActorContextId": "00000000-0000-0000-0000-000000000001",
  "AzureActiveDirectoryEventType": 1,
  "CreationTime": "2026-07-03T01:56:53Z",
  "ExtendedProperties": [
    {
      "Name": "additionalDetails",
      "Value": {
        "User-Agent": "TeamsMiddleTier/1.0a$*+"
      }
    },
    {
      "Name": "extendedAuditEventCategory",
      "Value": "Group"
    }
  ],
  "Id": "752ea005-96c5-4c55-83bb-7f3f6ed2b632",
  "InterSystemsId": "5d996715-22d3-4d25-b7ef-6ffae2513809",
  "IntraSystemId": "f4df435a-dd38-432e-a44b-e2ceebc83e0c",
  "ModifiedProperties": [
    {
      "Name": "Group.ObjectID",
      "NewValue": "324441a1-2f31-4d13-9d24-c24ad8bf950b",
      "OldValue": ""
    },
    {
      "Name": "Group.DisplayName",
      "NewValue": "dw-harness-a9dd06c7",
      "OldValue": ""
    },
    {
      "Name": "ActorId.ServicePrincipalNames",
      "NewValue": "cc15fd57-2c6c-4117-a88c-83b1d56b4bbe;https://api.spaces.skype.com/;https://teams.microsoft.com;https://api.spaces.skype.com;https://api.gcc.teams.microsoft.com;https://teams.microsoft.com/;https://middletier.dod.teams.microsoft.us;https://middletier.gov.teams.microsoft.us;https://teams.cloud.microsoft",
      "OldValue": ""
    },
    {
      "Name": "SPN",
      "NewValue": "cc15fd57-2c6c-4117-a88c-83b1d56b4bbe;https://api.spaces.skype.com/;https://teams.microsoft.com;https://api.spaces.skype.com;https://api.gcc.teams.microsoft.com;https://teams.microsoft.com/;https://middletier.dod.teams.microsoft.us;https://middletier.gov.teams.microsoft.us;https://teams.cloud.microsoft",
      "OldValue": ""
    }
  ],
  "ObjectId": "adminuser@example.onmicrosoft.com",
  "Operation": "Add owner to group.",
  "OrganizationId": "00000000-0000-0000-0000-000000000001",
  "RecordType": 8,
  "ResultStatus": "Success",
  "Target": [
    {
      "ID": "User_11111111-1111-1111-1111-111111111111",
      "Type": 2
    },
    {
      "ID": "11111111-1111-1111-1111-111111111111",
      "Type": 2
    },
    {
      "ID": "User",
      "Type": 2
    },
    {
      "ID": "NotAgentic",
      "Type": 2
    },
    {
      "ID": "adminuser@example.onmicrosoft.com",
      "Type": 5
    },
    {
      "ID": 1111111111111111,
      "Type": 3
    }
  ],
  "TargetContextId": "00000000-0000-0000-0000-000000000001",
  "UserId": "adminuser@example.onmicrosoft.com",
  "UserKey": "1111111111111111@example.onmicrosoft.com",
  "UserType": 0,
  "Version": 1,
  "Workload": "AzureActiveDirectory"
}

References #

Add permission grant policy.

#
RecordType
AzureActiveDirectory

Description

Add permission grant policy. activity in Microsoft Entra ID, recorded in the Unified Audit Log (observed in first-party capture).

Example Audit Record #

{
  "Actor": [
    {
      "ID": "adminuser@example.onmicrosoft.com",
      "Type": 5
    },
    {
      "ID": 1111111111111111,
      "Type": 3
    },
    {
      "ID": "User_aaaaaaaa-0000-0000-0000-000000000001",
      "Type": 2
    },
    {
      "ID": "aaaaaaaa-0000-0000-0000-000000000001",
      "Type": 2
    },
    {
      "ID": "User",
      "Type": 2
    },
    {
      "ID": "NotAgentic",
      "Type": 2
    }
  ],
  "ActorContextId": "11111111-1111-1111-1111-111111111111",
  "AzureActiveDirectoryEventType": 1,
  "CreationDate": "2026-07-03T01:53:05",
  "CreationTime": "2026-07-03T01:53:05",
  "ExtendedProperties": [
    {
      "Name": "additionalDetails",
      "Value": {
        "User-Agent": "python/3.13.9 (Linux-6.1.0-41-amd64-x86_64-with-glibc2.36) AZURECLI/2.82.0 (DEB)"
      }
    },
    {
      "Name": "extendedAuditEventCategory",
      "Value": "PermissionGrantPolicy"
    }
  ],
  "Id": "370b6676-3b9c-44be-8b4b-632f54c22b5c",
  "InterSystemsId": "f964ab16-6186-467a-99c0-ef6fce7d43ff",
  "IntraSystemId": "00000000-0000-0000-0000-000000000000",
  "ModifiedProperties": [
    {
      "Name": "PermissionGrantPolicy",
      "NewValue": {
        "EncodingVersion": 2,
        "Id": "dwharn-pgp-78619d48",
        "Includes": [],
        "Excludes": [],
        "DisplayName": "dw-harness-pgp-78619d48",
        "Description": "harness",
        "IncludeAllPreApprovedApplications": false,
        "ConsentResourceScopeType": "tenant"
      },
      "OldValue": ""
    }
  ],
  "ObjectId": "PermissionGrantPolicy_82aca392-bf62-49e7-a864-e071ba0e544d",
  "Operation": "Add permission grant policy.",
  "Operations": "Add permission grant policy.",
  "OrganizationId": "11111111-1111-1111-1111-111111111111",
  "RecordType": "AzureActiveDirectory",
  "ResultStatus": "Success",
  "Target": [
    {
      "ID": "PermissionGrantPolicy_82aca392-bf62-49e7-a864-e071ba0e544d",
      "Type": 2
    },
    {
      "ID": "82aca392-bf62-49e7-a864-e071ba0e544d",
      "Type": 2
    },
    {
      "ID": "Other",
      "Type": 2
    }
  ],
  "TargetContextId": "11111111-1111-1111-1111-111111111111",
  "UserId": "adminuser@example.onmicrosoft.com",
  "UserKey": "1111111111111111@example.onmicrosoft.com",
  "UserType": "Regular",
  "Version": 1,
  "Workload": "AzureActiveDirectory"
}

References #

Add policy.

#
RecordType
AzureActiveDirectory

Description

A directory policy object was created.

Example Audit Record #

{
  "Actor": [
    {
      "ID": "adminuser@example.onmicrosoft.com",
      "Type": 5
    },
    {
      "ID": 1111111111111111,
      "Type": 3
    },
    {
      "ID": "User_11111111-1111-1111-1111-111111111111",
      "Type": 2
    },
    {
      "ID": "11111111-1111-1111-1111-111111111111",
      "Type": 2
    },
    {
      "ID": "User",
      "Type": 2
    },
    {
      "ID": "NotAgentic",
      "Type": 2
    }
  ],
  "ActorContextId": "00000000-0000-0000-0000-000000000001",
  "AzureActiveDirectoryEventType": 1,
  "CreationTime": "2026-07-03T03:22:52Z",
  "ExtendedProperties": [
    {
      "Name": "additionalDetails",
      "Value": {
        "User-Agent": "python/3.13.9 (Linux-6.1.0-41-amd64-x86_64-with-glibc2.36) AZURECLI/2.82.0 (DEB)"
      }
    },
    {
      "Name": "extendedAuditEventCategory",
      "Value": "Policy"
    }
  ],
  "Id": "7738b439-5a87-4fd7-ac1f-d0969ab9a76b",
  "InterSystemsId": "5f65aed3-e4d0-4004-8a8b-e5ea8af701ef",
  "IntraSystemId": "8f8eb1aa-47fb-42b4-933f-ec8e4d7bd654",
  "ModifiedProperties": [
    {
      "Name": "DisplayName",
      "NewValue": [
        "dw-harness-cmp-2fe5ab51"
      ],
      "OldValue": []
    },
    {
      "Name": "PolicyType",
      "NewValue": [
        "ClaimsMappingPolicy"
      ],
      "OldValue": []
    },
    {
      "Name": "Included Updated Properties",
      "NewValue": "DisplayName, PolicyType",
      "OldValue": ""
    }
  ],
  "ObjectId": "Policy_f3feb286-060d-4879-a185-739c2cd4c8f5",
  "Operation": "Add policy.",
  "OrganizationId": "00000000-0000-0000-0000-000000000001",
  "RecordType": 8,
  "ResultStatus": "Success",
  "Target": [
    {
      "ID": "Policy_f3feb286-060d-4879-a185-739c2cd4c8f5",
      "Type": 2
    },
    {
      "ID": "f3feb286-060d-4879-a185-739c2cd4c8f5",
      "Type": 2
    },
    {
      "ID": "Policy",
      "Type": 2
    },
    {
      "ID": "dw-harness-cmp-2fe5ab51",
      "Type": 1
    }
  ],
  "TargetContextId": "00000000-0000-0000-0000-000000000001",
  "UserId": "adminuser@example.onmicrosoft.com",
  "UserKey": "1111111111111111@example.onmicrosoft.com",
  "UserType": 0,
  "Version": 1,
  "Workload": "AzureActiveDirectory"
}

References #

Add registered users to device.

#

Equivalent operation in the other pipeline: Add registered users to device (Entra ID directory audit)

RecordType
AzureActiveDirectory

Description

Registered users were added to a device object in Azure Active Directory (the UAL operation string includes a trailing period).

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

  • M365 Identity OAuth Flow by User Sign-in to Device Registration source high: Identifies attempts to register a new device in Microsoft Entra ID after OAuth authentication with authorization code grant. Adversaries may use OAuth phishing techniques to obtain an OAuth authorization code, which can then be exchanged for access and refresh tokens. This rule detects a sequence of events where a user principal authenticates via OAuth, followed by a device registration event, indicating potential misuse of the OAuth flow to establish persistence or access resources.T1098, T1098.005, T1528, T1566, T1566.002

References #

Add role definition.

#
RecordType
AzureActiveDirectory

Description

Add role definition. activity in Microsoft Entra ID, recorded in the Unified Audit Log (observed in first-party capture).

Example Audit Record #

{
  "Actor": [
    {
      "ID": "adminuser@example.onmicrosoft.com",
      "Type": 5
    },
    {
      "ID": 1111111111111111,
      "Type": 3
    },
    {
      "ID": "User_aaaaaaaa-0000-0000-0000-000000000001",
      "Type": 2
    },
    {
      "ID": "aaaaaaaa-0000-0000-0000-000000000001",
      "Type": 2
    },
    {
      "ID": "User",
      "Type": 2
    },
    {
      "ID": "NotAgentic",
      "Type": 2
    }
  ],
  "ActorContextId": "11111111-1111-1111-1111-111111111111",
  "AzureActiveDirectoryEventType": 1,
  "CreationDate": "2026-07-03T03:22:47",
  "CreationTime": "2026-07-03T03:22:47",
  "ExtendedProperties": [
    {
      "Name": "additionalDetails",
      "Value": {
        "User-Agent": "python/3.13.9 (Linux-6.1.0-41-amd64-x86_64-with-glibc2.36) AZURECLI/2.82.0 (DEB)"
      }
    },
    {
      "Name": "extendedAuditEventCategory",
      "Value": "RoleDefinition"
    }
  ],
  "Id": "8d7f0c90-5645-4809-9364-66b1ce1abfc4",
  "InterSystemsId": "c631a647-66b1-40d3-9a58-7f616841f98f",
  "IntraSystemId": "3d6dde62-7d73-4472-b528-c46ec2c4975e",
  "ModifiedProperties": [
    {
      "Name": "DisplayName",
      "NewValue": [
        "dw-harness-role-2fe5ab51"
      ],
      "OldValue": []
    },
    {
      "Name": "GrantedPermissions",
      "NewValue": [
        {
          "Actions": [
            {
              "ResourceCategory": "AadDirectory",
              "ResourceType": "Group",
              "TaskType": "Read",
              "ReadPropertySet": "Basic",
              "WritePropertySet": "None",
              "TaskTypeSubsetName": null
            }
          ],
          "Condition": null,
          "ScopeConstraints": [],
          "IsPrivileged": false
        }
      ],
      "OldValue": []
    },
    {
      "Name": "Included Updated Properties",
      "NewValue": "DisplayName, GrantedPermissions",
      "OldValue": ""
    }
  ],
  "ObjectId": "RoleDefinition_799abf44-b19b-4605-9606-2125d16ff1c8",
  "Operation": "Add role definition.",
  "Operations": "Add role definition.",
  "OrganizationId": "11111111-1111-1111-1111-111111111111",
  "RecordType": "AzureActiveDirectory",
  "ResultStatus": "Success",
  "Target": [
    {
      "ID": "RoleDefinition_799abf44-b19b-4605-9606-2125d16ff1c8",
      "Type": 2
    },
    {
      "ID": "799abf44-b19b-4605-9606-2125d16ff1c8",
      "Type": 2
    },
    {
      "ID": "Other",
      "Type": 2
    },
    {
      "ID": "dw-harness-role-2fe5ab51",
      "Type": 1
    }
  ],
  "TargetContextId": "11111111-1111-1111-1111-111111111111",
  "UserId": "adminuser@example.onmicrosoft.com",
  "UserKey": "1111111111111111@example.onmicrosoft.com",
  "UserType": "Regular",
  "Version": 1,
  "Workload": "AzureActiveDirectory"
}

References #

Add service principal credentials.

#
RecordType
AzureActiveDirectory

Description

Credentials were added to a service principal (common persistence technique).

Example Audit Record #

{
  "Actor": [
    {
      "ID": "rodsoto@rodsoto.onmicrosoft.com",
      "Type": 5
    },
    {
      "ID": "10037FFEA938FB92",
      "Type": 3
    },
    {
      "ID": "74658136-14ec-4630-ad9b-26e160ff0fc6",
      "Type": 2
    },
    {
      "ID": "User_bfb8c366-0406-41a5-b3e3-328f4a3b4484",
      "Type": 2
    },
    {
      "ID": "bfb8c366-0406-41a5-b3e3-328f4a3b4484",
      "Type": 2
    },
    {
      "ID": "User",
      "Type": 2
    }
  ],
  "ActorContextId": "0e8108b1-18e9-41a4-961b-dfcddf92ef08",
  "ActorIpAddress": "40.124.84.4",
  "AzureActiveDirectoryEventType": 1,
  "ClientIP": "40.124.84.4",
  "CreationTime": "2021-01-20T03:10:09",
  "ExtendedProperties": [
    {
      "Name": "additionalDetails",
      "Value": {}
    },
    {
      "Name": "extendedAuditEventCategory",
      "Value": "ServicePrincipal"
    }
  ],
  "Id": "e312b173-45bb-469f-bf3d-cc8709a14dd6",
  "InterSystemsId": "f2a86789-6357-4f08-9ff7-d6d2d86cbde0",
  "IntraSystemId": "6fc81447-9c94-4734-8bd7-307bb699c098",
  "ModifiedProperties": [
    {
      "Name": "KeyDescription",
      "NewValue": [
        "[KeyIdentifier=f4f7a4fb-6445-4b38-885f-fc634a60f805,KeyType=AsymmetricX509Cert,KeyUsage=Verify,DisplayName=CN=Microsoft Azure Federated SSO Certificate]",
        "[KeyIdentifier=d90a353c-2b06-44ad-a436-f54e2ba8129c,KeyType=X509CertAndPassword,KeyUsage=Sign,DisplayName=CN=Microsoft Azure Federated SSO Certificate]",
        "[KeyIdentifier=c34a9808-c377-47e9-b01f-545ec1129ab2,KeyType=X509CertAndPassword,KeyUsage=Sign,DisplayName=CN=adfs.attackrange.local]",
        "[KeyIdentifier=e420d926-6608-4844-9a32-03cc400481c2,KeyType=AsymmetricX509Cert,KeyUsage=Verify,DisplayName=CN=adfs.attackrange.local]"
      ],
      "OldValue": [
        "[KeyIdentifier=d90a353c-2b06-44ad-a436-f54e2ba8129c,KeyType=X509CertAndPassword,KeyUsage=Sign,DisplayName=CN=Microsoft Azure Federated SSO Certificate]",
        "[KeyIdentifier=f4f7a4fb-6445-4b38-885f-fc634a60f805,KeyType=AsymmetricX509Cert,KeyUsage=Verify,DisplayName=CN=Microsoft Azure Federated SSO Certificate]"
      ]
    },
    {
      "Name": "Included Updated Properties",
      "NewValue": "KeyDescription",
      "OldValue": ""
    },
    {
      "Name": "TargetId.ServicePrincipalNames",
      "NewValue": "https://signin.aws.amazon.com/saml;3e71560f-3e31-45ab-b439-46328fe55b88",
      "OldValue": ""
    }
  ],
  "ObjectId": "https://signin.aws.amazon.com/saml;3e71560f-3e31-45ab-b439-46328fe55b88",
  "Operation": "Add service principal credentials.",
  "OrganizationId": "0e8108b1-18e9-41a4-961b-dfcddf92ef08",
  "RecordType": 8,
  "ResultStatus": "Success",
  "Target": [
    {
      "ID": "ServicePrincipal_9fd10db9-dfe2-4d74-a724-c837eb8764d9",
      "Type": 2
    },
    {
      "ID": "9fd10db9-dfe2-4d74-a724-c837eb8764d9",
      "Type": 2
    },
    {
      "ID": "ServicePrincipal",
      "Type": 2
    },
    {
      "ID": "Amazon Web Services (AWS)",
      "Type": 1
    },
    {
      "ID": "3e71560f-3e31-45ab-b439-46328fe55b88",
      "Type": 2
    },
    {
      "ID": "https://signin.aws.amazon.com/saml;3e71560f-3e31-45ab-b439-46328fe55b88",
      "Type": 4
    }
  ],
  "TargetContextId": "0e8108b1-18e9-41a4-961b-dfcddf92ef08",
  "UserId": "rodsoto@rodsoto.onmicrosoft.com",
  "UserKey": "10037FFEA938FB92@rodsoto.onmicrosoft.com",
  "UserType": 0,
  "Version": 1,
  "Workload": "AzureActiveDirectory"
}

References #

Add service principal.

#
RecordType
AzureActiveDirectory

Description

Microsoft Entra ID (Azure Active Directory) audit activity in the ApplicationManagement category, recorded in the Office 365 Unified Audit Log.

Example Audit Record #

{
  "CreationTime": "2023-07-20T06:39:58",
  "Id": "152e701f-3a83-4553-8ef6-e04cb5691976",
  "Operation": "Add service principal.",
  "OrganizationId": "a417c578-c7ee-480d-a225-d48057e74df5",
  "RecordType": 8,
  "ResultStatus": "Success",
  "UserKey": "testing@office365.onmicrosoft.com",
  "UserType": 0,
  "Version": 1,
  "Workload": "AzureActiveDirectory",
  "ObjectId": "5cde9487-f84d-44c4-9715-2e856b6811ef",
  "UserId": "Testeruser@office365.onmicrosoft.com",
  "AzureActiveDirectoryEventType": 1,
  "ExtendedProperties": [
    {
      "Name": "additionalDetails",
      "Value": {
        "User-Agent": "Mozilla/5.0 Test Lab Machine) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/114.0.0.0 Safari/537.36",
        "AppId": "5cde9487-f84d-44c4-9715-2e856b6811ef"
      }
    },
    {
      "Name": "extendedAuditEventCategory",
      "Value": "ServicePrincipal"
    }
  ],
  "ModifiedProperties": [
    {
      "Name": "AccountEnabled",
      "NewValue": [
        true
      ],
      "OldValue": []
    },
    {
      "Name": "AppAddress",
      "NewValue": [
        {
          "AddressType": 0,
          "Address": "https://10.1.67.69/rest/handler/microsoftteams_6ba1906f-5899-44df-bb65-1bee4df8ca3c/test/result",
          "ReplyAddressClientType": 1,
          "ReplyAddressIndex": null,
          "IsReplyAddressDefault": false
        }
      ],
      "OldValue": []
    },
    {
      "Name": "AppPrincipalId",
      "NewValue": [
        "5cde9487-f84d-44c4-9715-2e856b6811ef"
      ],
      "OldValue": []
    },
    {
      "Name": "DisplayName",
      "NewValue": [
        "test-msteams"
      ],
      "OldValue": []
    },
    {
      "Name": "ServicePrincipalName",
      "NewValue": [
        "5cde9487-f84d-44c4-9715-2e856b6811ef"
      ],
      "OldValue": []
    },
    {
      "Name": "Credential",
      "NewValue": [
        {
          "CredentialType": 2,
          "KeyStoreId": "291154f0-a9f5-45bb-87be-9c8ee5b6d62c",
          "KeyGroupId": "291154f0-a9f5-45bb-87be-9c8ee5b6d62c"
        }
      ],
      "OldValue": []
    },
    {
      "Name": "Included Updated Properties",
      "NewValue": "AccountEnabled, AppAddress, AppPrincipalId, DisplayName, ServicePrincipalName, Credential",
      "OldValue": ""
    },
    {
      "Name": "TargetId.ServicePrincipalNames",
      "NewValue": "5cde9487-f84d-44c4-9715-2e856b6811ef",
      "OldValue": ""
    }
  ],
  "Actor": [
    {
      "ID": "Testeruser@office365.onmicrosoft.com",
      "Type": 5
    },
    {
      "ID": "1003BFFD98415B4E",
      "Type": 3
    },
    {
      "ID": "18ed3507-a475-4ccb-b669-d66bc9f2a36e",
      "Type": 2
    },
    {
      "ID": "User_e4c722ac-3b83-478d-8f52-c388885dc30f",
      "Type": 2
    },
    {
      "ID": "e4c722ac-3b83-478d-8f52-c388885dc30f",
      "Type": 2
    },
    {
      "ID": "User",
      "Type": 2
    }
  ],
  "ActorContextId": "a417c578-c7ee-480d-a225-d48057e74df5",
  "InterSystemsId": "6dbb2be0-aa75-477d-b231-aaf418c665e7",
  "IntraSystemId": "547aa851-c370-4ce7-aa40-47c576a5bcd3",
  "Target": [
    {
      "ID": "ServicePrincipal_9669aa7b-3517-46d5-a7c4-b040de9ee527",
      "Type": 2
    },
    {
      "ID": "9669aa7b-3517-46d5-a7c4-b040de9ee527",
      "Type": 2
    },
    {
      "ID": "ServicePrincipal",
      "Type": 2
    },
    {
      "ID": "test-msteams",
      "Type": 1
    },
    {
      "ID": "5cde9487-f84d-44c4-9715-2e856b6811ef",
      "Type": 2
    },
    {
      "ID": "5cde9487-f84d-44c4-9715-2e856b6811ef",
      "Type": 4
    }
  ],
  "TargetContextId": "a417c578-c7ee-480d-a225-d48057e74df5"
}

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
unique_apps (splunk rule field)gt32 rulessplunk
userType (splunk rule field)eqserviceprincipal1 rulesplunk

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Splunk #

References #

Add unverified domain.

#
RecordType
AzureActiveDirectory

Description

An unverified custom domain was added to the tenant.

Example Audit Record #

{
  "CreationTime": "2023-07-04T01:42:56",
  "Id": "abfe2230-72b4-4eb1-9361-9d9aee0fcc57",
  "Operation": "Add unverified domain.",
  "OrganizationId": "a417c578-c7ee-480d-a225-d48057e74df5",
  "RecordType": 8,
  "ResultStatus": "Success",
  "UserKey": "testuser@testazure.onmicrosoft.com",
  "UserType": 0,
  "Version": 1,
  "Workload": "AzureActiveDirectory",
  "ObjectId": "Not Available",
  "UserId": "Tester@testazure.onmicrosoft.com",
  "AzureActiveDirectoryEventType": 1,
  "ExtendedProperties": [
    {
      "Name": "additionalDetails",
      "Value": {
        "User-Agent": "Mozilla/5.0 (Test Lab - STRT 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/114.0.0.0 Safari/537.36"
      }
    },
    {
      "Name": "extendedAuditEventCategory",
      "Value": "Domain"
    }
  ],
  "ModifiedProperties": [
    {
      "Name": "Name",
      "NewValue": [
        "attackrange.local"
      ],
      "OldValue": [
        ""
      ]
    },
    {
      "Name": "LiveType",
      "NewValue": [
        "Managed"
      ],
      "OldValue": [
        "None"
      ]
    },
    {
      "Name": "Included Updated Properties",
      "NewValue": "Name,LiveType",
      "OldValue": ""
    }
  ],
  "Actor": [
    {
      "ID": "Tester@testazure.onmicrosoft.com",
      "Type": 5
    },
    {
      "ID": "1003BFFD98415B4E",
      "Type": 3
    },
    {
      "ID": "74658136-14ec-4630-ad9b-26e160ff0fc6",
      "Type": 2
    },
    {
      "ID": "User_e4c722ac-3b83-478d-8f52-c388885dc30f",
      "Type": 2
    },
    {
      "ID": "e4c722ac-3b83-478d-8f52-c388885dc30f",
      "Type": 2
    },
    {
      "ID": "User",
      "Type": 2
    }
  ],
  "ActorContextId": "a417c578-c7ee-480d-a225-d48057e74df5",
  "InterSystemsId": "a8d61658-9949-4dd8-9191-26bf59021da3",
  "IntraSystemId": "3031bdcb-6da7-4c15-8546-3cdf51d2400c",
  "Target": [
    {
      "ID": "attackrange.local",
      "Type": 1
    }
  ],
  "TargetContextId": "a417c578-c7ee-480d-a225-d48057e74df5"
}

References #

Add user.

#
RecordType
AzureActiveDirectory

Description

A new user account was created in the directory.

Example Audit Record #

{
  "Actor": [
    {
      "ID": "victim@attack_range.lan",
      "Type": 5
    },
    {
      "ID": "100300009FBEAAAA",
      "Type": 3
    },
    {
      "ID": "Microsoft B2B Admin Worker",
      "Type": 1
    },
    {
      "ID": "1e2ca66a-c176-45ea-a877-e87f7231e0ee",
      "Type": 2
    },
    {
      "ID": "User_42f229de-3fea-423d-b3aa-23034e486c40",
      "Type": 2
    },
    {
      "ID": "42f229de-3fea-423d-b3aa-23034e486c40",
      "Type": 2
    },
    {
      "ID": "User",
      "Type": 2
    }
  ],
  "ActorContextId": "6915b1e0-b081-4829-8866-f1a3e883a9ae",
  "ActorIpAddress": "52.252.209.205",
  "AzureActiveDirectoryEventType": 1,
  "ClientIP": "52.252.209.205",
  "CreationTime": "2024-03-20T16:38:17",
  "ExtendedProperties": [
    {
      "Name": "additionalDetails",
      "Value": {
        "User-Agent": "Microsoft Azure Graph Client Library 1.0"
      }
    },
    {
      "Name": "extendedAuditEventCategory",
      "Value": "User"
    }
  ],
  "Id": "86da0fd3-df67-4d91-b151-d371eca7bd3e",
  "InterSystemsId": "fb44cdfe-a07f-4a8e-aebf-90c5799bfed9",
  "IntraSystemId": "1916c159-1ad1-44d6-935a-3ee83cafdb4e",
  "ModifiedProperties": [
    {
      "Name": "AccountEnabled",
      "NewValue": [
        true
      ],
      "OldValue": []
    },
    {
      "Name": "CreationType",
      "NewValue": [
        "Invitation"
      ],
      "OldValue": []
    },
    {
      "Name": "DisplayName",
      "NewValue": [
        "attacker"
      ],
      "OldValue": []
    },
    {
      "Name": "InviteTicket",
      "NewValue": [
        {
          "Type": 1,
          "Ticket": "c53f6130-9c7b-4670-ba45-a20f4e7001f3"
        }
      ],
      "OldValue": []
    },
    {
      "Name": "MailNickname",
      "NewValue": [
        "attacker_bad_guy.lol#EXT#"
      ],
      "OldValue": []
    },
    {
      "Name": "OtherMail",
      "NewValue": [
        "attacker@bad_guy.lol"
      ],
      "OldValue": []
    },
    {
      "Name": "ProxyAddresses",
      "NewValue": [
        "SMTP:attacker@bad_guy.lol"
      ],
      "OldValue": []
    },
    {
      "Name": "StsRefreshTokensValidFrom",
      "NewValue": [
        "2024-03-20T16:38:17Z"
      ],
      "OldValue": []
    },
    {
      "Name": "UserPrincipalName",
      "NewValue": [
        "attacker_bad_guy.lol#EXT#@attack_range.onmicrosoft.com"
      ],
      "OldValue": []
    },
    {
      "Name": "UserState",
      "NewValue": [
        "PendingAcceptance"
      ],
      "OldValue": []
    },
    {
      "Name": "UserStateChangedOn",
      "NewValue": [
        "2024-03-20T16:38:17Z"
      ],
      "OldValue": []
    },
    {
      "Name": "UserType",
      "NewValue": [
        "Guest"
      ],
      "OldValue": []
    },
    {
      "Name": "Included Updated Properties",
      "NewValue": "AccountEnabled, CreationType, DisplayName, InviteTicket, MailNickname, OtherMail, ProxyAddresses, StsRefreshTokensValidFrom, UserPrincipalName, UserState, UserStateChangedOn, UserType",
      "OldValue": ""
    },
    {
      "Name": "ActorId.ServicePrincipalNames",
      "NewValue": "https://msb2badminworker.usgovcloudapp.net/;https://msb2badminworker.cloudapp.net/;1e2ca66a-c176-45ea-a877-e87f7231e0ee",
      "OldValue": ""
    },
    {
      "Name": "SPN",
      "NewValue": "https://msb2badminworker.usgovcloudapp.net/;https://msb2badminworker.cloudapp.net/;1e2ca66a-c176-45ea-a877-e87f7231e0ee",
      "OldValue": ""
    }
  ],
  "ObjectId": "attacker_bad_guy.lol#EXT#@attack_range.onmicrosoft.com",
  "Operation": "Add user.",
  "OrganizationId": "6915b1e0-b081-4829-8866-f1a3e883a9ae",
  "RecordType": 8,
  "ResultStatus": "Success",
  "Target": [
    {
      "ID": "User_001b519f-c2e6-4c5e-946f-85b0bcbeb2fd",
      "Type": 2
    },
    {
      "ID": "001b519f-c2e6-4c5e-946f-85b0bcbeb2fd",
      "Type": 2
    },
    {
      "ID": "User",
      "Type": 2
    },
    {
      "ID": "attacker_bad_guy.lol#EXT#@attack_range.onmicrosoft.com",
      "Type": 5
    },
    {
      "ID": "10032003656161CE",
      "Type": 3
    }
  ],
  "TargetContextId": "6915b1e0-b081-4829-8866-f1a3e883a9ae",
  "UserId": "victim@attack_range.lan",
  "UserKey": "100300009FBEAAAA@attack_range.lan",
  "UserType": 0,
  "Version": 1,
  "Workload": "AzureActiveDirectory"
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Splunk #

  • O365 External Guest User Invited source: The following analytic identifies the invitation of an external guest user within Azure AD. With Azure AD B2B collaboration, users and administrators can invite external users to collaborate with internal users. External guest account…T1136, T1136.003

YARA-L #

References #

Change user license.

#
RecordType
AzureActiveDirectory

Description

Microsoft Entra ID (Azure Active Directory) audit activity in the UserManagement category, recorded in the Office 365 Unified Audit Log.

Example Audit Record #

{
  "CreationTime": "2023-09-11T15:55:46",
  "Id": "8c9c938b-79d5-44b1-8581-de51fafa8216",
  "Operation": "Change user license.",
  "OrganizationId": "bbad9541-eb53-4533-bcef-2b76182c3b75",
  "RecordType": 8,
  "ResultStatus": "Success",
  "UserKey": "1003BFFD98415B4E@splunkresearch.onmicrosoft.com",
  "UserType": 0,
  "Version": 1,
  "Workload": "AzureActiveDirectory",
  "ObjectId": "victimUser@splunkresearch.onmicrosoft.com",
  "UserId": "evilUser@splunkresearch.onmicrosoft.com",
  "AzureActiveDirectoryEventType": 1,
  "ExtendedProperties": [
    {
      "Name": "additionalDetails",
      "Value": {
        "id": "64c07906-cb25-4d37-b38c-a862f2e49671",
        "seq": "1",
        "b": "{\"targetUpdatedProperties\":\"[{\\\"Name\\\":\\\"AssignedLicense\\\",\\\"OldValue\\\":[\\\"[SkuName=SPE_E5, AccountId=bbad9541-eb53-4533-bcef-2b76182c3b75, SkuId=06ebc4ee-1bb5-47dd-8120-11324bc54e06, DisabledPlans=[M365_ADVANCED_AUDITING]]\\\"],\\\"NewValue\\\":[\\\"[SkuName=SPE_E5, AccountId=bbad9541-eb53-4533-bcef-2b76182c3b75, SkuId=06ebc4ee-1bb5-47dd-8120-11324bc54e06, DisabledPlans=[]]\\\"]},{\\\"Name\\\":\\\"AssignedPlan\\\",\\\"OldValue\\\":[{\\\"SubscribedPlanId\\\":\\\"023234e8-a87e-4ba4-8814-da5609cd4426\\\",\\\"ServiceInstance\\\":\\\"TeamspaceAPI/NA001\\\",\\\"CapabilityStatus\\\":0,\\\"AssignedTimestamp\\\":\\\"2023-07-27T17:47:38Z\\\",\\\"InitialState\\\":null,\\\"Capability\\\":null,\\\"ServicePlanId\\\":\\\"57ff2da0-773e-42df-b2af-ffb7a2317929\\\"},{\\\"SubscribedPlanId\\\":\\\"072b9cb4-3176-43e6-882e-49b8836bf50b\\\",\\\"ServiceInstance\\\":\\\"YammerEnterprise/NA008\\\",\\\"CapabilityStatus\\\":0,\\\"AssignedTimestamp\\\":\\\"2023-07-27T17:47:38Z\\\",\\\"InitialState\\\":null,\\\"Capability\\\":null,\\\"ServicePlanId\\\":\\\"7547a3fe-08ee-4ccb-b430-5077c5041653\\\"},{\\\"SubscribedPlanId\\\":\\\"0a63ee3c-4c54-462d-a1c2-5766416685fb\\\",\\\"ServiceInstance\\\":\\\"YammerEnterprise/NA008\\\",\\\"CapabilityStatus\\\":0,\\\"AssignedTimestamp\\\":\\\"2023-07-27T17:47:38Z\\\",\\\"InitialState\\\":null,\\\"Capability\\\":null,\\\"ServicePlanId\\\":\\\"a82fbf69-b4d7-49f4-83a6-915b2cf354f4\\\"},{\\\"SubscribedPlanId\\\":\\\"0cd40d66-4fdd-4871-9af2-3e383b200b5d\\\",\\\"ServiceInstance\\\":\\\"CRM/NA02\\\",\\\"CapabilityStatus\\\":0,\\\"AssignedTimestamp\\\":\\\"2023-07-27T17:47:38Z\\\",\\\"InitialState\\\":null,\\\"Capability\\\":null,\\\"ServicePlanId\\\":\\\"afa73018-811e-46e9-988f-f75d2b1b8430\\\"},{\\\"SubscribedPlanId\\\":\\\"14faac42-bc6a-4c64-b309-6251c4cb09e2\\\",\\\"ServiceInstance\\\":\\\"exchange/namprd18-002-01\\\",\\\"CapabilityStatus\\\":0,\\\"AssignedTimestamp\\\":\\\"2023-07-27T17:47:38Z\\\",\\\"InitialState\\\":null,\\\"Capability\\\":null,\\\"ServicePlanId\\\":\\\"5136a095-5cf0-4aff-bec3-e84448b38ea5\\\"},{\\\"SubscribedPlanId\\\":\\\"1be931f9-9c0d-4148-a4ad-b61c221bc223\\\",\\\"ServiceInstance\\\":\\\"MicrosoftThreatProtection/NA001\\\",\\\"CapabilityStatus\\\":0,\\\"AssignedTimestamp\\\":\\\"2023-07-27T17:47:38Z\\\",\\\"InitialState\\\":null,\\\"Capability\\\":null,\\\"ServicePlanId\\\":\\\"bf28f719-7844-4079-9c78-c1307898e192\\\"},{\\\"SubscribedPlanId\\\":\\\"1cfbcaa7-abeb-483d-a197-7e36348ed0f8\\\",\\\"ServiceInstance\\\":\\\"exchange/namprd18-002-01\\\",\\\"CapabilityStatus\\\":0,\\\"AssignedTimestamp\\\":\\\"2023-07-27T17:47:38Z\\\",\\\"InitialState\\\":null,\\\"Capability\\\":null,\\\"ServicePlanId\\\":\\\"efb0351d-3b08-4503-993d-383af8de41e3\\\"},{\\\"SubscribedPlanId\\\":\\\"213dbe99-be20-4464-af87-54d0094fd6ce\\\",\\\"ServiceInstance\\\":\\\"AADPremiumService/NA001\\\",\\\"CapabilityStatus\\\":0,\\\"AssignedTimestamp\\\":\\\"2023-07-27T17:47:38Z\\\",\\\"InitialState\\\":null,\\\"Capability\\\":null,\\\"ServicePlanId\\\":\\\"eec0eb4f-6444-4f95-aba0-50c24d67f998\\\"},{\\\"SubscribedPlanId\\\":\\\"21765469-dcd6-4192-ab8a-e3f6bd760822\\\",\\\"ServiceInstance\\\":\\\"WhiteboardServices/NA001\\\",\\\"CapabilityStatus\\\":3,\\\"AssignedTimestamp\\\":\\\"2023-07-27T17:41:21Z\\\",\\\"InitialState\\\":null,\\\"Capability\\\":null,\\\"ServicePlanId\\\":\\\"b8afc642-032e-4de5-8c0a-507a7bba7e5d\\\"},{\\\"SubscribedPlanId\\\":\\\"227b5826-9349-4504-97a3-81b1da2bbfbb\\\",\\\"ServiceInstance\\\":\\\"MicrosoftOffice/NorthAmerica1\\\",\\\"CapabilityStatus\\\":0,\\\"AssignedTimestamp\\\":\\\"2023-07-27T17:47:38Z\\\",\\\"InitialState\\\":null,\\\"Capability\\\":null,\\\"ServicePlanId\\\":\\\"531ee2f8-b1cb-453b-9c21-d2180d014ca5\\\"},{\\\"SubscribedPlanId\\\":\\\"23cab049-6eee-4aac-9595-f9b02af3373b\\\",\\\"ServiceInstance\\\":\\\"AzureAdvancedThreatAnalytics/NA001\\\",\\\"CapabilityStatus\\\":0,\\\"AssignedTimestamp\\\":\\\"2023-07-27T17:47:38Z\\\",\\\"InitialState\\\":null,\\\"Capability\\\":null,\\\"ServicePlanId\\\":\\\"14ab5db5-e6c4-4b20-b4bc-13e36fd2227f\\\"},{\\\"SubscribedPlanId\\\":\\\"26a3d64a-198f-465b-a641-c3f8266f1ea5\\\",\\\"ServiceInstance\\\":\\\"MicrosoftCommunicationsOnline/NOAM-2A-S2\\\",\\\"CapabilityStatus\\\":0,\\\"AssignedTimestamp\\\":\\\"2023-07-27T17:47:38Z\\\",\\\"InitialState\\\":null,\\\"Capability\\\":null,\\\"ServicePlanId\\\":\\\"4828c8ec-dc2e-4779-b502-87ac9ce28ab7\\\"},{\\\"SubscribedPlanId\\\":\\\"2a3c7121-f4fe-46d1-9b5f-e93c865bf6dc\\\",\\\"ServiceInstance\\\":\\\"MicrosoftCommunicationsOnline/NOAM-2A-S2\\\",\\\"CapabilityStatus\\\":0,\\\"AssignedTimestamp\\\":\\\"2023-07-27T17:47:38Z\\\",\\\"InitialState\\\":null,\\\"Capability\\\":null,\\\"ServicePlanId\\\":\\\"3e26ee1f-8a5f-4d52-aee2-b81ce45c8f40\\\"},{\\\"SubscribedPlanId\\\":\\\"2b092686-43fd-40d2-9f20-794390aa1c16\\\",\\\"ServiceInstance\\\":\\\"exchange/namprd18-002-01\\\",\\\"CapabilityStatus\\\":0,\\\"AssignedTimestamp\\\":\\\"2023-07-27T17:47:38Z\\\",\\\"InitialState\\\":null,\\\"Capability\\\":null,\\\"ServicePlanId\\\":\\\"c4801e8a-cb58-4c35-aca6-f2dcc106f287\\\"},{\\\"SubscribedPlanId\\\":\\\"2c310eeb-327e-4bfc-9235-69386c3a8ce1\\\",\\\"ServiceInstance\\\":\\\"Adallom/NA002\\\",\\\"CapabilityStatus\\\":0,\\\"AssignedTimestamp\\\":\\\"2023-07-27T17:47:38Z\\\",\\\"InitialState\\\":null,\\\"Capability\\\":null,\\\"ServicePlanId\\\":\\\"8c098270-9dd4-4350-9b30-ba4703f3b36b\\\"},{\\\"SubscribedPlanId\\\":\\\"378cc2d1-7489-4372-b3c0-2179a6e8c72d\\\",\\\"ServiceInstance\\\":\\\"SCO/PROD_AMSUA0102_02\\\",\\\"CapabilityStatus\\\":0,\\\"AssignedTimestamp\\\":\\\"2023-07-27T17:47:38Z\\\",\\\"InitialState\\\":null,\\\"Capability\\\":null,\\\"ServicePlanId\\\":\\\"c1ec4a95-1f05-45b3-a911-aa3fa01094f5\\\"},{\\\"SubscribedPlanId\\\":\\\"39d44552-2bd6-4599-803e-3ccfd4b6502a\\\",\\\"ServiceInstance\\\":\\\"exchange/namprd18-002-01\\\",\\\"CapabilityStatus\\\":0,\\\"AssignedTimestamp\\\":\\\"2023-07-27T17:47:38Z\\\",\\\"InitialState\\\":null,\\\"Capability\\\":null,\\\"ServicePlanId\\\":\\\"9d0c4ee5-e4a1-4625-ab39-d82b619b1a34\\\"},{\\\"SubscribedPlanId\\\":\\\"39e9d742-53f6-4acc-a844-4fa26478de82\\\",\\\"ServiceInstance\\\":\\\"exchange/namprd18-002-01\\\",\\\"CapabilityStatus\\\":0,\\\"AssignedTimestamp\\\":\\\"2023-07-27T17:47:38Z\\\",\\\"InitialState\\\":null,\\\"Capability\\\":null,\\\"ServicePlanId\\\":\\\"b1188c4c-1b36-4018-b48b-ee07604f6feb\\\"},{\\\"SubscribedPlanId\\\":\\\"3bdaaeba-01a4-4b77-ba29-54845686b4af\\\",\\\"ServiceInstance\\\":\\\"MicrosoftCommunicationsOnline/NOAM-2A-S2\\\",\\\"CapabilityStatus\\\":0,\\\"AssignedTimestamp\\\":\\\"2023-07-27T17:47:38Z\\\",\\\"InitialState\\\":null,\\\"Capability\\\":null,\\\"ServicePlanId\\\":\\\"0feaeb32-d00e-4d66-bd5a-43b5b83db82c\\\"},{\\\"SubscribedPlanId\\\":\\\"3f2de5ba-2779-4e4b-b720-7abc47df4af5\\\",\\\"ServiceInstance\\\":\\\"CRM/NA02\\\",\\\"CapabilityStatus\\\":0,\\\"AssignedTimestamp\\\":\\\"2023-07-27T17:47:38Z\\\",\\\"InitialState\\\":null,\\\"Capability\\\":null,\\\"ServicePlanId\\\":\\\"28b0fa46-c39a-4188-89e2-58e979a6b014\\\"},{\\\"SubscribedPlanId\\\":\\\"426015f6-326a-41d7-bae4-82254ed4578d\\\",\\\"ServiceInstance\\\":\\\"exchange/namprd18-002-01\\\",\\\"CapabilityStatus\\\":3,\\\"AssignedTimestamp\\\":\\\"2023-09-11T15:49:49Z\\\",\\\"InitialState\\\":null,\\\"Capability\\\":null,\\\"ServicePlanId\\\":\\\"2f442157-a11c-46b9-ae5b-6e39ff4e5849\\\"},{\\\"SubscribedPlanId\\\":\\\"42a3adf0-6a2c-44df-b8bc-e435eb6aeb73\\\",\\\"ServiceInstance\\\":\\\"exchange/namprd18-002-01\\\",\\\"CapabilityStatus\\\":0,\\\"AssignedTimestamp\\\":\\\"2023-07-27T17:47:38Z\\\",\\\"InitialState\\\":null,\\\"Capability\\\":null,\\\"ServicePlanId\\\":\\\"d2d51368-76c9-4317-ada2-a12c004c432f\\\"},{\\\"SubscribedPlanId\\\":\\\"4b4b9b47-92ef-462c-aa50-afb777483ef4\\\",\\\"ServiceInstance\\\":\\\"SharePoint/US-105-0015\\\",\\\"CapabilityStatus\\\":0,\\\"AssignedTimestamp\\\":\\\"2023-07-27T17:47:38Z\\\",\\\"InitialState\\\":null,\\\"Capability\\\":null,\\\"ServicePlanId\\\":\\\"e95bec33-7c88-4a70-8e19-b10bd9d0c014\\\"},{\\\"SubscribedPlanId\\\":\\\"4bd6d0f1-692a-4626-b03f-1d72feaa8d7c\\\",\\\"ServiceInstance\\\":\\\"Office365InsiderRisk/NA001\\\",\\\"CapabilityStatus\\\":0,\\\"AssignedTimestamp\\\":\\\"2023-07-27T17:47:38Z\\\",\\\"InitialState\\\":null,\\\"Capability\\\":null,\\\"ServicePlanId\\\":\\\"d587c7a3-bda9-4f99-8776-9bcf59c84f75\\\"},{\\\"SubscribedPlanId\\\":\\\"4fd93da9-971e-45ae-a2dc-51154f0d174e\\\",\\\"ServiceInstance\\\":\\\"SharePoint/US-105-0015\\\",\\\"CapabilityStatus\\\":0,\\\"AssignedTimestamp\\\":\\\"2023-07-27T17:47:38Z\\\",\\\"InitialState\\\":null,\\\"Capability\\\":null,\\\"ServicePlanId\\\":\\\"5dbe027f-2339-4123-9542-606e4d348a72\\\"},{\\\"SubscribedPlanId\\\":\\\"5013f49d-b578-4a2d-9106-4dd025ef97b9\\\",\\\"ServiceInstance\\\":\\\"RMSOnline/NA\\\",\\\"CapabilityStatus\\\":0,\\\"AssignedTimestamp\\\":\\\"2023-07-27T17:47:38Z\\\",\\\"InitialState\\\":null,\\\"Capability\\\":null,\\\"ServicePlanId\\\":\\\"5689bec4-755d-4753-8b61-40975025187c\\\"},{\\\"SubscribedPlanId\\\":\\\"52cc074b-6308-4a8e-9c6c-5d3ac6175b6c\\\",\\\"ServiceInstance\\\":\\\"ccibotsprod/NA001\\\",\\\"CapabilityStatus\\\":3,\\\"AssignedTimestamp\\\":\\\"2023-07-27T17:41:21Z\\\",\\\"InitialState\\\":null,\\\"Capability\\\":null,\\\"ServicePlanId\\\":\\\"0683001c-0492-4d59-9515-d9a6426b5813\\\"},{\\\"SubscribedPlanId\\\":\\\"5638cb0f-dcef-4ee1-977b-7f17c177c847\\\",\\\"ServiceInstance\\\":\\\"SharePoint/US-105-0015\\\",\\\"CapabilityStatus\\\":3,\\\"AssignedTimestamp\\\":\\\"2023-07-27T17:41:21Z\\\",\\\"InitialState\\\":null,\\\"Capability\\\":null,\\\"ServicePlanId\\\":\\\"c7699d2e-19aa-44de-8edf-1736da088ca1\\\"},{\\\"SubscribedPlanId\\\":\\\"5960bdc8-5438-48cd-ab81-9c8815046666\\\",\\\"ServiceInstance\\\":\\\"exchange/namprd18-002-01\\\",\\\"CapabilityStatus\\\":0,\\\"AssignedTimestamp\\\":\\\"2023-07-27T17:47:38Z\\\",\\\"InitialState\\\":null,\\\"Capability\\\":null,\\\"ServicePlanId\\\":\\\"65cc641f-cccd-4643-97e0-a17e3045e541\\\"},{\\\"SubscribedPlanId\\\":\\\"59956027-42b4-4311-b7f3-9de3c2f82f29\\\",\\\"ServiceInstance\\\":\\\"MicrosoftPrint/NA001\\\",\\\"CapabilityStatus\\\":0,\\\"AssignedTimestamp\\\":\\\"2023-07-27T17:47:38Z\\\",\\\"InitialState\\\":null,\\\"Capability\\\":null,\\\"ServicePlanId\\\":\\\"795f6fe0-cc4d-4773-b050-5dde4dc704c9\\\"},{\\\"SubscribedPlanId\\\":\\\"5edcb9dd-550c-4fe7-a208-0e500b1c311c\\\",\\\"ServiceInstance\\\":\\\"PowerAppsService/NA001\\\",\\\"CapabilityStatus\\\":0,\\\"AssignedTimestamp\\\":\\\"2023-07-27T17:47:38Z\\\",\\\"InitialState\\\":null,\\\"Capability\\\":null,\\\"ServicePlanId\\\":\\\"9c0dab89-a30c-4117-86e7-97bda240acd2\\\"},{\\\"SubscribedPlanId\\\":\\\"609eaebf-31a9-49f6-a079-b6b130d4b1f0\\\",\\\"ServiceInstance\\\":\\\"ProjectWorkManagement/PROD_NA_Org_Ring_100\\\",\\\"CapabilityStatus\\\":0,\\\"AssignedTimestamp\\\":\\\"2023-07-27T17:47:38Z\\\",\\\"InitialState\\\":null,\\\"Capability\\\":null,\\\"ServicePlanId\\\":\\\"b737dad2-2f6c-4c65-90e3-ca563267e8b9\\\"},{\\\"SubscribedPlanId\\\":\\\"6632a0f5-bc7a-4c76-8ed9-0ba7b5f279bc\\\",\\\"ServiceInstance\\\":\\\"MicrosoftKaizala/NA001\\\",\\\"CapabilityStatus\\\":0,\\\"AssignedTimestamp\\\":\\\"2023-07-27T17:47:38Z\\\",\\\"InitialState\\\":null,\\\"Capability\\\":null,\\\"ServicePlanId\\\":\\\"0898bdbb-73b0-471a-81e5-20f1fe4dd66e\\\"},{\\\"SubscribedPlanId\\\":\\\"695f03a0-fa15-4b83-b4c5-312936e82361\\\",\\\"ServiceInstance\\\":\\\"ProcessSimple/NA001\\\",\\\"CapabilityStatus\\\":0,\\\"AssignedTimestamp\\\":\\\"2023-07-27T17:47:38Z\\\",\\\"InitialState\\\":null,\\\"Capability\\\"",
        "c": "6"
      }
    },
    {
      "Name": "extendedAuditEventCategory",
      "Value": "User"
    }
  ],
  "Actor": [
    {
      "ID": "evilUser@splunkresearch.onmicrosoft.com",
      "Type": 5
    },
    {
      "ID": "1003BFFD98415B4E",
      "Type": 3
    },
    {
      "ID": "Microsoft Office 365 Portal",
      "Type": 1
    },
    {
      "ID": "00000006-0000-0ff1-ce00-000000000000",
      "Type": 2
    },
    {
      "ID": "User_e4c722ac-3b83-478d-8f52-c388885dc30f",
      "Type": 2
    },
    {
      "ID": "e4c722ac-3b83-478d-8f52-c388885dc30f",
      "Type": 2
    },
    {
      "ID": "User",
      "Type": 2
    }
  ],
  "ActorContextId": "bbad9541-eb53-4533-bcef-2b76182c3b75",
  "InterSystemsId": "0817f79e-f0ea-4518-9c21-7babc9a36a79",
  "IntraSystemId": "6ae5503d-8764-4f6f-9547-668f4b2f82ca",
  "Target": [
    {
      "ID": "User_57e4bd36-9722-4a4a-9729-7203d8e00b72",
      "Type": 2
    },
    {
      "ID": "57e4bd36-9722-4a4a-9729-7203d8e00b72",
      "Type": 2
    },
    {
      "ID": "User",
      "Type": 2
    },
    {
      "ID": "victimUser@splunkresearch.onmicrosoft.com",
      "Type": 5
    },
    {
      "ID": "10032002CC029AE9",
      "Type": 3
    }
  ],
  "TargetContextId": "bbad9541-eb53-4533-bcef-2b76182c3b75"
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Splunk #

  • O365 Advanced Audit Disabled source: The following analytic detects instances where the O365 advanced audit is disabled for a specific user within the Office 365 tenant. It uses O365 audit logs, focusing on events related to audit license changes in AzureActiveDirectory…T1685, T1685.002

References #

Change user password.

#
RecordType
AzureActiveDirectory

Description

A user changed their own password.

Example Audit Record #

{
  "Actor": [
    {
      "ID": "mhaag@rodsoto.onmicrosoft.com",
      "Type": 5
    },
    {
      "ID": "100320010405E870",
      "Type": 3
    },
    {
      "ID": "User_fc1162cc-eb06-4ee9-b837-2aa840fa3181",
      "Type": 2
    },
    {
      "ID": "fc1162cc-eb06-4ee9-b837-2aa840fa3181",
      "Type": 2
    },
    {
      "ID": "User",
      "Type": 2
    }
  ],
  "ActorContextId": "0e8108b1-18e9-41a4-961b-dfcddf92ef08",
  "AzureActiveDirectoryEventType": 1,
  "CreationTime": "2020-12-16T17:16:58",
  "ExtendedProperties": [
    {
      "Name": "additionalDetails",
      "Value": {}
    },
    {
      "Name": "extendedAuditEventCategory",
      "Value": "User"
    }
  ],
  "Id": "d253db84-7206-4b9a-a6da-15b176cb662e",
  "InterSystemsId": "9aa2d0af-ca4a-46cf-900c-619a84b32c5d",
  "IntraSystemId": "aa7d9769-a27d-4eed-9d0a-132723084550",
  "ObjectId": "mhaag@rodsoto.onmicrosoft.com",
  "Operation": "Change user password.",
  "OrganizationId": "0e8108b1-18e9-41a4-961b-dfcddf92ef08",
  "RecordType": 8,
  "ResultStatus": "Success",
  "Target": [
    {
      "ID": "User_fc1162cc-eb06-4ee9-b837-2aa840fa3181",
      "Type": 2
    },
    {
      "ID": "fc1162cc-eb06-4ee9-b837-2aa840fa3181",
      "Type": 2
    },
    {
      "ID": "User",
      "Type": 2
    },
    {
      "ID": "mhaag@rodsoto.onmicrosoft.com",
      "Type": 5
    },
    {
      "ID": "100320010405E870",
      "Type": 3
    }
  ],
  "TargetContextId": "0e8108b1-18e9-41a4-961b-dfcddf92ef08",
  "UserId": "mhaag@rodsoto.onmicrosoft.com",
  "UserKey": "100320010405E870@rodsoto.onmicrosoft.com",
  "UserType": 0,
  "Version": 1,
  "Workload": "AzureActiveDirectory"
}

References #

Consent to application.

#

Equivalent operation in the other pipeline: Consent to application (Entra ID directory audit)

RecordType
AzureActiveDirectory

Create application password for user.

#
RecordType
AzureActiveDirectory

Description

An app password was created for a user, letting a legacy client sign in without completing MFA.

Example Audit Record #

{
  "Actor": [
    {
      "ID": "rodsoto@rodsoto.onmicrosoft.com",
      "Type": 5
    },
    {
      "ID": "10037FFEA938FB92",
      "Type": 3
    },
    {
      "ID": "User_bfb8c366-0406-41a5-b3e3-328f4a3b4484",
      "Type": 2
    },
    {
      "ID": "bfb8c366-0406-41a5-b3e3-328f4a3b4484",
      "Type": 2
    },
    {
      "ID": "User",
      "Type": 2
    }
  ],
  "ActorContextId": "0e8108b1-18e9-41a4-961b-dfcddf92ef08",
  "AzureActiveDirectoryEventType": 1,
  "CreationTime": "2020-12-15T20:49:58",
  "ExtendedProperties": [
    {
      "Name": "additionalDetails",
      "Value": {}
    },
    {
      "Name": "extendedAuditEventCategory",
      "Value": "User"
    }
  ],
  "Id": "aa3b475f-c5d0-4af5-9ad6-40b0cf144a2c",
  "InterSystemsId": "a1f4e2f1-be7a-425d-bdc2-22828cedf9ce",
  "IntraSystemId": "d44a9c8a-7dee-4fb8-9d79-6e9ad50fc61d",
  "ObjectId": "rodsoto@rodsoto.onmicrosoft.com",
  "Operation": "Create application password for user.",
  "OrganizationId": "0e8108b1-18e9-41a4-961b-dfcddf92ef08",
  "RecordType": 8,
  "ResultStatus": "Success",
  "Target": [
    {
      "ID": "User_bfb8c366-0406-41a5-b3e3-328f4a3b4484",
      "Type": 2
    },
    {
      "ID": "bfb8c366-0406-41a5-b3e3-328f4a3b4484",
      "Type": 2
    },
    {
      "ID": "User",
      "Type": 2
    },
    {
      "ID": "rodsoto@rodsoto.onmicrosoft.com",
      "Type": 5
    },
    {
      "ID": "10037FFEA938FB92",
      "Type": 3
    }
  ],
  "TargetContextId": "0e8108b1-18e9-41a4-961b-dfcddf92ef08",
  "UserId": "rodsoto@rodsoto.onmicrosoft.com",
  "UserKey": "10037FFEA938FB92@rodsoto.onmicrosoft.com",
  "UserType": 0,
  "Version": 1,
  "Workload": "AzureActiveDirectory"
}

References #

Create application – Certificates and secrets management

#
RecordType
AzureActiveDirectory

Description

Create application – Certificates and secrets management activity in Microsoft Entra ID, recorded in the Unified Audit Log (observed in first-party capture).

Example Audit Record #

{
  "Actor": [
    {
      "ID": "adminuser@example.onmicrosoft.com",
      "Type": 5
    },
    {
      "ID": "10000000AAAAAAAA",
      "Type": 3
    },
    {
      "ID": "User_11111111-1111-1111-1111-111111111111",
      "Type": 2
    },
    {
      "ID": "11111111-1111-1111-1111-111111111111",
      "Type": 2
    },
    {
      "ID": "User",
      "Type": 2
    },
    {
      "ID": "NotAgentic",
      "Type": 2
    }
  ],
  "ActorContextId": "00000000-0000-0000-0000-000000000001",
  "AzureActiveDirectoryEventType": 1,
  "CreationTime": "2026-07-02T16:41:44Z",
  "ExtendedProperties": [
    {
      "Name": "additionalDetails",
      "Value": {
        "User-Agent": "python/3.13.9 (Linux-6.1.0-41-amd64-x86_64-with-glibc2.36) AZURECLI/2.82.0 (DEB)",
        "AppId": "92274755-5861-4d35-a89e-c84961929883"
      }
    },
    {
      "Name": "extendedAuditEventCategory",
      "Value": "Application"
    }
  ],
  "Id": "9479a6f5-8f4f-4eef-914f-76fdc8b27b84",
  "InterSystemsId": "45cf671d-2f15-420d-8b0a-aa99f1956268",
  "IntraSystemId": "00000000-0000-0000-0000-000000000000",
  "ModifiedProperties": [
    {
      "Name": "KeyDescription",
      "NewValue": [],
      "OldValue": []
    },
    {
      "Name": "Included Updated Properties",
      "NewValue": "KeyDescription"
    }
  ],
  "ObjectId": "Application_5bb4d314-9a25-4a5c-861c-8fac7de88dc2",
  "Operation": "Create application – Certificates and secrets management ",
  "OrganizationId": "00000000-0000-0000-0000-000000000001",
  "RecordType": 8,
  "ResultStatus": "Success",
  "Target": [
    {
      "ID": "Application_5bb4d314-9a25-4a5c-861c-8fac7de88dc2",
      "Type": 2
    },
    {
      "ID": "5bb4d314-9a25-4a5c-861c-8fac7de88dc2",
      "Type": 2
    },
    {
      "ID": "Application",
      "Type": 2
    },
    {
      "ID": "NotAgentic",
      "Type": 2
    },
    {
      "ID": "dw-harness-app-980a2377",
      "Type": 1
    },
    {
      "ID": "92274755-5861-4d35-a89e-c84961929883",
      "Type": 2
    }
  ],
  "TargetContextId": "00000000-0000-0000-0000-000000000001",
  "UserId": "adminuser@example.onmicrosoft.com",
  "UserKey": "10000000AAAAAAAA@example.onmicrosoft.com",
  "UserType": 0,
  "Version": 1,
  "Workload": "AzureActiveDirectory"
}

References #

Create company settings

#
RecordType
AzureActiveDirectory

Description

Create company settings activity in Microsoft Entra ID, recorded in the Unified Audit Log (observed in first-party capture).

Example Audit Record #

{
  "Actor": [
    {
      "ID": "adminuser@example.onmicrosoft.com",
      "Type": 5
    },
    {
      "ID": 1111111111111111,
      "Type": 3
    },
    {
      "ID": "User_aaaaaaaa-0000-0000-0000-000000000001",
      "Type": 2
    },
    {
      "ID": "aaaaaaaa-0000-0000-0000-000000000001",
      "Type": 2
    },
    {
      "ID": "User",
      "Type": 2
    },
    {
      "ID": "NotAgentic",
      "Type": 2
    }
  ],
  "ActorContextId": "11111111-1111-1111-1111-111111111111",
  "AzureActiveDirectoryEventType": 1,
  "CreationDate": "2026-07-03T03:22:33",
  "CreationTime": "2026-07-03T03:22:33",
  "ExtendedProperties": [
    {
      "Name": "additionalDetails",
      "Value": {
        "User-Agent": "python/3.13.9 (Linux-6.1.0-41-amd64-x86_64-with-glibc2.36) AZURECLI/2.82.0 (DEB)"
      }
    },
    {
      "Name": "extendedAuditEventCategory",
      "Value": "Company"
    }
  ],
  "Id": "32d6405e-7965-491d-aba6-b05c20377d2b",
  "InterSystemsId": "c0a4e8d4-d41f-4bbc-ad88-25f2181ee7ee",
  "IntraSystemId": "00000000-0000-0000-0000-000000000000",
  "ModifiedProperties": [
    {
      "Name": "ObjectSettings",
      "NewValue": [
        {
          "Settings": [
            {
              "Id": "dd8b601a-a235-4858-8c92-4d2aafb7826e",
              "ObjectSettingTemplateId": "62375ab9-6b52-47ed-826b-58e47e0e304b",
              "Properties": [
                {
                  "Key": "EnableMSStandardBlockedWords",
                  "Value": "false"
                }
              ]
            }
          ]
        }
      ],
      "OldValue": [
        {
          "Settings": []
        }
      ]
    },
    {
      "Name": "Included Updated Properties",
      "NewValue": "ObjectSettings",
      "OldValue": ""
    }
  ],
  "ObjectId": "Company_11111111-1111-1111-1111-111111111111",
  "Operation": "Create company settings",
  "Operations": "Create company settings",
  "OrganizationId": "11111111-1111-1111-1111-111111111111",
  "RecordType": "AzureActiveDirectory",
  "ResultStatus": "Success",
  "Target": [
    {
      "ID": "Company_11111111-1111-1111-1111-111111111111",
      "Type": 2
    },
    {
      "ID": "11111111-1111-1111-1111-111111111111",
      "Type": 2
    },
    {
      "ID": "Directory",
      "Type": 2
    },
    {
      "ID": "NCT",
      "Type": 1
    }
  ],
  "TargetContextId": "11111111-1111-1111-1111-111111111111",
  "UserId": "adminuser@example.onmicrosoft.com",
  "UserKey": "1111111111111111@example.onmicrosoft.com",
  "UserType": "Regular",
  "Version": 1,
  "Workload": "AzureActiveDirectory"
}

References #

Delete administrative unit.

#
RecordType
AzureActiveDirectory

Description

Delete administrative unit. activity in Microsoft Entra ID, recorded in the Unified Audit Log (observed in first-party capture).

Example Audit Record #

{
  "Actor": [
    {
      "ID": "adminuser@example.onmicrosoft.com",
      "Type": 5
    },
    {
      "ID": 1111111111111111,
      "Type": 3
    },
    {
      "ID": "User_aaaaaaaa-0000-0000-0000-000000000001",
      "Type": 2
    },
    {
      "ID": "aaaaaaaa-0000-0000-0000-000000000001",
      "Type": 2
    },
    {
      "ID": "User",
      "Type": 2
    },
    {
      "ID": "NotAgentic",
      "Type": 2
    }
  ],
  "ActorContextId": "11111111-1111-1111-1111-111111111111",
  "AzureActiveDirectoryEventType": 1,
  "CreationDate": "2026-07-03T03:23:07",
  "CreationTime": "2026-07-03T03:23:07",
  "ExtendedProperties": [
    {
      "Name": "additionalDetails",
      "Value": {
        "User-Agent": "python/3.13.9 (Linux-6.1.0-41-amd64-x86_64-with-glibc2.36) AZURECLI/2.82.0 (DEB)"
      }
    },
    {
      "Name": "extendedAuditEventCategory",
      "Value": "AdministrativeUnit"
    }
  ],
  "Id": "0919b200-4c2f-4766-b2ca-c807386d3a18",
  "InterSystemsId": "99b2da51-6799-4f66-abf1-3bd37bb1e413",
  "IntraSystemId": "8a546fed-abb3-4a11-90d0-ba48a316ad7d",
  "ObjectId": "AdministrativeUnit_78e00ff9-4f90-4a2d-ba46-416e73ce7793",
  "Operation": "Delete administrative unit.",
  "Operations": "Delete administrative unit.",
  "OrganizationId": "11111111-1111-1111-1111-111111111111",
  "RecordType": "AzureActiveDirectory",
  "ResultStatus": "Success",
  "Target": [
    {
      "ID": "AdministrativeUnit_78e00ff9-4f90-4a2d-ba46-416e73ce7793",
      "Type": 2
    },
    {
      "ID": "78e00ff9-4f90-4a2d-ba46-416e73ce7793",
      "Type": 2
    },
    {
      "ID": "Manager",
      "Type": 2
    },
    {
      "ID": "dw-harness-aum-2fe5ab51",
      "Type": 1
    }
  ],
  "TargetContextId": "11111111-1111-1111-1111-111111111111",
  "UserId": "adminuser@example.onmicrosoft.com",
  "UserKey": "1111111111111111@example.onmicrosoft.com",
  "UserType": "Regular",
  "Version": 1,
  "Workload": "AzureActiveDirectory"
}

References #

Delete application password for user.

#
RecordType
AzureActiveDirectory

Description

An app-password credential was deleted for a user, revoking a legacy non-MFA sign-in credential.

Example Audit Record #

{
  "Actor": [
    {
      "ID": "rodsoto@rodsoto.onmicrosoft.com",
      "Type": 5
    },
    {
      "ID": "10037FFEA938FB92",
      "Type": 3
    },
    {
      "ID": "User_bfb8c366-0406-41a5-b3e3-328f4a3b4484",
      "Type": 2
    },
    {
      "ID": "bfb8c366-0406-41a5-b3e3-328f4a3b4484",
      "Type": 2
    },
    {
      "ID": "User",
      "Type": 2
    }
  ],
  "ActorContextId": "0e8108b1-18e9-41a4-961b-dfcddf92ef08",
  "AzureActiveDirectoryEventType": 1,
  "CreationTime": "2020-12-15T22:35:20",
  "ExtendedProperties": [
    {
      "Name": "additionalDetails",
      "Value": {}
    },
    {
      "Name": "extendedAuditEventCategory",
      "Value": "User"
    }
  ],
  "Id": "d4c0430f-34ea-43c7-b7eb-d8cd99e20e7f",
  "InterSystemsId": "9d18b521-23df-4130-99e2-1ff2eee13333",
  "IntraSystemId": "7d96ab40-6e16-48e5-bf78-677c89683775",
  "ObjectId": "rodsoto@rodsoto.onmicrosoft.com",
  "Operation": "Delete application password for user.",
  "OrganizationId": "0e8108b1-18e9-41a4-961b-dfcddf92ef08",
  "RecordType": 8,
  "ResultStatus": "Success",
  "Target": [
    {
      "ID": "User_bfb8c366-0406-41a5-b3e3-328f4a3b4484",
      "Type": 2
    },
    {
      "ID": "bfb8c366-0406-41a5-b3e3-328f4a3b4484",
      "Type": 2
    },
    {
      "ID": "User",
      "Type": 2
    },
    {
      "ID": "rodsoto@rodsoto.onmicrosoft.com",
      "Type": 5
    },
    {
      "ID": "10037FFEA938FB92",
      "Type": 3
    }
  ],
  "TargetContextId": "0e8108b1-18e9-41a4-961b-dfcddf92ef08",
  "UserId": "rodsoto@rodsoto.onmicrosoft.com",
  "UserKey": "10037FFEA938FB92@rodsoto.onmicrosoft.com",
  "UserType": 0,
  "Version": 1,
  "Workload": "AzureActiveDirectory"
}

References #

Delete application.

#
RecordType
AzureActiveDirectory

Description

An application registration was deleted.

Example Audit Record #

{
  "CreationTime": "2023-09-01T17:10:56",
  "Id": "43581925-c9c0-4cf0-8f14-83853ec1e63d",
  "Operation": "Delete application.",
  "OrganizationId": "58aee3b9-7433-46a0-b54e-2429487992a0",
  "RecordType": 8,
  "ResultStatus": "Success",
  "UserKey": "1003BFFD98415B4E@contoso.onmicrosoft.com",
  "UserType": 0,
  "Version": 1,
  "Workload": "AzureActiveDirectory",
  "ObjectId": "Application_acdcd612-0053-407b-88f1-ebe32e193cee",
  "UserId": "attacker@contoso.onmicrosoft.com",
  "AzureActiveDirectoryEventType": 1,
  "ExtendedProperties": [
    {
      "Name": "additionalDetails",
      "Value": {
        "User-Agent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Safari/537.36",
        "AppId": "c1d6e216-dfbf-4c1f-818d-d6bfc99f0694"
      }
    },
    {
      "Name": "extendedAuditEventCategory",
      "Value": "Application"
    }
  ],
  "Actor": [
    {
      "ID": "attacker@contoso.onmicrosoft.com",
      "Type": 5
    },
    {
      "ID": "1003BFFD98415B4E",
      "Type": 3
    },
    {
      "ID": "18ed3507-a475-4ccb-b669-d66bc9f2a36e",
      "Type": 2
    },
    {
      "ID": "User_e4c722ac-3b83-478d-8f52-c388885dc30f",
      "Type": 2
    },
    {
      "ID": "e4c722ac-3b83-478d-8f52-c388885dc30f",
      "Type": 2
    },
    {
      "ID": "User",
      "Type": 2
    }
  ],
  "ActorContextId": "58aee3b9-7433-46a0-b54e-2429487992a0",
  "InterSystemsId": "12534c88-4425-477a-a40f-ea74457a7c9b",
  "IntraSystemId": "a2d4d7c4-727c-401b-9e6c-70413a080855",
  "Target": [
    {
      "ID": "Application_acdcd612-0053-407b-88f1-ebe32e193cee",
      "Type": 2
    },
    {
      "ID": "acdcd612-0053-407b-88f1-ebe32e193cee",
      "Type": 2
    },
    {
      "ID": "Application",
      "Type": 2
    },
    {
      "ID": "TestApp1",
      "Type": 1
    },
    {
      "ID": "c1d6e216-dfbf-4c1f-818d-d6bfc99f0694",
      "Type": 2
    }
  ],
  "TargetContextId": "58aee3b9-7433-46a0-b54e-2429487992a0"
}

References #

Delete company settings

#
RecordType
AzureActiveDirectory

Description

Delete company settings activity in Microsoft Entra ID, recorded in the Unified Audit Log (observed in first-party capture).

Example Audit Record #

{
  "Actor": [
    {
      "ID": "adminuser@example.onmicrosoft.com",
      "Type": 5
    },
    {
      "ID": 1111111111111111,
      "Type": 3
    },
    {
      "ID": "User_aaaaaaaa-0000-0000-0000-000000000001",
      "Type": 2
    },
    {
      "ID": "aaaaaaaa-0000-0000-0000-000000000001",
      "Type": 2
    },
    {
      "ID": "User",
      "Type": 2
    },
    {
      "ID": "NotAgentic",
      "Type": 2
    }
  ],
  "ActorContextId": "11111111-1111-1111-1111-111111111111",
  "AzureActiveDirectoryEventType": 1,
  "CreationDate": "2026-07-03T03:22:35",
  "CreationTime": "2026-07-03T03:22:35",
  "ExtendedProperties": [
    {
      "Name": "additionalDetails",
      "Value": {
        "User-Agent": "python/3.13.9 (Linux-6.1.0-41-amd64-x86_64-with-glibc2.36) AZURECLI/2.82.0 (DEB)"
      }
    },
    {
      "Name": "extendedAuditEventCategory",
      "Value": "Company"
    }
  ],
  "Id": "e35b05e3-a203-4832-a53f-fd9eea108bfb",
  "InterSystemsId": "06236982-a2ab-4284-97f3-8d5821dca5b7",
  "IntraSystemId": "00000000-0000-0000-0000-000000000000",
  "ModifiedProperties": [
    {
      "Name": "ObjectSettings",
      "NewValue": [
        {
          "Settings": []
        }
      ],
      "OldValue": [
        {
          "Settings": [
            {
              "Id": "dd8b601a-a235-4858-8c92-4d2aafb7826e",
              "ObjectSettingTemplateId": "62375ab9-6b52-47ed-826b-58e47e0e304b",
              "Properties": [
                {
                  "Key": "EnableMSStandardBlockedWords",
                  "Value": "true"
                }
              ]
            }
          ]
        }
      ]
    },
    {
      "Name": "Included Updated Properties",
      "NewValue": "ObjectSettings",
      "OldValue": ""
    }
  ],
  "ObjectId": "Company_11111111-1111-1111-1111-111111111111",
  "Operation": "Delete company settings",
  "Operations": "Delete company settings",
  "OrganizationId": "11111111-1111-1111-1111-111111111111",
  "RecordType": "AzureActiveDirectory",
  "ResultStatus": "Success",
  "Target": [
    {
      "ID": "Company_11111111-1111-1111-1111-111111111111",
      "Type": 2
    },
    {
      "ID": "11111111-1111-1111-1111-111111111111",
      "Type": 2
    },
    {
      "ID": "Directory",
      "Type": 2
    },
    {
      "ID": "NCT",
      "Type": 1
    }
  ],
  "TargetContextId": "11111111-1111-1111-1111-111111111111",
  "UserId": "adminuser@example.onmicrosoft.com",
  "UserKey": "1111111111111111@example.onmicrosoft.com",
  "UserType": "Regular",
  "Version": 1,
  "Workload": "AzureActiveDirectory"
}

References #

Delete group.

#
RecordType
AzureActiveDirectory

Description

A group was deleted in Azure Active Directory (the UAL operation string includes a trailing period).

Example Audit Record #

{
  "Actor": [
    {
      "ID": "adminuser@example.onmicrosoft.com",
      "Type": 5
    },
    {
      "ID": "10000000AAAAAAAA",
      "Type": 3
    },
    {
      "ID": "dw-activity-gen",
      "Type": 1
    },
    {
      "ID": "22222222-2222-2222-2222-222222222222",
      "Type": 2
    },
    {
      "ID": "User_11111111-1111-1111-1111-111111111111",
      "Type": 2
    },
    {
      "ID": "11111111-1111-1111-1111-111111111111",
      "Type": 2
    },
    {
      "ID": "User",
      "Type": 2
    },
    {
      "ID": "NotAgentic",
      "Type": 2
    }
  ],
  "ActorContextId": "00000000-0000-0000-0000-000000000001",
  "AzureActiveDirectoryEventType": 1,
  "CreationTime": "2026-07-02T02:10:51Z",
  "ExtendedProperties": [
    {
      "Name": "additionalDetails",
      "Value": {
        "User-Agent": "python-requests/2.34.2"
      }
    },
    {
      "Name": "extendedAuditEventCategory",
      "Value": "Group"
    }
  ],
  "Id": "51c24454-8f68-45ac-a504-30d4d4ab1c98",
  "InterSystemsId": "38e9e4c1-c82d-4f05-867d-94557529faf5",
  "IntraSystemId": "00000000-0000-0000-0000-000000000000",
  "ModifiedProperties": [
    {
      "Name": "DeletionType",
      "OldValue": "SoftDelete"
    },
    {
      "Name": "GroupType",
      "OldValue": "M365 group with static membership"
    },
    {
      "Name": "CreatedDateTime",
      "OldValue": "7/2/2026 2:10:45 AM"
    },
    {
      "Name": "LastUpdatedDateTime",
      "OldValue": "7/2/2026 2:10:45 AM"
    }
  ],
  "ObjectId": "Group_72ff2416-ca78-4443-8b25-800823d06143",
  "Operation": "Delete group.",
  "OrganizationId": "00000000-0000-0000-0000-000000000001",
  "RecordType": 8,
  "ResultStatus": "Success",
  "Target": [
    {
      "ID": "Group_72ff2416-ca78-4443-8b25-800823d06143",
      "Type": 2
    },
    {
      "ID": "72ff2416-ca78-4443-8b25-800823d06143",
      "Type": 2
    },
    {
      "ID": "Group",
      "Type": 2
    },
    {
      "ID": "dw-harness-60974bd7-group",
      "Type": 1
    }
  ],
  "TargetContextId": "00000000-0000-0000-0000-000000000001",
  "UserId": "adminuser@example.onmicrosoft.com",
  "UserKey": "10000000AAAAAAAA@example.onmicrosoft.com",
  "UserType": 0,
  "Version": 1,
  "Workload": "AzureActiveDirectory"
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

YARA-L #

References #

Delete label.

#
RecordType
AzureActiveDirectory

Description

Delete label. activity in Microsoft Entra ID, recorded in the Unified Audit Log (observed in first-party capture).

Example Audit Record #

{
  "Actor": [
    {
      "ID": "Microsoft Exchange Online Protection",
      "Type": 1
    },
    {
      "ID": "00000007-0000-0ff1-ce00-000000000000",
      "Type": 2
    },
    {
      "ID": "ServicePrincipal_7346eb28-2787-4db2-8f6e-a9ebdeec5988",
      "Type": 2
    },
    {
      "ID": "7346eb28-2787-4db2-8f6e-a9ebdeec5988",
      "Type": 2
    },
    {
      "ID": "ServicePrincipal",
      "Type": 2
    },
    {
      "ID": "NotAgentic",
      "Type": 2
    }
  ],
  "ActorContextId": "11111111-1111-1111-1111-111111111111",
  "AzureActiveDirectoryEventType": 1,
  "CreationDate": "2026-07-03T05:56:17",
  "CreationTime": "2026-07-03T05:56:17",
  "ExtendedProperties": [
    {
      "Name": "additionalDetails",
      "Value": {}
    },
    {
      "Name": "extendedAuditEventCategory",
      "Value": "Label"
    }
  ],
  "Id": "dae1f8a3-a8fd-46c9-b8c8-8192cdd5853c",
  "InterSystemsId": "60856770-4c0f-4eab-bcea-4b00af3af49d",
  "IntraSystemId": "00000000-0000-0000-0000-000000000000",
  "ObjectId": "Label_6f3246c9-cb0a-478b-82c7-09d34f9603cc",
  "Operation": "Delete label.",
  "Operations": "Delete label.",
  "OrganizationId": "11111111-1111-1111-1111-111111111111",
  "RecordType": "AzureActiveDirectory",
  "ResultStatus": "Success",
  "Target": [
    {
      "ID": "Label_6f3246c9-cb0a-478b-82c7-09d34f9603cc",
      "Type": 2
    },
    {
      "ID": "6f3246c9-cb0a-478b-82c7-09d34f9603cc",
      "Type": 2
    },
    {
      "ID": "Other",
      "Type": 2
    },
    {
      "ID": "dwharn9babc3 label",
      "Type": 1
    }
  ],
  "TargetContextId": "11111111-1111-1111-1111-111111111111",
  "UserId": "ServicePrincipal_7346eb28-2787-4db2-8f6e-a9ebdeec5988",
  "UserKey": "Not Available",
  "UserType": "System",
  "Version": 1,
  "Workload": "AzureActiveDirectory"
}

References #

Delete partner specific cross-tenant access setting.

#
RecordType
AzureActiveDirectory

Description

Microsoft Entra ID (Azure Active Directory) audit activity in the CrossTenantAccessSettings category, recorded in the Office 365 Unified Audit Log.

Example Audit Record #

{
  "Actor": [
    {
      "ID": "attacker@attack_range.lan",
      "Type": 5
    },
    {
      "ID": "10037FFEAA5FB8A0",
      "Type": 3
    },
    {
      "ID": "User_91ec8a8a-88b4-4159-9a36-acdf37ef17b2",
      "Type": 2
    },
    {
      "ID": "91ec8a8a-88b4-4159-9a36-acdf37ef17b2",
      "Type": 2
    },
    {
      "ID": "User",
      "Type": 2
    }
  ],
  "ActorContextId": "6915b1e0-b081-4829-8866-f1a3e883a9ae",
  "AzureActiveDirectoryEventType": 1,
  "CreationTime": "2024-02-22T21:09:46",
  "ExtendedProperties": [
    {
      "Name": "additionalDetails",
      "Value": {}
    },
    {
      "Name": "extendedAuditEventCategory",
      "Value": "CrossTenantAccessSettings"
    }
  ],
  "Id": "e9881eef-97df-4fda-aa53-bf3aaf35f7aa",
  "InterSystemsId": "abb242e5-b3e2-4d8d-9d26-4d74f494f888",
  "IntraSystemId": "a5fedd23-0e60-4326-bfda-1cd5909ba68f",
  "ModifiedProperties": [
    {
      "Name": "tenantId",
      "NewValue": "341dac3b-34e1-4b06-a4df-5c0259946074",
      "OldValue": "341dac3b-34e1-4b06-a4df-5c0259946074"
    }
  ],
  "ObjectId": "Policy_17c7001d-3a4d-4bf7-9cc6-ee0e40f665da",
  "Operation": "Delete partner specific cross-tenant access setting.",
  "OrganizationId": "6915b1e0-b081-4829-8866-f1a3e883a9ae",
  "RecordType": 8,
  "ResultStatus": "Success",
  "Target": [
    {
      "ID": "Policy_17c7001d-3a4d-4bf7-9cc6-ee0e40f665da",
      "Type": 2
    },
    {
      "ID": "17c7001d-3a4d-4bf7-9cc6-ee0e40f665da",
      "Type": 2
    },
    {
      "ID": "Policy",
      "Type": 2
    },
    {
      "ID": "CrossTenantAccessPolicy for 6915b1e0-b081-4829-8866-f1a3e883a9ae",
      "Type": 1
    }
  ],
  "TargetContextId": "6915b1e0-b081-4829-8866-f1a3e883a9ae",
  "UserId": "attacker@attack_range.lan",
  "UserKey": "10037FFEAA5FB8A0@attack_range.lan",
  "UserType": 0,
  "Version": 1,
  "Workload": "AzureActiveDirectory"
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Splunk #

References #

Delete permission grant policy.

#
RecordType
AzureActiveDirectory

Description

Delete permission grant policy. activity in Microsoft Entra ID, recorded in the Unified Audit Log (observed in first-party capture).

Example Audit Record #

{
  "Actor": [
    {
      "ID": "adminuser@example.onmicrosoft.com",
      "Type": 5
    },
    {
      "ID": 1111111111111111,
      "Type": 3
    },
    {
      "ID": "User_aaaaaaaa-0000-0000-0000-000000000001",
      "Type": 2
    },
    {
      "ID": "aaaaaaaa-0000-0000-0000-000000000001",
      "Type": 2
    },
    {
      "ID": "User",
      "Type": 2
    },
    {
      "ID": "NotAgentic",
      "Type": 2
    }
  ],
  "ActorContextId": "11111111-1111-1111-1111-111111111111",
  "AzureActiveDirectoryEventType": 1,
  "CreationDate": "2026-07-03T03:22:51",
  "CreationTime": "2026-07-03T03:22:51",
  "ExtendedProperties": [
    {
      "Name": "additionalDetails",
      "Value": {
        "User-Agent": "python/3.13.9 (Linux-6.1.0-41-amd64-x86_64-with-glibc2.36) AZURECLI/2.82.0 (DEB)"
      }
    },
    {
      "Name": "extendedAuditEventCategory",
      "Value": "PermissionGrantPolicy"
    }
  ],
  "Id": "2dd84ef4-b42e-4cbe-9f5b-8dce6a978b85",
  "InterSystemsId": "34de479f-5633-4e29-8f7d-6a8f9f34c245",
  "IntraSystemId": "00000000-0000-0000-0000-000000000000",
  "ModifiedProperties": [
    {
      "Name": "PermissionGrantPolicy",
      "NewValue": "",
      "OldValue": {
        "EncodingVersion": 2,
        "Id": "dwharn-pgp-2fe5ab51",
        "Includes": [],
        "Excludes": [],
        "DisplayName": "dw-harness-pgp-2fe5ab51",
        "Description": "harness",
        "IncludeAllPreApprovedApplications": false,
        "ConsentResourceScopeType": "tenant"
      }
    }
  ],
  "ObjectId": "PermissionGrantPolicy_82aca392-bf62-49e7-a864-e071ba0e544d",
  "Operation": "Delete permission grant policy.",
  "Operations": "Delete permission grant policy.",
  "OrganizationId": "11111111-1111-1111-1111-111111111111",
  "RecordType": "AzureActiveDirectory",
  "ResultStatus": "Success",
  "Target": [
    {
      "ID": "PermissionGrantPolicy_82aca392-bf62-49e7-a864-e071ba0e544d",
      "Type": 2
    },
    {
      "ID": "82aca392-bf62-49e7-a864-e071ba0e544d",
      "Type": 2
    },
    {
      "ID": "Other",
      "Type": 2
    }
  ],
  "TargetContextId": "11111111-1111-1111-1111-111111111111",
  "UserId": "adminuser@example.onmicrosoft.com",
  "UserKey": "1111111111111111@example.onmicrosoft.com",
  "UserType": "Regular",
  "Version": 1,
  "Workload": "AzureActiveDirectory"
}

References #

Delete policy.

#
RecordType
AzureActiveDirectory

Description

Delete policy. activity in Microsoft Entra ID, recorded in the Unified Audit Log (observed in first-party capture).

Example Audit Record #

{
  "Actor": [
    {
      "ID": "adminuser@example.onmicrosoft.com",
      "Type": 5
    },
    {
      "ID": 1111111111111111,
      "Type": 3
    },
    {
      "ID": "User_aaaaaaaa-0000-0000-0000-000000000001",
      "Type": 2
    },
    {
      "ID": "aaaaaaaa-0000-0000-0000-000000000001",
      "Type": 2
    },
    {
      "ID": "User",
      "Type": 2
    },
    {
      "ID": "NotAgentic",
      "Type": 2
    }
  ],
  "ActorContextId": "11111111-1111-1111-1111-111111111111",
  "AzureActiveDirectoryEventType": 1,
  "CreationDate": "2026-07-03T03:22:54",
  "CreationTime": "2026-07-03T03:22:54",
  "ExtendedProperties": [
    {
      "Name": "additionalDetails",
      "Value": {
        "User-Agent": "python/3.13.9 (Linux-6.1.0-41-amd64-x86_64-with-glibc2.36) AZURECLI/2.82.0 (DEB)"
      }
    },
    {
      "Name": "extendedAuditEventCategory",
      "Value": "Policy"
    }
  ],
  "Id": "18bc263b-0f43-4a56-a142-6a4fb1275d19",
  "InterSystemsId": "9fee2c11-e301-4f12-b6ef-6a1a2a57baf1",
  "IntraSystemId": "af472d78-b9b1-411d-90b4-12fe51b42379",
  "ObjectId": "Policy_61f14cb5-4392-4980-ac03-bb056999ff98",
  "Operation": "Delete policy.",
  "Operations": "Delete policy.",
  "OrganizationId": "11111111-1111-1111-1111-111111111111",
  "RecordType": "AzureActiveDirectory",
  "ResultStatus": "Success",
  "Target": [
    {
      "ID": "Policy_61f14cb5-4392-4980-ac03-bb056999ff98",
      "Type": 2
    },
    {
      "ID": "61f14cb5-4392-4980-ac03-bb056999ff98",
      "Type": 2
    },
    {
      "ID": "Policy",
      "Type": 2
    },
    {
      "ID": "dw-harness-hrd-2fe5ab51",
      "Type": 1
    }
  ],
  "TargetContextId": "11111111-1111-1111-1111-111111111111",
  "UserId": "adminuser@example.onmicrosoft.com",
  "UserKey": "1111111111111111@example.onmicrosoft.com",
  "UserType": "Regular",
  "Version": 1,
  "Workload": "AzureActiveDirectory"
}

References #

Delete role definition.

#
RecordType
AzureActiveDirectory

Description

Delete role definition. activity in Microsoft Entra ID, recorded in the Unified Audit Log (observed in first-party capture).

Example Audit Record #

{
  "Actor": [
    {
      "ID": "adminuser@example.onmicrosoft.com",
      "Type": 5
    },
    {
      "ID": 1111111111111111,
      "Type": 3
    },
    {
      "ID": "User_aaaaaaaa-0000-0000-0000-000000000001",
      "Type": 2
    },
    {
      "ID": "aaaaaaaa-0000-0000-0000-000000000001",
      "Type": 2
    },
    {
      "ID": "User",
      "Type": 2
    },
    {
      "ID": "NotAgentic",
      "Type": 2
    }
  ],
  "ActorContextId": "11111111-1111-1111-1111-111111111111",
  "AzureActiveDirectoryEventType": 1,
  "CreationDate": "2026-07-03T03:22:49",
  "CreationTime": "2026-07-03T03:22:49",
  "ExtendedProperties": [
    {
      "Name": "additionalDetails",
      "Value": {
        "User-Agent": "python/3.13.9 (Linux-6.1.0-41-amd64-x86_64-with-glibc2.36) AZURECLI/2.82.0 (DEB)"
      }
    },
    {
      "Name": "extendedAuditEventCategory",
      "Value": "RoleDefinition"
    }
  ],
  "Id": "7560b4f3-a087-4fbe-a6d6-c8051e8a07fd",
  "InterSystemsId": "909994a4-f186-42b8-b5b7-b18b18460859",
  "IntraSystemId": "de2a4893-f197-47ce-96cf-6b31c14b6f98",
  "ModifiedProperties": [
    {
      "Name": "Included Updated Properties",
      "NewValue": "",
      "OldValue": ""
    }
  ],
  "ObjectId": "RoleDefinition_799abf44-b19b-4605-9606-2125d16ff1c8",
  "Operation": "Delete role definition.",
  "Operations": "Delete role definition.",
  "OrganizationId": "11111111-1111-1111-1111-111111111111",
  "RecordType": "AzureActiveDirectory",
  "ResultStatus": "Success",
  "Target": [
    {
      "ID": "RoleDefinition_799abf44-b19b-4605-9606-2125d16ff1c8",
      "Type": 2
    },
    {
      "ID": "799abf44-b19b-4605-9606-2125d16ff1c8",
      "Type": 2
    },
    {
      "ID": "Other",
      "Type": 2
    },
    {
      "ID": "dw-harness-role-2fe5ab51",
      "Type": 1
    }
  ],
  "TargetContextId": "11111111-1111-1111-1111-111111111111",
  "UserId": "adminuser@example.onmicrosoft.com",
  "UserKey": "1111111111111111@example.onmicrosoft.com",
  "UserType": "Regular",
  "Version": 1,
  "Workload": "AzureActiveDirectory"
}

References #

Delete user.

#
RecordType
AzureActiveDirectory

Description

A user account was deleted.

Example Audit Record #

{
  "Actor": [
    {
      "ID": "Microsoft Substrate Management",
      "Type": 1
    },
    {
      "ID": "98db8bd6-0cc0-4e67-9de5-f187f1cd1b41",
      "Type": 2
    },
    {
      "ID": "ServicePrincipal_414635d2-0108-489f-8a72-0a53de565cf9",
      "Type": 2
    },
    {
      "ID": "414635d2-0108-489f-8a72-0a53de565cf9",
      "Type": 2
    },
    {
      "ID": "ServicePrincipal",
      "Type": 2
    },
    {
      "ID": "NotAgentic",
      "Type": 2
    }
  ],
  "ActorContextId": "00000000-0000-0000-0000-000000000001",
  "AzureActiveDirectoryEventType": 1,
  "CreationTime": "2026-07-02T15:32:11Z",
  "ExtendedProperties": [
    {
      "Name": "additionalDetails",
      "Value": {}
    },
    {
      "Name": "extendedAuditEventCategory",
      "Value": "User"
    }
  ],
  "Id": "1d34e995-ca6e-49ad-a4ca-303c9318a8f1",
  "InterSystemsId": "441498ec-92e2-4235-9e7b-df017ac32fcb",
  "IntraSystemId": "344ba01a-f37f-49c2-8ad0-89c7802a1c0a",
  "ModifiedProperties": [
    {
      "Name": "Is Hard Deleted",
      "NewValue": "False"
    }
  ],
  "ObjectId": "5a110d55d6e040faa887b35f60262a12ExRemoved-48b8bcaf80964ac399523a64d64bd0b2@example.onmicrosoft.com",
  "Operation": "Delete user.",
  "OrganizationId": "00000000-0000-0000-0000-000000000001",
  "RecordType": 8,
  "ResultStatus": "Success",
  "Target": [
    {
      "ID": "User_5a110d55-d6e0-40fa-a887-b35f60262a12",
      "Type": 2
    },
    {
      "ID": "5a110d55-d6e0-40fa-a887-b35f60262a12",
      "Type": 2
    },
    {
      "ID": "User",
      "Type": 2
    },
    {
      "ID": "NotAgentic",
      "Type": 2
    },
    {
      "ID": "5a110d55d6e040faa887b35f60262a12ExRemoved-48b8bcaf80964ac399523a64d64bd0b2@example.onmicrosoft.com",
      "Type": 5
    },
    {
      "ID": "100320060FE64721",
      "Type": 3
    }
  ],
  "TargetContextId": "00000000-0000-0000-0000-000000000001",
  "UserId": "ServicePrincipal_414635d2-0108-489f-8a72-0a53de565cf9",
  "UserKey": "Not Available",
  "UserType": 4,
  "Version": 1,
  "Workload": "AzureActiveDirectory"
}

References #

Disable Strong Authentication.

#
RecordType
AzureActiveDirectory

Description

Microsoft Entra ID (Azure Active Directory) audit activity in the UserManagement category, recorded in the Office 365 Unified Audit Log.

Example Audit Record #

{
  "Actor": [
    {
      "ID": "rodsoto@rodsoto.onmicrosoft.com",
      "Type": 5
    },
    {
      "ID": "10037FFEA938FB92",
      "Type": 3
    },
    {
      "ID": "User_bfb8c366-0406-41a5-b3e3-328f4a3b4484",
      "Type": 2
    },
    {
      "ID": "bfb8c366-0406-41a5-b3e3-328f4a3b4484",
      "Type": 2
    },
    {
      "ID": "User",
      "Type": 2
    }
  ],
  "ActorContextId": "0e8108b1-18e9-41a4-961b-dfcddf92ef08",
  "AzureActiveDirectoryEventType": 1,
  "CreationTime": "2020-12-15T22:35:20",
  "ExtendedProperties": [
    {
      "Name": "additionalDetails",
      "Value": {}
    },
    {
      "Name": "extendedAuditEventCategory",
      "Value": "User"
    }
  ],
  "Id": "a5aea9c5-b879-495a-b764-119b2bd54d80",
  "InterSystemsId": "9d18b521-23df-4130-99e2-1ff2eee13333",
  "IntraSystemId": "7d96ab40-6e16-48e5-bf78-677c89683775",
  "ModifiedProperties": [
    {
      "Name": "StrongAuthenticationRequirement",
      "NewValue": [],
      "OldValue": [
        {
          "RelyingParty": "*",
          "State": 0,
          "RememberDevicesNotIssuedBefore": "2020-12-15T20:47:57+00:00"
        }
      ]
    },
    {
      "Name": "Included Updated Properties",
      "NewValue": "StrongAuthenticationRequirement",
      "OldValue": ""
    }
  ],
  "ObjectId": "rodsoto@rodsoto.onmicrosoft.com",
  "Operation": "Disable Strong Authentication.",
  "OrganizationId": "0e8108b1-18e9-41a4-961b-dfcddf92ef08",
  "RecordType": 8,
  "ResultStatus": "Success",
  "Target": [
    {
      "ID": "User_bfb8c366-0406-41a5-b3e3-328f4a3b4484",
      "Type": 2
    },
    {
      "ID": "bfb8c366-0406-41a5-b3e3-328f4a3b4484",
      "Type": 2
    },
    {
      "ID": "User",
      "Type": 2
    },
    {
      "ID": "rodsoto@rodsoto.onmicrosoft.com",
      "Type": 5
    },
    {
      "ID": "10037FFEA938FB92",
      "Type": 3
    }
  ],
  "TargetContextId": "0e8108b1-18e9-41a4-961b-dfcddf92ef08",
  "UserId": "rodsoto@rodsoto.onmicrosoft.com",
  "UserKey": "10037FFEA938FB92@rodsoto.onmicrosoft.com",
  "UserType": 0,
  "Version": 1,
  "Workload": "AzureActiveDirectory"
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sigma #

Splunk #

  • O365 Disable MFA source: The following analytic identifies instances where Multi-Factor Authentication (MFA) is disabled for a user within the Office 365 environment. It leverages O365 audit logs, specifically focusing on events related to MFA settings. Disabling…T1556

References #

Enable Strong Authentication.

#
RecordType
AzureActiveDirectory

Description

Records strong authentication (multifactor authentication) being enabled for a directory user.

Example Audit Record #

{
  "Actor": [
    {
      "ID": "rodsoto@rodsoto.onmicrosoft.com",
      "Type": 5
    },
    {
      "ID": "10037FFEA938FB92",
      "Type": 3
    },
    {
      "ID": "User_bfb8c366-0406-41a5-b3e3-328f4a3b4484",
      "Type": 2
    },
    {
      "ID": "bfb8c366-0406-41a5-b3e3-328f4a3b4484",
      "Type": 2
    },
    {
      "ID": "User",
      "Type": 2
    }
  ],
  "ActorContextId": "0e8108b1-18e9-41a4-961b-dfcddf92ef08",
  "AzureActiveDirectoryEventType": 1,
  "CreationTime": "2020-12-15T23:35:08",
  "ExtendedProperties": [
    {
      "Name": "additionalDetails",
      "Value": {}
    },
    {
      "Name": "extendedAuditEventCategory",
      "Value": "User"
    }
  ],
  "Id": "6aeb7062-8f6e-41d6-9b67-70b6a0c6a8f4",
  "InterSystemsId": "c3628235-f9cb-447b-bcba-9d1d4fba74e7",
  "IntraSystemId": "b4d02b98-f28e-4adf-b205-65167c2458c2",
  "ModifiedProperties": [
    {
      "Name": "StrongAuthenticationRequirement",
      "NewValue": [
        {
          "RelyingParty": "*",
          "State": 1,
          "RememberDevicesNotIssuedBefore": "2020-12-15T23:35:08.1700786Z"
        }
      ],
      "OldValue": []
    },
    {
      "Name": "Included Updated Properties",
      "NewValue": "StrongAuthenticationRequirement",
      "OldValue": ""
    }
  ],
  "ObjectId": "rodsoto@rodsoto.onmicrosoft.com",
  "Operation": "Enable Strong Authentication.",
  "OrganizationId": "0e8108b1-18e9-41a4-961b-dfcddf92ef08",
  "RecordType": 8,
  "ResultStatus": "Success",
  "Target": [
    {
      "ID": "User_bfb8c366-0406-41a5-b3e3-328f4a3b4484",
      "Type": 2
    },
    {
      "ID": "bfb8c366-0406-41a5-b3e3-328f4a3b4484",
      "Type": 2
    },
    {
      "ID": "User",
      "Type": 2
    },
    {
      "ID": "rodsoto@rodsoto.onmicrosoft.com",
      "Type": 5
    },
    {
      "ID": "10037FFEA938FB92",
      "Type": 3
    }
  ],
  "TargetContextId": "0e8108b1-18e9-41a4-961b-dfcddf92ef08",
  "UserId": "rodsoto@rodsoto.onmicrosoft.com",
  "UserKey": "10037FFEA938FB92@rodsoto.onmicrosoft.com",
  "UserType": 0,
  "Version": 1,
  "Workload": "AzureActiveDirectory"
}

References #

Remove app role assignment from service principal.

#
RecordType
AzureActiveDirectory

Description

An app role assignment was removed from a service principal, revoking an application's granted app role.

Example Audit Record #

{
  "CreationTime": "2024-02-08T21:45:53",
  "Id": "1b1c4d79-2b3a-4f7b-9947-04cc5abbbfc4",
  "Operation": "Remove app role assignment from service principal.",
  "OrganizationId": "75243ab2-44f8-435c-a7a6-b479385df6d4",
  "RecordType": 8,
  "ResultStatus": "Success",
  "UserKey": "1003BFFD98415B4E@splunkresearch.onmicrosoft.com",
  "UserType": 0,
  "Version": 1,
  "Workload": "AzureActiveDirectory",
  "ObjectId": "https://outlook.office.com;Microsoft.Exchange;00000002-0000-0ff1-ce00-000000000000;00000002-0000-0ff1-ce00-000000000000/*.outlook.com;00000002-0000-0ff1-ce00-000000000000/outlook.com;00000002-0000-0ff1-ce00-000000000000/mail.office365.com;00000002-0000-0ff1-ce00-000000000000/outlook.office365.com;https://webmail.apps.mil/;https://ps.protection.outlook.com/;https://outlook-dod.office365.us/;https://outlook.com/;https://outlook.office365.com/;https://outlook.office.com/;https://outlook.office365.com:443/;https://outlook-sdf.office365.com/;https://outlook-sdf.office.com/;https://outlook.office365.us/;https://autodiscover-s.office365.us/;https://ps.compliance.protection.outlook.com;https://manage.protection.apps.mil;https://outlook-tdf.office.com/;https://outlook-tdf-2.office.com/;https://ps.outlook.com",
  "UserId": "user30@splunkresearch.onmicrosoft.com",
  "AzureActiveDirectoryEventType": 1,
  "ExtendedProperties": [
    {
      "Name": "additionalDetails",
      "Value": {
        "User-Agent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/121.0.0.0 Safari/537.36",
        "AppId": "00000002-0000-0ff1-ce00-000000000000"
      }
    },
    {
      "Name": "extendedAuditEventCategory",
      "Value": "ServicePrincipal"
    }
  ],
  "ModifiedProperties": [
    {
      "Name": "AppRole.Id",
      "NewValue": "",
      "OldValue": "dc890d15-9560-4a4c-9b7f-a736ec74ec40"
    },
    {
      "Name": "AppRole.Value",
      "NewValue": "",
      "OldValue": ""
    },
    {
      "Name": "AppRole.DisplayName",
      "NewValue": "",
      "OldValue": ""
    },
    {
      "Name": "AppRoleAssignment.CreatedDateTime",
      "NewValue": "",
      "OldValue": "2/8/2024 9:40:19 PM"
    },
    {
      "Name": "AppRoleAssignment.LastModifiedDateTime",
      "NewValue": "",
      "OldValue": "2/8/2024 9:40:19 PM"
    },
    {
      "Name": "ServicePrincipal.ObjectID",
      "NewValue": "",
      "OldValue": "2e5c2fd0-cca4-452c-9891-a07c0dafd964"
    },
    {
      "Name": "ServicePrincipal.DisplayName",
      "NewValue": "",
      "OldValue": "STRT_Oauth"
    },
    {
      "Name": "ServicePrincipal.AppId",
      "NewValue": "5f91ce94-4cc5-4ebe-aeb6-f074e57201bb",
      "OldValue": ""
    },
    {
      "Name": "ServicePrincipal.Name",
      "NewValue": "5f91ce94-4cc5-4ebe-aeb6-f074e57201bb",
      "OldValue": ""
    },
    {
      "Name": "TargetId.ServicePrincipalNames",
      "NewValue": "https://outlook.office.com;Microsoft.Exchange;00000002-0000-0ff1-ce00-000000000000;00000002-0000-0ff1-ce00-000000000000/*.outlook.com;00000002-0000-0ff1-ce00-000000000000/outlook.com;00000002-0000-0ff1-ce00-000000000000/mail.office365.com;00000002-0000-0ff1-ce00-000000000000/outlook.office365.com;https://webmail.apps.mil/;https://ps.protection.outlook.com/;https://outlook-dod.office365.us/;https://outlook.com/;https://outlook.office365.com/;https://outlook.office.com/;https://outlook.office365.com:443/;https://outlook-sdf.office365.com/;https://outlook-sdf.office.com/;https://outlook.office365.us/;https://autodiscover-s.office365.us/;https://ps.compliance.protection.outlook.com;https://manage.protection.apps.mil;https://outlook-tdf.office.com/;https://outlook-tdf-2.office.com/;https://ps.outlook.com",
      "OldValue": ""
    }
  ],
  "Actor": [
    {
      "ID": "user30@splunkresearch.onmicrosoft.com",
      "Type": 5
    },
    {
      "ID": "1003BFFD98415B4E",
      "Type": 3
    },
    {
      "ID": "18ed3507-a475-4ccb-b669-d66bc9f2a36e",
      "Type": 2
    },
    {
      "ID": "User_e4c722ac-3b83-478d-8f52-c388885dc30f",
      "Type": 2
    },
    {
      "ID": "e4c722ac-3b83-478d-8f52-c388885dc30f",
      "Type": 2
    },
    {
      "ID": "User",
      "Type": 2
    }
  ],
  "ActorContextId": "75243ab2-44f8-435c-a7a6-b479385df6d4",
  "InterSystemsId": "4bb4393b-41c8-477a-8e78-e51760ed6748",
  "IntraSystemId": "00000000-0000-0000-0000-000000000000",
  "Target": [
    {
      "ID": "ServicePrincipal_8429eb5c-faeb-4ade-8eac-acc003790769",
      "Type": 2
    },
    {
      "ID": "8429eb5c-faeb-4ade-8eac-acc003790769",
      "Type": 2
    },
    {
      "ID": "ServicePrincipal",
      "Type": 2
    },
    {
      "ID": "Office 365 Exchange Online",
      "Type": 1
    },
    {
      "ID": "00000002-0000-0ff1-ce00-000000000000",
      "Type": 2
    },
    {
      "ID": "https://outlook.office.com;Microsoft.Exchange;00000002-0000-0ff1-ce00-000000000000;00000002-0000-0ff1-ce00-000000000000/*.outlook.com;00000002-0000-0ff1-ce00-000000000000/outlook.com;00000002-0000-0ff1-ce00-000000000000/mail.office365.com;00000002-0000-0ff1-ce00-000000000000/outlook.office365.com;https://webmail.apps.mil/;https://ps.protection.outlook.com/;https://outlook-dod.office365.us/;https://outlook.com/;https://outlook.office365.com/;https://outlook.office.com/;https://outlook.office365.com:443/;https://outlook-sdf.office365.com/;https://outlook-sdf.office.com/;https://outlook.office365.us/;https://autodiscover-s.office365.us/;https://ps.compliance.protection.outlook.com;https://manage.protection.apps.mil;https://outlook-tdf.office.com/;https://outlook-tdf-2.office.com/;https://ps.outlook.com",
      "Type": 4
    }
  ],
  "TargetContextId": "75243ab2-44f8-435c-a7a6-b479385df6d4"
}

References #

Remove delegated permission grant.

#
RecordType
AzureActiveDirectory

Description

An OAuth2 delegated permission grant was deleted, revoking the delegated API permissions granted to an application.

Example Audit Record #

{
  "Actor": [
    {
      "ID": "adminuser@example.onmicrosoft.com",
      "Type": 5
    },
    {
      "ID": "10000000AAAAAAAA",
      "Type": 3
    },
    {
      "ID": "User_11111111-1111-1111-1111-111111111111",
      "Type": 2
    },
    {
      "ID": "11111111-1111-1111-1111-111111111111",
      "Type": 2
    },
    {
      "ID": "User",
      "Type": 2
    },
    {
      "ID": "NotAgentic",
      "Type": 2
    }
  ],
  "ActorContextId": "00000000-0000-0000-0000-000000000001",
  "AzureActiveDirectoryEventType": 1,
  "CreationTime": "2026-07-02T15:30:16Z",
  "ExtendedProperties": [
    {
      "Name": "additionalDetails",
      "Value": {
        "User-Agent": "python/3.13.9 (Linux-6.1.0-41-amd64-x86_64-with-glibc2.36) AZURECLI/2.82.0 (DEB)",
        "AppId": "00000003-0000-0000-c000-000000000000",
        "ServicePrincipalProvisioningType": "Other"
      }
    },
    {
      "Name": "extendedAuditEventCategory",
      "Value": "ServicePrincipal"
    }
  ],
  "Id": "35e1ed1f-a18c-4d6b-a55b-0755ec0dffb2",
  "InterSystemsId": "ec463a89-5e9f-4c18-8bf9-a2796a0371cc",
  "IntraSystemId": "00000000-0000-0000-0000-000000000000",
  "ModifiedProperties": [
    {
      "Name": "DelegatedPermissionGrant.Scope",
      "OldValue": "User.Read"
    },
    {
      "Name": "DelegatedPermissionGrant.ConsentType",
      "OldValue": "Principal"
    },
    {
      "Name": "ServicePrincipal.ObjectID",
      "OldValue": "af2cee02-3ad4-4486-85a2-e8eafc78cd6e"
    },
    {
      "Name": "ServicePrincipal.DisplayName"
    },
    {
      "Name": "ServicePrincipal.AppId"
    },
    {
      "Name": "ServicePrincipal.Name"
    },
    {
      "Name": "TargetId.ServicePrincipalNames",
      "NewValue": "00000003-0000-0000-c000-000000000000/ags.windows.net;00000003-0000-0000-c000-000000000000;https://canary.graph.microsoft.com;https://graph.microsoft.com;https://ags.windows.net;https://graph.microsoft.us;https://graph.microsoft.com/;https://dod-graph.microsoft.us;https://canary.graph.microsoft.com/;https://graph.microsoft.us/;https://dod-graph.microsoft.us/"
    }
  ],
  "ObjectId": "00000003-0000-0000-c000-000000000000/ags.windows.net;00000003-0000-0000-c000-000000000000;https://canary.graph.microsoft.com;https://graph.microsoft.com;https://ags.windows.net;https://graph.microsoft.us;https://graph.microsoft.com/;https://dod-graph.microsoft.us;https://canary.graph.microsoft.com/;https://graph.microsoft.us/;https://dod-graph.microsoft.us/",
  "Operation": "Remove delegated permission grant.",
  "OrganizationId": "00000000-0000-0000-0000-000000000001",
  "RecordType": 8,
  "ResultStatus": "Success",
  "Target": [
    {
      "ID": "ServicePrincipal_2e5ab30e-ae89-43c2-b130-0022f3d655a7",
      "Type": 2
    },
    {
      "ID": "2e5ab30e-ae89-43c2-b130-0022f3d655a7",
      "Type": 2
    },
    {
      "ID": "ServicePrincipal",
      "Type": 2
    },
    {
      "ID": "NotAgentic",
      "Type": 2
    },
    {
      "ID": "Microsoft Graph",
      "Type": 1
    },
    {
      "ID": "00000003-0000-0000-c000-000000000000",
      "Type": 2
    },
    {
      "ID": "00000003-0000-0000-c000-000000000000/ags.windows.net;00000003-0000-0000-c000-000000000000;https://canary.graph.microsoft.com;https://graph.microsoft.com;https://ags.windows.net;https://graph.microsoft.us;https://graph.microsoft.com/;https://dod-graph.microsoft.us;https://canary.graph.microsoft.com/;https://graph.microsoft.us/;https://dod-graph.microsoft.us/",
      "Type": 4
    },
    {
      "ID": "Other",
      "Type": 2
    }
  ],
  "TargetContextId": "00000000-0000-0000-0000-000000000001",
  "UserId": "adminuser@example.onmicrosoft.com",
  "UserKey": "10000000AAAAAAAA@example.onmicrosoft.com",
  "UserType": 0,
  "Version": 1,
  "Workload": "AzureActiveDirectory"
}

References #

Remove member from administrative unit.

#
RecordType
AzureActiveDirectory

Description

Remove member from administrative unit. activity in Microsoft Entra ID, recorded in the Unified Audit Log (observed in first-party capture).

Example Audit Record #

{
  "Actor": [
    {
      "ID": "adminuser@example.onmicrosoft.com",
      "Type": 5
    },
    {
      "ID": 1111111111111111,
      "Type": 3
    },
    {
      "ID": "User_aaaaaaaa-0000-0000-0000-000000000001",
      "Type": 2
    },
    {
      "ID": "aaaaaaaa-0000-0000-0000-000000000001",
      "Type": 2
    },
    {
      "ID": "User",
      "Type": 2
    },
    {
      "ID": "NotAgentic",
      "Type": 2
    }
  ],
  "ActorContextId": "11111111-1111-1111-1111-111111111111",
  "AzureActiveDirectoryEventType": 1,
  "CreationDate": "2026-07-03T03:23:06",
  "CreationTime": "2026-07-03T03:23:06",
  "ExtendedProperties": [
    {
      "Name": "additionalDetails",
      "Value": {
        "User-Agent": "python/3.13.9 (Linux-6.1.0-41-amd64-x86_64-with-glibc2.36) AZURECLI/2.82.0 (DEB)"
      }
    },
    {
      "Name": "extendedAuditEventCategory",
      "Value": "AdministrativeUnit"
    }
  ],
  "Id": "ca5cb0c3-fa64-4ed9-82e7-581b5d9ee8fe",
  "InterSystemsId": "726ef9b3-5df3-49dd-93ad-bf105a018fce",
  "IntraSystemId": "9498d6b1-eb7d-4421-9748-cfa1ca5a103a",
  "ModifiedProperties": [
    {
      "Name": "AdministrativeUnit.ObjectID",
      "NewValue": "",
      "OldValue": "78e00ff9-4f90-4a2d-ba46-416e73ce7793"
    },
    {
      "Name": "AdministrativeUnit.DisplayName",
      "NewValue": "",
      "OldValue": "dw-harness-aum-2fe5ab51"
    }
  ],
  "ObjectId": "adminuser@example.onmicrosoft.com",
  "Operation": "Remove member from administrative unit.",
  "Operations": "Remove member from administrative unit.",
  "OrganizationId": "11111111-1111-1111-1111-111111111111",
  "RecordType": "AzureActiveDirectory",
  "ResultStatus": "Success",
  "Target": [
    {
      "ID": "User_aaaaaaaa-0000-0000-0000-000000000001",
      "Type": 2
    },
    {
      "ID": "aaaaaaaa-0000-0000-0000-000000000001",
      "Type": 2
    },
    {
      "ID": "User",
      "Type": 2
    },
    {
      "ID": "NotAgentic",
      "Type": 2
    },
    {
      "ID": "adminuser@example.onmicrosoft.com",
      "Type": 5
    },
    {
      "ID": 1111111111111111,
      "Type": 3
    }
  ],
  "TargetContextId": "11111111-1111-1111-1111-111111111111",
  "UserId": "adminuser@example.onmicrosoft.com",
  "UserKey": "1111111111111111@example.onmicrosoft.com",
  "UserType": "Regular",
  "Version": 1,
  "Workload": "AzureActiveDirectory"
}

References #

Remove member from group.

#
RecordType
AzureActiveDirectory

Description

A principal was removed from a group in Azure Active Directory (the UAL operation string includes a trailing period).

Example Audit Record #

{
  "Actor": [
    {
      "ID": "adminuser@example.onmicrosoft.com",
      "Type": 5
    },
    {
      "ID": "10000000AAAAAAAA",
      "Type": 3
    },
    {
      "ID": "dw-activity-gen",
      "Type": 1
    },
    {
      "ID": "22222222-2222-2222-2222-222222222222",
      "Type": 2
    },
    {
      "ID": "User_11111111-1111-1111-1111-111111111111",
      "Type": 2
    },
    {
      "ID": "11111111-1111-1111-1111-111111111111",
      "Type": 2
    },
    {
      "ID": "User",
      "Type": 2
    },
    {
      "ID": "NotAgentic",
      "Type": 2
    }
  ],
  "ActorContextId": "00000000-0000-0000-0000-000000000001",
  "AzureActiveDirectoryEventType": 1,
  "CreationTime": "2026-07-02T02:10:50Z",
  "ExtendedProperties": [
    {
      "Name": "additionalDetails",
      "Value": {
        "User-Agent": "python-requests/2.34.2"
      }
    },
    {
      "Name": "extendedAuditEventCategory",
      "Value": "Group"
    }
  ],
  "Id": "6af15b64-c0a6-4170-a570-5b1dbdb4f71b",
  "InterSystemsId": "0a9a66d0-cf43-4033-b845-b1ffdf639ce8",
  "IntraSystemId": "00000000-0000-0000-0000-000000000000",
  "ModifiedProperties": [
    {
      "Name": "Group.ObjectID",
      "OldValue": "72ff2416-ca78-4443-8b25-800823d06143"
    },
    {
      "Name": "Group.DisplayName",
      "OldValue": "dw-harness-60974bd7-group"
    }
  ],
  "ObjectId": "adminuser@example.onmicrosoft.com",
  "Operation": "Remove member from group.",
  "OrganizationId": "00000000-0000-0000-0000-000000000001",
  "RecordType": 8,
  "ResultStatus": "Success",
  "Target": [
    {
      "ID": "User_11111111-1111-1111-1111-111111111111",
      "Type": 2
    },
    {
      "ID": "11111111-1111-1111-1111-111111111111",
      "Type": 2
    },
    {
      "ID": "User",
      "Type": 2
    },
    {
      "ID": "NotAgentic",
      "Type": 2
    },
    {
      "ID": "adminuser@example.onmicrosoft.com",
      "Type": 5
    },
    {
      "ID": "10000000AAAAAAAA",
      "Type": 3
    }
  ],
  "TargetContextId": "00000000-0000-0000-0000-000000000001",
  "UserId": "adminuser@example.onmicrosoft.com",
  "UserKey": "10000000AAAAAAAA@example.onmicrosoft.com",
  "UserType": 0,
  "Version": 1,
  "Workload": "AzureActiveDirectory"
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

YARA-L #

References #

Remove member from role.

#
RecordType
AzureActiveDirectory

Description

A principal was removed from a directory role.

Example Audit Record #

{
  "Actor": [
    {
      "ID": "adminuser@example.onmicrosoft.com",
      "Type": 5
    },
    {
      "ID": "10000000AAAAAAAA",
      "Type": 3
    },
    {
      "ID": "User_11111111-1111-1111-1111-111111111111",
      "Type": 2
    },
    {
      "ID": "11111111-1111-1111-1111-111111111111",
      "Type": 2
    },
    {
      "ID": "User",
      "Type": 2
    },
    {
      "ID": "NotAgentic",
      "Type": 2
    }
  ],
  "ActorContextId": "00000000-0000-0000-0000-000000000001",
  "AzureActiveDirectoryEventType": 1,
  "CreationTime": "2026-07-02T15:30:07Z",
  "ExtendedProperties": [
    {
      "Name": "additionalDetails",
      "Value": {
        "User-Agent": "python/3.13.9 (Linux-6.1.0-41-amd64-x86_64-with-glibc2.36) AZURECLI/2.82.0 (DEB)"
      }
    },
    {
      "Name": "extendedAuditEventCategory",
      "Value": "Role"
    }
  ],
  "Id": "7104b5e7-9dd6-44dc-a644-0e160c40cdf0",
  "InterSystemsId": "11141a75-f187-43d5-96e9-74c3b6c2c937",
  "IntraSystemId": "6860ba53-8504-4b16-b3e4-3b20b7f29417",
  "ModifiedProperties": [
    {
      "Name": "Role.ObjectID",
      "OldValue": "ba4b3989-6c3a-4095-bec6-a973070cfa28"
    },
    {
      "Name": "Role.DisplayName",
      "OldValue": "Directory Readers"
    },
    {
      "Name": "Role.TemplateId",
      "OldValue": "88d8e3e3-8f55-4a1e-953a-9b9898b8876b"
    },
    {
      "Name": "Role.WellKnownObjectName",
      "OldValue": "DirectoryReaders"
    }
  ],
  "ObjectId": "dwtestuser@example.onmicrosoft.com",
  "Operation": "Remove member from role.",
  "OrganizationId": "00000000-0000-0000-0000-000000000001",
  "RecordType": 8,
  "ResultStatus": "Success",
  "Target": [
    {
      "ID": "User_6b8aef40-5bf4-449f-8164-c2ae9affa2df",
      "Type": 2
    },
    {
      "ID": "6b8aef40-5bf4-449f-8164-c2ae9affa2df",
      "Type": 2
    },
    {
      "ID": "User",
      "Type": 2
    },
    {
      "ID": "NotAgentic",
      "Type": 2
    },
    {
      "ID": "dwtestuser@example.onmicrosoft.com",
      "Type": 5
    },
    {
      "ID": "10032006100D3C25",
      "Type": 3
    }
  ],
  "TargetContextId": "00000000-0000-0000-0000-000000000001",
  "UserId": "adminuser@example.onmicrosoft.com",
  "UserKey": "10000000AAAAAAAA@example.onmicrosoft.com",
  "UserType": 0,
  "Version": 1,
  "Workload": "AzureActiveDirectory"
}

References #

Remove service principal.

#
RecordType
AzureActiveDirectory

Description

A service principal was removed.

Example Audit Record #

{
  "CreationTime": "2023-09-01T17:10:56",
  "Id": "730cbb8e-962e-43e6-b442-aaf3bc8dfece",
  "Operation": "Remove service principal.",
  "OrganizationId": "58aee3b9-7433-46a0-b54e-2429487992a0",
  "RecordType": 8,
  "ResultStatus": "Success",
  "UserKey": "1003BFFD98415B4E@contoso.onmicrosoft.com",
  "UserType": 0,
  "Version": 1,
  "Workload": "AzureActiveDirectory",
  "ObjectId": "c1d6e216-dfbf-4c1f-818d-d6bfc99f0694",
  "UserId": "attacker@contoso.onmicrosoft.com",
  "AzureActiveDirectoryEventType": 1,
  "ExtendedProperties": [
    {
      "Name": "additionalDetails",
      "Value": {
        "User-Agent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Safari/537.36",
        "AppId": "c1d6e216-dfbf-4c1f-818d-d6bfc99f0694"
      }
    },
    {
      "Name": "extendedAuditEventCategory",
      "Value": "ServicePrincipal"
    }
  ],
  "ModifiedProperties": [
    {
      "Name": "TargetId.ServicePrincipalNames",
      "NewValue": "c1d6e216-dfbf-4c1f-818d-d6bfc99f0694",
      "OldValue": ""
    }
  ],
  "Actor": [
    {
      "ID": "attacker@contoso.onmicrosoft.com",
      "Type": 5
    },
    {
      "ID": "1003BFFD98415B4E",
      "Type": 3
    },
    {
      "ID": "18ed3507-a475-4ccb-b669-d66bc9f2a36e",
      "Type": 2
    },
    {
      "ID": "User_e4c722ac-3b83-478d-8f52-c388885dc30f",
      "Type": 2
    },
    {
      "ID": "e4c722ac-3b83-478d-8f52-c388885dc30f",
      "Type": 2
    },
    {
      "ID": "User",
      "Type": 2
    }
  ],
  "ActorContextId": "58aee3b9-7433-46a0-b54e-2429487992a0",
  "InterSystemsId": "12534c88-4425-477a-a40f-ea74457a7c9b",
  "IntraSystemId": "a2d4d7c4-727c-401b-9e6c-70413a080855",
  "Target": [
    {
      "ID": "ServicePrincipal_01b95e22-4308-41f0-abec-9c49aa213698",
      "Type": 2
    },
    {
      "ID": "01b95e22-4308-41f0-abec-9c49aa213698",
      "Type": 2
    },
    {
      "ID": "ServicePrincipal",
      "Type": 2
    },
    {
      "ID": "TestApp1",
      "Type": 1
    },
    {
      "ID": "c1d6e216-dfbf-4c1f-818d-d6bfc99f0694",
      "Type": 2
    },
    {
      "ID": "c1d6e216-dfbf-4c1f-818d-d6bfc99f0694",
      "Type": 4
    }
  ],
  "TargetContextId": "58aee3b9-7433-46a0-b54e-2429487992a0"
}

References #

Reset user password.

#
RecordType
AzureActiveDirectory

Description

An administrator reset a user's password.

Example Audit Record #

{
  "Actor": [
    {
      "ID": "adminuser@example.onmicrosoft.com",
      "Type": 5
    },
    {
      "ID": "10000000AAAAAAAA",
      "Type": 3
    },
    {
      "ID": "User_11111111-1111-1111-1111-111111111111",
      "Type": 2
    },
    {
      "ID": "11111111-1111-1111-1111-111111111111",
      "Type": 2
    },
    {
      "ID": "User",
      "Type": 2
    },
    {
      "ID": "NotAgentic",
      "Type": 2
    }
  ],
  "ActorContextId": "00000000-0000-0000-0000-000000000001",
  "AzureActiveDirectoryEventType": 1,
  "CreationTime": "2026-07-02T15:29:59Z",
  "ExtendedProperties": [
    {
      "Name": "additionalDetails",
      "Value": {
        "User-Agent": "python/3.13.9 (Linux-6.1.0-41-amd64-x86_64-with-glibc2.36) AZURECLI/2.82.0 (DEB)"
      }
    },
    {
      "Name": "extendedAuditEventCategory",
      "Value": "User"
    }
  ],
  "Id": "34d94b27-3857-4c87-80e5-f6c60d8b5d7b",
  "InterSystemsId": "884ecd76-2d50-48e7-b8de-af4fb379eaf9",
  "IntraSystemId": "9c60102e-f8d1-40d4-b9ee-f9cd71600ece",
  "ObjectId": "dwtestuser@example.onmicrosoft.com",
  "Operation": "Reset user password.",
  "OrganizationId": "00000000-0000-0000-0000-000000000001",
  "RecordType": 8,
  "ResultStatus": "Success",
  "Target": [
    {
      "ID": "User_6b8aef40-5bf4-449f-8164-c2ae9affa2df",
      "Type": 2
    },
    {
      "ID": "6b8aef40-5bf4-449f-8164-c2ae9affa2df",
      "Type": 2
    },
    {
      "ID": "User",
      "Type": 2
    },
    {
      "ID": "NotAgentic",
      "Type": 2
    },
    {
      "ID": "dwtestuser@example.onmicrosoft.com",
      "Type": 5
    },
    {
      "ID": "10032006100D3C25",
      "Type": 3
    }
  ],
  "TargetContextId": "00000000-0000-0000-0000-000000000001",
  "UserId": "adminuser@example.onmicrosoft.com",
  "UserKey": "10000000AAAAAAAA@example.onmicrosoft.com",
  "UserType": 0,
  "Version": 1,
  "Workload": "AzureActiveDirectory"
}

References #

Set Company Information.

#
RecordType
AzureActiveDirectory

Description

Microsoft Entra ID (Azure Active Directory) audit activity in the DirectoryManagement category, recorded in the Office 365 Unified Audit Log.

Example Audit Record #

{
  "Actor": [
    {
      "ID": "bpatel@rodsoto.onmicrosoft.com",
      "Type": 5
    },
    {
      "ID": "100320010208B5DC",
      "Type": 3
    },
    {
      "ID": "User_425b75db-38be-4c7b-a474-5f0709247370",
      "Type": 2
    },
    {
      "ID": "425b75db-38be-4c7b-a474-5f0709247370",
      "Type": 2
    },
    {
      "ID": "User",
      "Type": 2
    }
  ],
  "ActorContextId": "0e8108b1-18e9-41a4-961b-dfcddf92ef08",
  "AzureActiveDirectoryEventType": 1,
  "CreationTime": "2021-01-13T22:57:21",
  "ExtendedProperties": [
    {
      "Name": "additionalDetails",
      "Value": {}
    },
    {
      "Name": "extendedAuditEventCategory",
      "Value": "Company"
    }
  ],
  "Id": "50a62783-f9d7-472c-9e44-f4f3d346e53c",
  "InterSystemsId": "6f435e84-e95b-44da-820f-2d2c9c237293",
  "IntraSystemId": "1163f0db-2241-4689-8486-b15c7812bbe0",
  "ModifiedProperties": [
    {
      "Name": "StrongAuthenticationPolicy",
      "NewValue": [
        {
          "RelyingPartyStrongAuthenticationPolicies": [
            {
              "RelyingParties": [
                "*"
              ],
              "Rules": [
                {
                  "SelectionConditions": [
                    {
                      "Claim": 1,
                      "Operator": 0,
                      "Values": [
                        "73.15.72.101/32",
                        "66.176.252.11/32"
                      ]
                    }
                  ]
                }
              ],
              "Enabled": true
            }
          ]
        }
      ],
      "OldValue": [
        {
          "RelyingPartyStrongAuthenticationPolicies": [
            {
              "RelyingParties": [
                "*"
              ],
              "Rules": [
                {
                  "SelectionConditions": [
                    {
                      "Claim": 1,
                      "Operator": 0,
                      "Values": [
                        "73.15.72.101/32",
                        "66.176.252.11/32"
                      ]
                    }
                  ]
                },
                {
                  "SelectionConditions": [
                    {
                      "Claim": 2,
                      "Operator": 0,
                      "Values": [
                        "insidecorporatenetwork--true"
                      ]
                    }
                  ]
                }
              ],
              "Enabled": true
            }
          ]
        }
      ]
    },
    {
      "Name": "Included Updated Properties",
      "NewValue": "StrongAuthenticationPolicy",
      "OldValue": ""
    }
  ],
  "ObjectId": "Company_0e8108b1-18e9-41a4-961b-dfcddf92ef08",
  "Operation": "Set Company Information.",
  "OrganizationId": "0e8108b1-18e9-41a4-961b-dfcddf92ef08",
  "RecordType": 8,
  "ResultStatus": "Success",
  "Target": [
    {
      "ID": "Company_0e8108b1-18e9-41a4-961b-dfcddf92ef08",
      "Type": 2
    },
    {
      "ID": "0e8108b1-18e9-41a4-961b-dfcddf92ef08",
      "Type": 2
    },
    {
      "ID": "Directory",
      "Type": 2
    },
    {
      "ID": "Emergency Information Technology Services LLC",
      "Type": 1
    }
  ],
  "TargetContextId": "0e8108b1-18e9-41a4-961b-dfcddf92ef08",
  "UserId": "bpatel@rodsoto.onmicrosoft.com",
  "UserKey": "100320010208B5DC@rodsoto.onmicrosoft.com",
  "UserType": 0,
  "Version": 1,
  "Workload": "AzureActiveDirectory"
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Splunk #

  • O365 Bypass MFA via Trusted IP source: The following analytic identifies instances where new IP addresses are added to the trusted IPs list in Office 365, potentially allowing users from these IPs to bypass Multi-Factor Authentication (MFA) during login. It leverages O365 audit…T1686, T1686.001

References #

Set-MsolDomainFederationSettings

#
RecordType
AzureActiveDirectory

Description

Federation settings for a domain were changed via the MSOnline module (a directory operation, not an Exchange cmdlet); abused to add a backdoor federation trust.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

References #

Update administrative unit.

#
RecordType
AzureActiveDirectory

Description

Update administrative unit. activity in Microsoft Entra ID, recorded in the Unified Audit Log (observed in first-party capture).

Example Audit Record #

{
  "Actor": [
    {
      "ID": "adminuser@example.onmicrosoft.com",
      "Type": 5
    },
    {
      "ID": 1111111111111111,
      "Type": 3
    },
    {
      "ID": "User_aaaaaaaa-0000-0000-0000-000000000001",
      "Type": 2
    },
    {
      "ID": "aaaaaaaa-0000-0000-0000-000000000001",
      "Type": 2
    },
    {
      "ID": "User",
      "Type": 2
    },
    {
      "ID": "NotAgentic",
      "Type": 2
    }
  ],
  "ActorContextId": "11111111-1111-1111-1111-111111111111",
  "AzureActiveDirectoryEventType": 1,
  "CreationDate": "2026-07-03T03:22:26",
  "CreationTime": "2026-07-03T03:22:26",
  "ExtendedProperties": [
    {
      "Name": "additionalDetails",
      "Value": {
        "User-Agent": "python/3.13.9 (Linux-6.1.0-41-amd64-x86_64-with-glibc2.36) AZURECLI/2.82.0 (DEB)"
      }
    },
    {
      "Name": "extendedAuditEventCategory",
      "Value": "AdministrativeUnit"
    }
  ],
  "Id": "f6522d70-5658-44f7-8f41-f875ffc187a3",
  "InterSystemsId": "a4938fd1-cdc7-4231-b6a2-dc01f7e9753c",
  "IntraSystemId": "b4076f75-40d6-418c-986f-c4aa7fae04ff",
  "ModifiedProperties": [
    {
      "Name": "Description",
      "NewValue": [
        "harness"
      ],
      "OldValue": []
    },
    {
      "Name": "Included Updated Properties",
      "NewValue": "Description",
      "OldValue": ""
    }
  ],
  "ObjectId": "AdministrativeUnit_7e05260c-9113-4f21-832d-52289dfbea92",
  "Operation": "Update administrative unit.",
  "Operations": "Update administrative unit.",
  "OrganizationId": "11111111-1111-1111-1111-111111111111",
  "RecordType": "AzureActiveDirectory",
  "ResultStatus": "Success",
  "Target": [
    {
      "ID": "AdministrativeUnit_7e05260c-9113-4f21-832d-52289dfbea92",
      "Type": 2
    },
    {
      "ID": "7e05260c-9113-4f21-832d-52289dfbea92",
      "Type": 2
    },
    {
      "ID": "Manager",
      "Type": 2
    },
    {
      "ID": "dw-harness-au-2fe5ab51",
      "Type": 1
    }
  ],
  "TargetContextId": "11111111-1111-1111-1111-111111111111",
  "UserId": "adminuser@example.onmicrosoft.com",
  "UserKey": "1111111111111111@example.onmicrosoft.com",
  "UserType": "Regular",
  "Version": 1,
  "Workload": "AzureActiveDirectory"
}

References #

Update application – Certificates and secrets management

#
RecordType
AzureActiveDirectory

Description

Update application – Certificates and secrets management activity in Microsoft Entra ID, recorded in the Unified Audit Log (observed in first-party capture).

Example Audit Record #

{
  "Actor": [
    {
      "ID": "adminuser@example.onmicrosoft.com",
      "Type": 5
    },
    {
      "ID": 1111111111111111,
      "Type": 3
    },
    {
      "ID": "User_aaaaaaaa-0000-0000-0000-000000000001",
      "Type": 2
    },
    {
      "ID": "aaaaaaaa-0000-0000-0000-000000000001",
      "Type": 2
    },
    {
      "ID": "User",
      "Type": 2
    },
    {
      "ID": "NotAgentic",
      "Type": 2
    }
  ],
  "ActorContextId": "11111111-1111-1111-1111-111111111111",
  "AzureActiveDirectoryEventType": 1,
  "CreationDate": "2026-07-03T01:41:35",
  "CreationTime": "2026-07-03T01:41:35",
  "ExtendedProperties": [
    {
      "Name": "additionalDetails",
      "Value": {
        "User-Agent": "python/3.13.9 (Linux-6.1.0-41-amd64-x86_64-with-glibc2.36) AZURECLI/2.82.0 (DEB)",
        "AppId": "22222222-2222-2222-2222-222222222222"
      }
    },
    {
      "Name": "extendedAuditEventCategory",
      "Value": "Application"
    }
  ],
  "Id": "59870a3a-48ba-4acc-ab0c-cc757d59d436",
  "InterSystemsId": "f88fbfc5-4409-4f78-8235-a91af522f219",
  "IntraSystemId": "00000000-0000-0000-0000-000000000000",
  "ModifiedProperties": [
    {
      "Name": "KeyDescription",
      "NewValue": [
        "[KeyIdentifier=c628b892-73f9-4045-927c-48934ab19b20,KeyType=AsymmetricX509Cert,KeyUsage=Verify,DisplayName=CN=dw-activity-gen]",
        "[KeyIdentifier=47646249-73bb-41e2-9bdd-3d1b3984acc5,KeyType=AsymmetricX509Cert,KeyUsage=Verify,DisplayName=CN=dw-activity-gen-harness]"
      ],
      "OldValue": [
        "[KeyIdentifier=c628b892-73f9-4045-927c-48934ab19b20,KeyType=AsymmetricX509Cert,KeyUsage=Verify,DisplayName=CN=dw-activity-gen]"
      ]
    },
    {
      "Name": "Included Updated Properties",
      "NewValue": "KeyDescription",
      "OldValue": ""
    }
  ],
  "ObjectId": "Application_5da95dd1-8642-48d8-86c1-5f3fc4e7dd64",
  "Operation": "Update application – Certificates and secrets management ",
  "Operations": "Update application – Certificates and secrets management ",
  "OrganizationId": "11111111-1111-1111-1111-111111111111",
  "RecordType": "AzureActiveDirectory",
  "ResultStatus": "Success",
  "Target": [
    {
      "ID": "Application_5da95dd1-8642-48d8-86c1-5f3fc4e7dd64",
      "Type": 2
    },
    {
      "ID": "5da95dd1-8642-48d8-86c1-5f3fc4e7dd64",
      "Type": 2
    },
    {
      "ID": "Application",
      "Type": 2
    },
    {
      "ID": "NotAgentic",
      "Type": 2
    },
    {
      "ID": "dw-activity-gen",
      "Type": 1
    },
    {
      "ID": "22222222-2222-2222-2222-222222222222",
      "Type": 2
    }
  ],
  "TargetContextId": "11111111-1111-1111-1111-111111111111",
  "UserId": "adminuser@example.onmicrosoft.com",
  "UserKey": "1111111111111111@example.onmicrosoft.com",
  "UserType": "Regular",
  "Version": 1,
  "Workload": "AzureActiveDirectory"
}

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
target.resource.product_object_id (Chronicle)eq1b730954-1685-4b74-9bfd-dac224a7b8941 rulechronicle

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

YARA-L #

References #

Update application.

#
RecordType
AzureActiveDirectory

Description

An application registration was modified in Azure Active Directory (the UAL operation string includes a trailing period).

Example Audit Record #

{
  "Actor": [
    {
      "ID": "adminuser@example.onmicrosoft.com",
      "Type": 5
    },
    {
      "ID": 1111111111111111,
      "Type": 3
    },
    {
      "ID": "User_11111111-1111-1111-1111-111111111111",
      "Type": 2
    },
    {
      "ID": "11111111-1111-1111-1111-111111111111",
      "Type": 2
    },
    {
      "ID": "User",
      "Type": 2
    },
    {
      "ID": "NotAgentic",
      "Type": 2
    }
  ],
  "ActorContextId": "00000000-0000-0000-0000-000000000001",
  "AzureActiveDirectoryEventType": 1,
  "CreationTime": "2026-07-03T01:52:35Z",
  "ExtendedProperties": [
    {
      "Name": "additionalDetails",
      "Value": {
        "User-Agent": "python/3.13.9 (Linux-6.1.0-41-amd64-x86_64-with-glibc2.36) AZURECLI/2.82.0 (DEB)",
        "AppId": "82f6bc24-719b-4329-a62c-e20d64c1ed9b"
      }
    },
    {
      "Name": "extendedAuditEventCategory",
      "Value": "Application"
    }
  ],
  "Id": "d369b34f-2e4f-474a-8673-2449e37b9efe",
  "InterSystemsId": "6f53ee1a-4999-4e13-b4b1-fe2738b6364a",
  "IntraSystemId": "00000000-0000-0000-0000-000000000000",
  "ModifiedProperties": [
    {
      "Name": "Included Updated Properties",
      "NewValue": "",
      "OldValue": ""
    }
  ],
  "ObjectId": "Application_7de47a5c-1afd-4428-b11c-b9359b8380f6",
  "Operation": "Update application.",
  "OrganizationId": "00000000-0000-0000-0000-000000000001",
  "RecordType": 8,
  "ResultStatus": "Success",
  "Target": [
    {
      "ID": "Application_7de47a5c-1afd-4428-b11c-b9359b8380f6",
      "Type": 2
    },
    {
      "ID": "7de47a5c-1afd-4428-b11c-b9359b8380f6",
      "Type": 2
    },
    {
      "ID": "Application",
      "Type": 2
    },
    {
      "ID": "NotAgentic",
      "Type": 2
    },
    {
      "ID": "dw-harness-app-78619d48",
      "Type": 1
    },
    {
      "ID": "82f6bc24-719b-4329-a62c-e20d64c1ed9b",
      "Type": 2
    }
  ],
  "TargetContextId": "00000000-0000-0000-0000-000000000001",
  "UserId": "adminuser@example.onmicrosoft.com",
  "UserKey": "1111111111111111@example.onmicrosoft.com",
  "UserType": 0,
  "Version": 1,
  "Workload": "AzureActiveDirectory"
}

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
target.resource.attribute.labels.key (Chronicle)regex_matchNewValue_EntitlementId-3 ruleschronicle
target.resource.attribute.labels.key (Chronicle)regex_matchOldValue_EntitlementId-3 ruleschronicle
target.resource.product_object_id (Chronicle)eq1b730954-1685-4b74-9bfd-dac224a7b8941 rulechronicle
{}.RequiredAppPermissions{}.EntitlementId (splunk rule field)eq06b708a9-e830-4db3-a914-8e69da51d44f1 rulesplunk
{}.RequiredAppPermissions{}.EntitlementId (splunk rule field)eq9e3f62cf-ca93-4989-b6ce-bf83c28f9fe81 rulesplunk
{}.RequiredAppPermissions{}.EntitlementId (splunk rule field)eqdc890d15-9560-4a4c-9b7f-a736ec74ec401 rulesplunk
{}.ResourceAppId (splunk rule field)eq00000002-0000-0ff1-ce00-0000000000001 rulesplunk

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Splunk #

YARA-L #

References #

Update authorization policy.

#
RecordType
AzureActiveDirectory

Description

Microsoft Entra ID (Azure Active Directory) audit activity in the AuthorizationPolicy category, recorded in the Office 365 Unified Audit Log.

Example Audit Record #

{
  "CreationTime": "2023-10-26T19:22:20",
  "Id": "83774e72-313f-4d1f-8609-7d0c7bb3b4ff",
  "Operation": "Update authorization policy.",
  "OrganizationId": "a417c578-c7ee-480d-a225-d48057e74df5",
  "RecordType": 8,
  "ResultStatus": "Success",
  "UserKey": "1003BFFD98415B4E@splunkresearch.onmicrosoft.com",
  "UserType": 0,
  "Version": 1,
  "Workload": "AzureActiveDirectory",
  "ObjectId": "AuthorizationPolicy_24484114-1daa-4700-aaf7-44ee5cbe5678",
  "UserId": "user30@splunkresearch.onmicrosoft.com",
  "AzureActiveDirectoryEventType": 1,
  "ExtendedProperties": [
    {
      "Name": "additionalDetails",
      "Value": {
        "User-Agent": "Swagger-Codegen/1.0.0.0/csharp/msal"
      }
    },
    {
      "Name": "extendedAuditEventCategory",
      "Value": "AuthorizationPolicy"
    }
  ],
  "ModifiedProperties": [
    {
      "Name": "AllowUserConsentForRiskyApps",
      "NewValue": [
        true
      ],
      "OldValue": [
        false
      ]
    },
    {
      "Name": "PermissionGrantPolicyIdsAssignedToDefaultUserRole",
      "NewValue": [
        "microsoft-user-default-legacy"
      ],
      "OldValue": [
        "ManagePermissionGrantsForSelf.microsoft-user-default-legacy"
      ]
    },
    {
      "Name": "Included Updated Properties",
      "NewValue": "AllowUserConsentForRiskyApps, PermissionGrantPolicyIdsAssignedToDefaultUserRole",
      "OldValue": ""
    }
  ],
  "Actor": [
    {
      "ID": "user30@splunkresearch.onmicrosoft.com",
      "Type": 5
    },
    {
      "ID": "1003BFFD98415B4E",
      "Type": 3
    },
    {
      "ID": "User_e4c722ac-3b83-478d-8f52-c388885dc30f",
      "Type": 2
    },
    {
      "ID": "e4c722ac-3b83-478d-8f52-c388885dc30f",
      "Type": 2
    },
    {
      "ID": "User",
      "Type": 2
    }
  ],
  "ActorContextId": "a417c578-c7ee-480d-a225-d48057e74df5",
  "InterSystemsId": "cc46d719-4c0f-4b78-8795-b0d6ca5b2065",
  "IntraSystemId": "92a0d051-2d0d-4608-9d09-6fca619764a2",
  "Target": [
    {
      "ID": "AuthorizationPolicy_24484114-1daa-4700-aaf7-44ee5cbe5678",
      "Type": 2
    },
    {
      "ID": "24484114-1daa-4700-aaf7-44ee5cbe5678",
      "Type": 2
    },
    {
      "ID": "Other",
      "Type": 2
    },
    {
      "ID": "Authorization Policy",
      "Type": 1
    }
  ],
  "TargetContextId": "a417c578-c7ee-480d-a225-d48057e74df5"
}

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
index_number (splunk rule field)ge01 rulesplunk

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Splunk #

  • O365 Block User Consent For Risky Apps Disabled source: The following analytic detects when the "risk-based step-up consent" security setting in Microsoft 365 is disabled. It monitors Azure Active Directory logs for the "Update authorization policy" operation, specifically changes to the…T1685

References #

Update company settings

#
RecordType
AzureActiveDirectory

Description

Update company settings activity in Microsoft Entra ID, recorded in the Unified Audit Log (observed in first-party capture).

Example Audit Record #

{
  "Actor": [
    {
      "ID": "adminuser@example.onmicrosoft.com",
      "Type": 5
    },
    {
      "ID": 1111111111111111,
      "Type": 3
    },
    {
      "ID": "User_aaaaaaaa-0000-0000-0000-000000000001",
      "Type": 2
    },
    {
      "ID": "aaaaaaaa-0000-0000-0000-000000000001",
      "Type": 2
    },
    {
      "ID": "User",
      "Type": 2
    },
    {
      "ID": "NotAgentic",
      "Type": 2
    }
  ],
  "ActorContextId": "11111111-1111-1111-1111-111111111111",
  "AzureActiveDirectoryEventType": 1,
  "CreationDate": "2026-07-03T01:52:56",
  "CreationTime": "2026-07-03T01:52:56",
  "ExtendedProperties": [
    {
      "Name": "additionalDetails",
      "Value": {
        "User-Agent": "python/3.13.9 (Linux-6.1.0-41-amd64-x86_64-with-glibc2.36) AZURECLI/2.82.0 (DEB)"
      }
    },
    {
      "Name": "extendedAuditEventCategory",
      "Value": "Company"
    }
  ],
  "Id": "f3e66cd3-18c8-4fd8-b03f-c03be7b96baf",
  "InterSystemsId": "3cd323b3-3000-4a06-b9de-43a8557c95e0",
  "IntraSystemId": "00000000-0000-0000-0000-000000000000",
  "ModifiedProperties": [
    {
      "Name": "ObjectSettings",
      "NewValue": [
        {
          "Settings": [
            {
              "Id": "7052686f-501a-40f5-9d7d-4e2a36372a6d",
              "ObjectSettingTemplateId": "62375ab9-6b52-47ed-826b-58e47e0e304b",
              "Properties": [
                {
                  "Key": "EnableMSStandardBlockedWords",
                  "Value": "true"
                }
              ]
            }
          ]
        }
      ],
      "OldValue": [
        {
          "Settings": [
            {
              "Id": "7052686f-501a-40f5-9d7d-4e2a36372a6d",
              "ObjectSettingTemplateId": "62375ab9-6b52-47ed-826b-58e47e0e304b",
              "Properties": [
                {
                  "Key": "EnableMSStandardBlockedWords",
                  "Value": "false"
                }
              ]
            }
          ]
        }
      ]
    },
    {
      "Name": "Included Updated Properties",
      "NewValue": "ObjectSettings",
      "OldValue": ""
    }
  ],
  "ObjectId": "Company_11111111-1111-1111-1111-111111111111",
  "Operation": "Update company settings",
  "Operations": "Update company settings",
  "OrganizationId": "11111111-1111-1111-1111-111111111111",
  "RecordType": "AzureActiveDirectory",
  "ResultStatus": "Success",
  "Target": [
    {
      "ID": "Company_11111111-1111-1111-1111-111111111111",
      "Type": 2
    },
    {
      "ID": "11111111-1111-1111-1111-111111111111",
      "Type": 2
    },
    {
      "ID": "Directory",
      "Type": 2
    },
    {
      "ID": "NCT",
      "Type": 1
    }
  ],
  "TargetContextId": "11111111-1111-1111-1111-111111111111",
  "UserId": "adminuser@example.onmicrosoft.com",
  "UserKey": "1111111111111111@example.onmicrosoft.com",
  "UserType": "Regular",
  "Version": 1,
  "Workload": "AzureActiveDirectory"
}

References #

Update device.

#
RecordType
AzureActiveDirectory

Description

Update device. activity in Microsoft Entra ID, recorded in the Unified Audit Log (observed in first-party capture).

Example Audit Record #

{
  "Actor": [
    {
      "ID": "Device Registration Service",
      "Type": 1
    },
    {
      "ID": "01cb2876-7ebd-4aa4-9cc9-d28bd4d359a9",
      "Type": 2
    },
    {
      "ID": "ServicePrincipal_9611bdea-8105-4fd4-9a4a-14f1681a57cf",
      "Type": 2
    },
    {
      "ID": "9611bdea-8105-4fd4-9a4a-14f1681a57cf",
      "Type": 2
    },
    {
      "ID": "ServicePrincipal",
      "Type": 2
    },
    {
      "ID": "NotAgentic",
      "Type": 2
    }
  ],
  "ActorContextId": "11111111-1111-1111-1111-111111111111",
  "AzureActiveDirectoryEventType": 1,
  "CreationDate": "2026-07-03T05:46:30",
  "CreationTime": "2026-07-03T05:46:30",
  "ExtendedProperties": [
    {
      "Name": "additionalDetails",
      "Value": {
        "DeviceId": "ef01b99d-7f4f-4ca5-a03c-956e8fa7f2a1",
        "DeviceOSType": "Windows",
        "DeviceTrustType": "Workplace"
      }
    },
    {
      "Name": "extendedAuditEventCategory",
      "Value": "Device"
    }
  ],
  "Id": "ca3630e8-446e-439a-977c-5840388b4fb9",
  "InterSystemsId": "c27ab2f6-16e5-44c6-adf3-b62869e29055",
  "IntraSystemId": "00000000-0000-0000-0000-000000000000",
  "ModifiedProperties": [
    {
      "Name": "Included Updated Properties",
      "NewValue": "",
      "OldValue": ""
    },
    {
      "Name": "TargetId.DeviceId",
      "NewValue": "ef01b99d-7f4f-4ca5-a03c-956e8fa7f2a1",
      "OldValue": ""
    },
    {
      "Name": "TargetId.DeviceOSType",
      "NewValue": "Windows",
      "OldValue": ""
    },
    {
      "Name": "TargetId.DeviceTrustType",
      "NewValue": "Workplace",
      "OldValue": ""
    }
  ],
  "ObjectId": "Device_9b9ec43f-cf91-456d-85cf-7d2c5ee3b666",
  "Operation": "Update device.",
  "Operations": "Update device.",
  "OrganizationId": "11111111-1111-1111-1111-111111111111",
  "RecordType": "AzureActiveDirectory",
  "ResultStatus": "Success",
  "Target": [
    {
      "ID": "Device_9b9ec43f-cf91-456d-85cf-7d2c5ee3b666",
      "Type": 2
    },
    {
      "ID": "9b9ec43f-cf91-456d-85cf-7d2c5ee3b666",
      "Type": 2
    },
    {
      "ID": "Device",
      "Type": 2
    },
    {
      "ID": "JD-DC01-2022",
      "Type": 1
    }
  ],
  "TargetContextId": "11111111-1111-1111-1111-111111111111",
  "UserId": "ServicePrincipal_9611bdea-8105-4fd4-9a4a-14f1681a57cf",
  "UserKey": "Not Available",
  "UserType": "System",
  "Version": 1,
  "Workload": "AzureActiveDirectory"
}

References #

Update group.

#
RecordType
AzureActiveDirectory

Description

Update group. activity in Microsoft Entra ID, recorded in the Unified Audit Log (observed in first-party capture).

Example Audit Record #

{
  "Actor": [
    {
      "ID": "adminuser@example.onmicrosoft.com",
      "Type": 5
    },
    {
      "ID": "10000000AAAAAAAA",
      "Type": 3
    },
    {
      "ID": "Groups Service",
      "Type": 1
    },
    {
      "ID": "86b4b4b4-db10-481c-876b-07447e7f204f",
      "Type": 2
    },
    {
      "ID": "User_11111111-1111-1111-1111-111111111111",
      "Type": 2
    },
    {
      "ID": "11111111-1111-1111-1111-111111111111",
      "Type": 2
    },
    {
      "ID": "User",
      "Type": 2
    },
    {
      "ID": "NotAgentic",
      "Type": 2
    }
  ],
  "ActorContextId": "00000000-0000-0000-0000-000000000001",
  "AzureActiveDirectoryEventType": 1,
  "CreationTime": "2026-07-02T02:10:29Z",
  "ExtendedProperties": [
    {
      "Name": "additionalDetails",
      "Value": {
        "GroupType": "Unified"
      }
    },
    {
      "Name": "extendedAuditEventCategory",
      "Value": "Group"
    }
  ],
  "Id": "24583057-7f57-4802-8d63-3225b7c0f2d4",
  "InterSystemsId": "05cc70aa-f45d-431e-922d-80f284086ca6",
  "IntraSystemId": "00000000-0000-0000-0000-000000000000",
  "ModifiedProperties": [
    {
      "Name": "Included Updated Properties"
    },
    {
      "Name": "MethodExecutionResult.",
      "NewValue": "Microsoft.Online.Workflows.ObjectNotFoundException"
    },
    {
      "Name": "TargetId.GroupType",
      "NewValue": "Unified"
    }
  ],
  "ObjectId": "Group_ca5d50d9-83af-43d6-8a3a-4f3c00590bec",
  "Operation": "Update group.",
  "OrganizationId": "00000000-0000-0000-0000-000000000001",
  "RecordType": 8,
  "ResultStatus": "Failure",
  "Target": [
    {
      "ID": "Group_ca5d50d9-83af-43d6-8a3a-4f3c00590bec",
      "Type": 2
    },
    {
      "ID": "ca5d50d9-83af-43d6-8a3a-4f3c00590bec",
      "Type": 2
    },
    {
      "ID": "Group",
      "Type": 2
    },
    {
      "ID": "dw-harness-60974bd7",
      "Type": 1
    }
  ],
  "TargetContextId": "00000000-0000-0000-0000-000000000001",
  "UserId": "adminuser@example.onmicrosoft.com",
  "UserKey": "10000000AAAAAAAA@example.onmicrosoft.com",
  "UserType": 0,
  "Version": 1,
  "Workload": "AzureActiveDirectory"
}

References #

Update PasswordProfile.

#
RecordType
AzureActiveDirectory

Description

Update Password Profile. activity in Microsoft Entra ID, recorded in the Unified Audit Log (observed in first-party capture).

Example Audit Record #

{
  "Actor": [
    {
      "ID": "adminuser@example.onmicrosoft.com",
      "Type": 5
    },
    {
      "ID": "10000000AAAAAAAA",
      "Type": 3
    },
    {
      "ID": "User_11111111-1111-1111-1111-111111111111",
      "Type": 2
    },
    {
      "ID": "11111111-1111-1111-1111-111111111111",
      "Type": 2
    },
    {
      "ID": "User",
      "Type": 2
    },
    {
      "ID": "NotAgentic",
      "Type": 2
    }
  ],
  "ActorContextId": "00000000-0000-0000-0000-000000000001",
  "AzureActiveDirectoryEventType": 1,
  "CreationTime": "2026-07-02T15:29:58Z",
  "ExtendedProperties": [
    {
      "Name": "additionalDetails",
      "Value": {
        "User-Agent": "python/3.13.9 (Linux-6.1.0-41-amd64-x86_64-with-glibc2.36) AZURECLI/2.82.0 (DEB)"
      }
    },
    {
      "Name": "extendedAuditEventCategory",
      "Value": "User"
    }
  ],
  "Id": "6ba071d4-2868-45cc-8288-f5ba26662d30",
  "InterSystemsId": "884ecd76-2d50-48e7-b8de-af4fb379eaf9",
  "IntraSystemId": "9c60102e-f8d1-40d4-b9ee-f9cd71600ece",
  "ModifiedProperties": [
    {
      "Name": "Password"
    }
  ],
  "ObjectId": "dwtestuser@example.onmicrosoft.com",
  "Operation": "Update PasswordProfile.",
  "OrganizationId": "00000000-0000-0000-0000-000000000001",
  "RecordType": 8,
  "ResultStatus": "Success",
  "Target": [
    {
      "ID": "User_6b8aef40-5bf4-449f-8164-c2ae9affa2df",
      "Type": 2
    },
    {
      "ID": "6b8aef40-5bf4-449f-8164-c2ae9affa2df",
      "Type": 2
    },
    {
      "ID": "User",
      "Type": 2
    },
    {
      "ID": "NotAgentic",
      "Type": 2
    },
    {
      "ID": "dwtestuser@example.onmicrosoft.com",
      "Type": 5
    },
    {
      "ID": "10032006100D3C25",
      "Type": 3
    }
  ],
  "TargetContextId": "00000000-0000-0000-0000-000000000001",
  "UserId": "adminuser@example.onmicrosoft.com",
  "UserKey": "10000000AAAAAAAA@example.onmicrosoft.com",
  "UserType": 0,
  "Version": 1,
  "Workload": "AzureActiveDirectory"
}

References #

Update policy.

#
RecordType
AzureActiveDirectory

Description

Microsoft Entra ID (Azure Active Directory) audit activity in the Policy category, recorded in the Office 365 Unified Audit Log.

Example Audit Record #

{
  "Actor": [
    {
      "ID": "adminuser@example.onmicrosoft.com",
      "Type": 5
    },
    {
      "ID": 1111111111111111,
      "Type": 3
    },
    {
      "ID": "User_11111111-1111-1111-1111-111111111111",
      "Type": 2
    },
    {
      "ID": "11111111-1111-1111-1111-111111111111",
      "Type": 2
    },
    {
      "ID": "User",
      "Type": 2
    },
    {
      "ID": "NotAgentic",
      "Type": 2
    }
  ],
  "ActorContextId": "00000000-0000-0000-0000-000000000001",
  "AzureActiveDirectoryEventType": 1,
  "CreationTime": "2026-07-03T03:22:44Z",
  "ExtendedProperties": [
    {
      "Name": "additionalDetails",
      "Value": {}
    },
    {
      "Name": "extendedAuditEventCategory",
      "Value": "Policy"
    }
  ],
  "Id": "a08bf4fb-ca71-4654-8b7c-a867aa8086fc",
  "InterSystemsId": "6b2594ae-7def-4bf0-8a34-f5b48b22cbf4",
  "IntraSystemId": "c4aa92a3-ce9f-41bd-a57a-16bcad716c99",
  "ModifiedProperties": [
    {
      "Name": "Included Updated Properties",
      "NewValue": "",
      "OldValue": ""
    }
  ],
  "ObjectId": "Policy_ad962b47-fdc9-48fe-8178-52f5a356ad51",
  "Operation": "Update policy.",
  "OrganizationId": "00000000-0000-0000-0000-000000000001",
  "RecordType": 8,
  "ResultStatus": "Success",
  "Target": [
    {
      "ID": "Policy_ad962b47-fdc9-48fe-8178-52f5a356ad51",
      "Type": 2
    },
    {
      "ID": "ad962b47-fdc9-48fe-8178-52f5a356ad51",
      "Type": 2
    },
    {
      "ID": "Policy",
      "Type": 2
    },
    {
      "ID": "Default Policy",
      "Type": 1
    }
  ],
  "TargetContextId": "00000000-0000-0000-0000-000000000001",
  "UserId": "adminuser@example.onmicrosoft.com",
  "UserKey": "1111111111111111@example.onmicrosoft.com",
  "UserType": 0,
  "Version": 1,
  "Workload": "AzureActiveDirectory"
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Splunk #

  • O365 External Identity Policy Changed source: The following analytic identifies when changes are made to the external guest policies within Azure AD. With Azure AD B2B collaboration, users and administrators can invite external users to collaborate with internal users. This detection…T1136, T1136.003

YARA-L #

References #

Update role definition.

#
RecordType
AzureActiveDirectory

Description

Update role definition. activity in Microsoft Entra ID, recorded in the Unified Audit Log (observed in first-party capture).

Example Audit Record #

{
  "Actor": [
    {
      "ID": "adminuser@example.onmicrosoft.com",
      "Type": 5
    },
    {
      "ID": 1111111111111111,
      "Type": 3
    },
    {
      "ID": "User_aaaaaaaa-0000-0000-0000-000000000001",
      "Type": 2
    },
    {
      "ID": "aaaaaaaa-0000-0000-0000-000000000001",
      "Type": 2
    },
    {
      "ID": "User",
      "Type": 2
    },
    {
      "ID": "NotAgentic",
      "Type": 2
    }
  ],
  "ActorContextId": "11111111-1111-1111-1111-111111111111",
  "AzureActiveDirectoryEventType": 1,
  "CreationDate": "2026-07-03T03:22:48",
  "CreationTime": "2026-07-03T03:22:48",
  "ExtendedProperties": [
    {
      "Name": "additionalDetails",
      "Value": {
        "User-Agent": "python/3.13.9 (Linux-6.1.0-41-amd64-x86_64-with-glibc2.36) AZURECLI/2.82.0 (DEB)"
      }
    },
    {
      "Name": "extendedAuditEventCategory",
      "Value": "RoleDefinition"
    }
  ],
  "Id": "f7bab2dc-d2d9-400c-9011-1a8f0b8d27cb",
  "InterSystemsId": "78b47f4b-0cc1-4586-a9fc-8851f81c6692",
  "IntraSystemId": "3520a8f7-7840-406e-a6a3-ac991aed68b6",
  "ModifiedProperties": [
    {
      "Name": "Included Updated Properties",
      "NewValue": "",
      "OldValue": ""
    }
  ],
  "ObjectId": "RoleDefinition_799abf44-b19b-4605-9606-2125d16ff1c8",
  "Operation": "Update role definition.",
  "Operations": "Update role definition.",
  "OrganizationId": "11111111-1111-1111-1111-111111111111",
  "RecordType": "AzureActiveDirectory",
  "ResultStatus": "Success",
  "Target": [
    {
      "ID": "RoleDefinition_799abf44-b19b-4605-9606-2125d16ff1c8",
      "Type": 2
    },
    {
      "ID": "799abf44-b19b-4605-9606-2125d16ff1c8",
      "Type": 2
    },
    {
      "ID": "Other",
      "Type": 2
    },
    {
      "ID": "dw-harness-role-2fe5ab51",
      "Type": 1
    }
  ],
  "TargetContextId": "11111111-1111-1111-1111-111111111111",
  "UserId": "adminuser@example.onmicrosoft.com",
  "UserKey": "1111111111111111@example.onmicrosoft.com",
  "UserType": "Regular",
  "Version": 1,
  "Workload": "AzureActiveDirectory"
}

References #

Update role.

#
RecordType
AzureActiveDirectory

Description

Update role. activity in Microsoft Entra ID, recorded in the Unified Audit Log (observed in first-party capture).

Example Audit Record #

{
  "Actor": [
    {
      "ID": "adminuser@example.onmicrosoft.com",
      "Type": 5
    },
    {
      "ID": 1111111111111111,
      "Type": 3
    },
    {
      "ID": "User_aaaaaaaa-0000-0000-0000-000000000001",
      "Type": 2
    },
    {
      "ID": "aaaaaaaa-0000-0000-0000-000000000001",
      "Type": 2
    },
    {
      "ID": "User",
      "Type": 2
    },
    {
      "ID": "NotAgentic",
      "Type": 2
    }
  ],
  "ActorContextId": "11111111-1111-1111-1111-111111111111",
  "AzureActiveDirectoryEventType": 1,
  "CreationDate": "2026-07-03T03:22:33",
  "CreationTime": "2026-07-03T03:22:33",
  "ExtendedProperties": [
    {
      "Name": "additionalDetails",
      "Value": {
        "User-Agent": "python/3.13.9 (Linux-6.1.0-41-amd64-x86_64-with-glibc2.36) AZURECLI/2.82.0 (DEB)"
      }
    },
    {
      "Name": "extendedAuditEventCategory",
      "Value": "Role"
    }
  ],
  "Id": "1f9fd9ea-556f-4b4d-a730-1eb56a015ca9",
  "InterSystemsId": "c0a4e8d4-d41f-4bbc-ad88-25f2181ee7ee",
  "IntraSystemId": "00000000-0000-0000-0000-000000000000",
  "ModifiedProperties": [
    {
      "Name": "Included Updated Properties",
      "NewValue": "",
      "OldValue": ""
    },
    {
      "Name": "TargetId.RoleTemplateId",
      "NewValue": "a0b1b346-4d3e-4e8b-98f8-753987be4970",
      "OldValue": ""
    },
    {
      "Name": "TargetId.RoleWellKnownObjectName",
      "NewValue": "Users",
      "OldValue": ""
    }
  ],
  "ObjectId": "Role_d0d8ab1f-38e0-4911-96ba-2a01f139862b",
  "Operation": "Update role.",
  "Operations": "Update role.",
  "OrganizationId": "11111111-1111-1111-1111-111111111111",
  "RecordType": "AzureActiveDirectory",
  "ResultStatus": "Success",
  "Target": [
    {
      "ID": "Role_d0d8ab1f-38e0-4911-96ba-2a01f139862b",
      "Type": 2
    },
    {
      "ID": "d0d8ab1f-38e0-4911-96ba-2a01f139862b",
      "Type": 2
    },
    {
      "ID": "Role",
      "Type": 2
    },
    {
      "ID": "User",
      "Type": 1
    },
    {
      "ID": "a0b1b346-4d3e-4e8b-98f8-753987be4970",
      "Type": 2
    },
    {
      "ID": "Users",
      "Type": 2
    }
  ],
  "TargetContextId": "11111111-1111-1111-1111-111111111111",
  "UserId": "adminuser@example.onmicrosoft.com",
  "UserKey": "1111111111111111@example.onmicrosoft.com",
  "UserType": "Regular",
  "Version": 1,
  "Workload": "AzureActiveDirectory"
}

References #

Update service principal.

#
RecordType
AzureActiveDirectory

Description

A service principal object was modified (properties, credentials, or tags).

Example Audit Record #

{
  "Actor": [
    {
      "ID": "adminuser@example.onmicrosoft.com",
      "Type": 5
    },
    {
      "ID": 1111111111111111,
      "Type": 3
    },
    {
      "ID": "User_11111111-1111-1111-1111-111111111111",
      "Type": 2
    },
    {
      "ID": "11111111-1111-1111-1111-111111111111",
      "Type": 2
    },
    {
      "ID": "User",
      "Type": 2
    },
    {
      "ID": "NotAgentic",
      "Type": 2
    }
  ],
  "ActorContextId": "00000000-0000-0000-0000-000000000001",
  "AzureActiveDirectoryEventType": 1,
  "CreationTime": "2026-07-03T05:27:27Z",
  "ExtendedProperties": [
    {
      "Name": "additionalDetails",
      "Value": {
        "User-Agent": "python/3.13.9 (Linux-6.1.0-41-amd64-x86_64-with-glibc2.36) AZURECLI/2.82.0 (DEB)",
        "AppId": "22222222-2222-2222-2222-222222222222",
        "AppOwnerOrganizationId": "00000000-0000-0000-0000-000000000001",
        "ServicePrincipalProvisioningType": "Other"
      }
    },
    {
      "Name": "extendedAuditEventCategory",
      "Value": "ServicePrincipal"
    }
  ],
  "Id": "fe73a39b-cd76-40bf-bbda-43d3323a9c1f",
  "InterSystemsId": "434c435d-00fe-4b82-a00c-ea865443dc62",
  "IntraSystemId": "00000000-0000-0000-0000-000000000000",
  "ModifiedProperties": [
    {
      "Name": "Included Updated Properties",
      "NewValue": "",
      "OldValue": ""
    }
  ],
  "ObjectId": "22222222-2222-2222-2222-222222222222",
  "Operation": "Update service principal.",
  "OrganizationId": "00000000-0000-0000-0000-000000000001",
  "RecordType": 8,
  "ResultStatus": "Success",
  "Target": [
    {
      "ID": "ServicePrincipal_af2cee02-3ad4-4486-85a2-e8eafc78cd6e",
      "Type": 2
    },
    {
      "ID": "af2cee02-3ad4-4486-85a2-e8eafc78cd6e",
      "Type": 2
    },
    {
      "ID": "ServicePrincipal",
      "Type": 2
    },
    {
      "ID": "NotAgentic",
      "Type": 2
    },
    {
      "ID": "dw-activity-gen",
      "Type": 1
    },
    {
      "ID": "22222222-2222-2222-2222-222222222222",
      "Type": 2
    },
    {
      "ID": "22222222-2222-2222-2222-222222222222",
      "Type": 4
    },
    {
      "ID": "00000000-0000-0000-0000-000000000001",
      "Type": 2
    },
    {
      "ID": "Other",
      "Type": 2
    }
  ],
  "TargetContextId": "00000000-0000-0000-0000-000000000001",
  "UserId": "adminuser@example.onmicrosoft.com",
  "UserKey": "1111111111111111@example.onmicrosoft.com",
  "UserType": 0,
  "Version": 1,
  "Workload": "AzureActiveDirectory"
}

References #

Update StsRefreshTokenValidFrom Timestamp.

#
RecordType
AzureActiveDirectory

Description

A user's refresh tokens were invalidated (revoke sessions); also set silently by some attacks.

Example Audit Record #

{
  "Actor": [
    {
      "ID": "adminuser@example.onmicrosoft.com",
      "Type": 5
    },
    {
      "ID": 1111111111111111,
      "Type": 3
    },
    {
      "ID": "User_11111111-1111-1111-1111-111111111111",
      "Type": 2
    },
    {
      "ID": "11111111-1111-1111-1111-111111111111",
      "Type": 2
    },
    {
      "ID": "User",
      "Type": 2
    },
    {
      "ID": "NotAgentic",
      "Type": 2
    }
  ],
  "ActorContextId": "00000000-0000-0000-0000-000000000001",
  "AzureActiveDirectoryEventType": 1,
  "CreationTime": "2026-07-03T03:22:05Z",
  "ExtendedProperties": [
    {
      "Name": "additionalDetails",
      "Value": {
        "User-Agent": "python/3.13.9 (Linux-6.1.0-41-amd64-x86_64-with-glibc2.36) AZURECLI/2.82.0 (DEB)"
      }
    },
    {
      "Name": "extendedAuditEventCategory",
      "Value": "User"
    }
  ],
  "Id": "f88fba2a-c324-4549-940a-3928db20821b",
  "InterSystemsId": "04ff1d88-7781-44a8-8f2e-d3246297f07c",
  "IntraSystemId": "3a161d99-ddfb-4961-be6c-f56c153f613f",
  "ObjectId": "dwharn-2fe5ab51@example.onmicrosoft.com",
  "Operation": "Update StsRefreshTokenValidFrom Timestamp.",
  "OrganizationId": "00000000-0000-0000-0000-000000000001",
  "RecordType": 8,
  "ResultStatus": "Success",
  "Target": [
    {
      "ID": "User_cb2e74f0-ecab-4632-8779-2523b77641f4",
      "Type": 2
    },
    {
      "ID": "cb2e74f0-ecab-4632-8779-2523b77641f4",
      "Type": 2
    },
    {
      "ID": "User",
      "Type": 2
    },
    {
      "ID": "NotAgentic",
      "Type": 2
    },
    {
      "ID": "dwharn-2fe5ab51@example.onmicrosoft.com",
      "Type": 5
    },
    {
      "ID": "1003200610B1FC81",
      "Type": 3
    }
  ],
  "TargetContextId": "00000000-0000-0000-0000-000000000001",
  "UserId": "adminuser@example.onmicrosoft.com",
  "UserKey": "1111111111111111@example.onmicrosoft.com",
  "UserType": 0,
  "Version": 1,
  "Workload": "AzureActiveDirectory"
}

References #

Update user.

#
RecordType
AzureActiveDirectory

Description

Microsoft Entra ID (Azure Active Directory) audit activity in the UserManagement category, recorded in the Office 365 Unified Audit Log.

Example Audit Record #

{
  "Actor": [
    {
      "ID": "Microsoft Substrate Management",
      "Type": 1
    },
    {
      "ID": "98db8bd6-0cc0-4e67-9de5-f187f1cd1b41",
      "Type": 2
    },
    {
      "ID": "ServicePrincipal_414635d2-0108-489f-8a72-0a53de565cf9",
      "Type": 2
    },
    {
      "ID": "414635d2-0108-489f-8a72-0a53de565cf9",
      "Type": 2
    },
    {
      "ID": "ServicePrincipal",
      "Type": 2
    },
    {
      "ID": "NotAgentic",
      "Type": 2
    }
  ],
  "ActorContextId": "00000000-0000-0000-0000-000000000001",
  "AzureActiveDirectoryEventType": 1,
  "CreationTime": "2026-07-02T15:39:15Z",
  "ExtendedProperties": [
    {
      "Name": "additionalDetails",
      "Value": {
        "UserType": "Member"
      }
    },
    {
      "Name": "extendedAuditEventCategory",
      "Value": "User"
    }
  ],
  "Id": "38596428-ed2a-4227-90a4-c6c6e2eb4f2f",
  "InterSystemsId": "3dbe0d9b-837d-4569-8aa8-632d86c2eac3",
  "IntraSystemId": "8b32b9b0-9dc1-4580-9de6-1d8996e9dcba",
  "ModifiedProperties": [
    {
      "Name": "ProxyAddresses",
      "NewValue": [
        "SMTP:ExRemoved-be5e8f8fcdbc486d907c247a75839e1c@example.onmicrosoft.com",
        "smtp:dwshared2@example.onmicrosoft.com"
      ],
      "OldValue": [
        "SMTP:dwshared2@example.onmicrosoft.com"
      ]
    },
    {
      "Name": "UserPrincipalName",
      "NewValue": [
        "ExRemoved-be5e8f8fcdbc486d907c247a75839e1c@example.onmicrosoft.com"
      ],
      "OldValue": [
        "dwshared2@example.onmicrosoft.com"
      ]
    },
    {
      "Name": "Included Updated Properties",
      "NewValue": "ProxyAddresses, UserPrincipalName",
      "OldValue": ""
    },
    {
      "Name": "TargetId.UserType",
      "NewValue": "Member",
      "OldValue": ""
    }
  ],
  "ObjectId": "ExRemoved-be5e8f8fcdbc486d907c247a75839e1c@example.onmicrosoft.com",
  "Operation": "Update user.",
  "OrganizationId": "00000000-0000-0000-0000-000000000001",
  "RecordType": 8,
  "ResultStatus": "Success",
  "Target": [
    {
      "ID": "User_60d98188-8dac-4658-b257-8094fa03147e",
      "Type": 2
    },
    {
      "ID": "60d98188-8dac-4658-b257-8094fa03147e",
      "Type": 2
    },
    {
      "ID": "User",
      "Type": 2
    },
    {
      "ID": "NotAgentic",
      "Type": 2
    },
    {
      "ID": "ExRemoved-be5e8f8fcdbc486d907c247a75839e1c@example.onmicrosoft.com",
      "Type": 5
    },
    {
      "ID": "100320060FE65D06",
      "Type": 3
    }
  ],
  "TargetContextId": "00000000-0000-0000-0000-000000000001",
  "UserId": "ServicePrincipal_414635d2-0108-489f-8a72-0a53de565cf9",
  "UserKey": "Not Available",
  "UserType": 4,
  "Version": 1,
  "Workload": "AzureActiveDirectory"
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Splunk #

  • O365 New MFA Method Registered source: The following analytic detects the registration of a new Multi-Factor Authentication (MFA) method for a user account within Office 365. It leverages O365 audit logs to identify changes in MFA configurations. This activity is significant as…T1098, T1098.005

Panther #

References #

M365 audit records use different field names on each surface #

The same Unified Audit Log record uses different field names on each surface. A query built for one surface can silently miss on another. These pages document the Management Activity API JSON names, the same names Search-UnifiedAuditLog and the Office 365 Management Activity API return.

  • Purview CSV export flattens each record to four columns (CreationDate, UserIds, Operations, AuditData). The API field names live only inside the AuditData JSON blob. Expand it with ConvertFrom-Json. The wrapper columns are renamed too: CreationDate not CreationTime, UserIds not UserId, Operations not Operation.
  • Sentinel's OfficeActivity table renames several fields and turns two integer enum columns into strings. The table below maps them.
API JSON (event pages)OfficeActivity columnNote
IdOfficeIdRenamed.
WorkloadOfficeWorkloadRenamed.
ObjectIdOfficeObjectIdRenamed.
CreationTimeTimeGeneratedRenamed. OfficeActivity has no CreationTime column.
SiteUrlSite_UrlRenamed (SharePoint family).
RecordTypeRecordTypeSame name; the Int32 enum becomes its string enum name.
UserTypeUserTypeSame name; the Int32 enum becomes a string.
ClientIPClientIP, Client_IPAddressBoth columns present on OfficeActivity.
Scope(none)No OfficeActivity equivalent under any name. Recover it from the API JSON or the Purview AuditData blob.
Operation, UserId, ResultStatus, UserKey, AppAccessContext, OrganizationIdsame namesUnchanged. No _s / _d suffixes (a native table, not a custom log).

Mapping verified against the OfficeActivity table reference, the Management Activity API schema, and the Purview audit-record export format.