Azure Active Directory / Entra ID events
| Operation | Description | Sample | Rule |
|---|---|---|---|
| any | Catch-all for M365-AzureActiveDirectory rules matching the RecordType but no specific Operation. | N | Y |
| Add a partner to cross-tenant access setting. | Microsoft Entra ID (Azure Active Directory) audit activity in the CrossTenantAccessSettings category, recorded in the Office 365 Unified Audit Log. | Y | Y |
| Add administrative unit. | Add administrative unit. activity in Microsoft Entra ID, recorded in the Unified Audit Log (observed in first-party capture). | Y | N |
| Add app role assignment grant to user. | An app role assignment was granted to a user in Microsoft Entra ID (an enterprise application role assigned to a user account). A directory operation, so it carries RecordType AzureActiveDirectory (8) like its documented siblings (Add/Remove app role assignment to service principal / from user). | Y | Y |
| Add app role assignment to service principal. | Microsoft Entra ID (Azure Active Directory) audit activity in the ApplicationManagement category, recorded in the Office 365 Unified Audit Log. | Y | Y |
| Add application. | An application registration was created in Azure Active Directory (the UAL operation string includes a trailing period). | Y | Y |
| Add delegated permission grant. | An OAuth2 delegated permission grant was created for an application. | Y | Y |
| Add eligible member to role. | Microsoft Entra ID (Azure Active Directory) audit activity in the RoleManagement category, recorded in the Office 365 Unified Audit Log. | N | Y |
| Add group. | A group was created in Azure Active Directory (the UAL operation string includes a trailing period). | Y | Y |
| Add label. | Add label. activity in Microsoft Entra ID, recorded in the Unified Audit Log (observed in first-party capture). | Y | N |
| Add member to administrative unit. | Add member to administrative unit. activity in Microsoft Entra ID, recorded in the Unified Audit Log (observed in first-party capture). | Y | N |
| Add member to group. | A principal was added to a group in Azure Active Directory (the UAL operation string includes a trailing period). | Y | Y |
| Add member to role. | A principal was added to an Azure Active Directory directory role (the UAL operation string includes a trailing period). | Y | Y |
| Add owner to application. | Microsoft Entra ID (Azure Active Directory) audit activity in the ApplicationManagement category, recorded in the Office 365 Unified Audit Log. | Y | Y |
| Add owner to group. | An owner was added to a group. | Y | N |
| Add permission grant policy. | Add permission grant policy. activity in Microsoft Entra ID, recorded in the Unified Audit Log (observed in first-party capture). | Y | N |
| Add policy. | A directory policy object was created. | Y | N |
| Add registered users to device. | Registered users were added to a device object in Azure Active Directory (the UAL operation string includes a trailing period). | N | Y |
| Add role definition. | Add role definition. activity in Microsoft Entra ID, recorded in the Unified Audit Log (observed in first-party capture). | Y | N |
| Add service principal credentials. | Credentials were added to a service principal (common persistence technique). | Y | N |
| Add service principal. | Microsoft Entra ID (Azure Active Directory) audit activity in the ApplicationManagement category, recorded in the Office 365 Unified Audit Log. | Y | Y |
| Add unverified domain. | An unverified custom domain was added to the tenant. | Y | N |
| Add user. | A new user account was created in the directory. | Y | Y |
| Change user license. | Microsoft Entra ID (Azure Active Directory) audit activity in the UserManagement category, recorded in the Office 365 Unified Audit Log. | Y | Y |
| Change user password. | A user changed their own password. | Y | N |
| Consent to application. | Admin or user consent was granted to an application in Azure Active Directory (the UAL operation string includes a trailing period). | Y | Y |
| Create application password for user. | An app password was created for a user, letting a legacy client sign in without completing MFA. | Y | N |
| Create application – Certificates and secrets management | Create application – Certificates and secrets management activity in Microsoft Entra ID, recorded in the Unified Audit Log (observed in first-party capture). | Y | N |
| Create company settings | Create company settings activity in Microsoft Entra ID, recorded in the Unified Audit Log (observed in first-party capture). | Y | N |
| Delete administrative unit. | Delete administrative unit. activity in Microsoft Entra ID, recorded in the Unified Audit Log (observed in first-party capture). | Y | N |
| Delete application password for user. | An app-password credential was deleted for a user, revoking a legacy non-MFA sign-in credential. | Y | N |
| Delete application. | An application registration was deleted. | Y | N |
| Delete company settings | Delete company settings activity in Microsoft Entra ID, recorded in the Unified Audit Log (observed in first-party capture). | Y | N |
| Delete group. | A group was deleted in Azure Active Directory (the UAL operation string includes a trailing period). | Y | Y |
| Delete label. | Delete label. activity in Microsoft Entra ID, recorded in the Unified Audit Log (observed in first-party capture). | Y | N |
| Delete partner specific cross-tenant access setting. | Microsoft Entra ID (Azure Active Directory) audit activity in the CrossTenantAccessSettings category, recorded in the Office 365 Unified Audit Log. | Y | Y |
| Delete permission grant policy. | Delete permission grant policy. activity in Microsoft Entra ID, recorded in the Unified Audit Log (observed in first-party capture). | Y | N |
| Delete policy. | Delete policy. activity in Microsoft Entra ID, recorded in the Unified Audit Log (observed in first-party capture). | Y | N |
| Delete role definition. | Delete role definition. activity in Microsoft Entra ID, recorded in the Unified Audit Log (observed in first-party capture). | Y | N |
| Delete user. | A user account was deleted. | Y | N |
| Disable Strong Authentication. | Microsoft Entra ID (Azure Active Directory) audit activity in the UserManagement category, recorded in the Office 365 Unified Audit Log. | Y | Y |
| Enable Strong Authentication. | Records strong authentication (multifactor authentication) being enabled for a directory user. | Y | N |
| Remove app role assignment from service principal. | An app role assignment was removed from a service principal, revoking an application's granted app role. | Y | N |
| Remove delegated permission grant. | An OAuth2 delegated permission grant was deleted, revoking the delegated API permissions granted to an application. | Y | N |
| Remove member from administrative unit. | Remove member from administrative unit. activity in Microsoft Entra ID, recorded in the Unified Audit Log (observed in first-party capture). | Y | N |
| Remove member from group. | A principal was removed from a group in Azure Active Directory (the UAL operation string includes a trailing period). | Y | Y |
| Remove member from role. | A principal was removed from a directory role. | Y | N |
| Remove service principal. | A service principal was removed. | Y | N |
| Reset user password. | An administrator reset a user's password. | Y | N |
| Set Company Information. | Microsoft Entra ID (Azure Active Directory) audit activity in the DirectoryManagement category, recorded in the Office 365 Unified Audit Log. | Y | Y |
| Set-Msol | Federation settings for a domain were changed via the MSOnline module (a directory operation, not an Exchange cmdlet); abused to add a backdoor federation trust. | N | Y |
| Update administrative unit. | Update administrative unit. activity in Microsoft Entra ID, recorded in the Unified Audit Log (observed in first-party capture). | Y | N |
| Update application – Certificates and secrets management | Update application – Certificates and secrets management activity in Microsoft Entra ID, recorded in the Unified Audit Log (observed in first-party capture). | Y | Y |
| Update application. | An application registration was modified in Azure Active Directory (the UAL operation string includes a trailing period). | Y | Y |
| Update authorization policy. | Microsoft Entra ID (Azure Active Directory) audit activity in the AuthorizationPolicy category, recorded in the Office 365 Unified Audit Log. | Y | Y |
| Update company settings | Update company settings activity in Microsoft Entra ID, recorded in the Unified Audit Log (observed in first-party capture). | Y | N |
| Update device. | Update device. activity in Microsoft Entra ID, recorded in the Unified Audit Log (observed in first-party capture). | Y | N |
| Update group. | Update group. activity in Microsoft Entra ID, recorded in the Unified Audit Log (observed in first-party capture). | Y | N |
| Update Password | Update Password Profile. activity in Microsoft Entra ID, recorded in the Unified Audit Log (observed in first-party capture). | Y | N |
| Update policy. | Microsoft Entra ID (Azure Active Directory) audit activity in the Policy category, recorded in the Office 365 Unified Audit Log. | Y | Y |
| Update role definition. | Update role definition. activity in Microsoft Entra ID, recorded in the Unified Audit Log (observed in first-party capture). | Y | N |
| Update role. | Update role. activity in Microsoft Entra ID, recorded in the Unified Audit Log (observed in first-party capture). | Y | N |
| Update service principal. | A service principal object was modified (properties, credentials, or tags). | Y | N |
| Update Sts | A user's refresh tokens were invalidated (revoke sessions); also set silently by some attacks. | Y | N |
| Update user. | Microsoft Entra ID (Azure Active Directory) audit activity in the UserManagement category, recorded in the Office 365 Unified Audit Log. | Y | Y |
any: Azure Active Directory / Entra ID events (catch-all)
#Description
Catch-all for M365-AzureActiveDirectory rules matching the RecordType but no specific Operation.
Common Indicators #
Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.
| Field | Kind | Value | Rules | Vendors |
|---|---|---|---|---|
action (splunk rule field) | eq | created | 1 rule | splunk |
csUserAgent (kusto rule field) | is_not_null | | 1 rule | kusto |
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Splunk #
o365_management_activity dataset, specifically monitoring for operations related to adding or creating service…T1136, T1136.003Kusto #
T1071, T1189, T1203
References #
Add a partner to cross-tenant access setting.
#Description
Microsoft Entra ID (Azure Active Directory) audit activity in the CrossTenantAccessSettings category, recorded in the Office 365 Unified Audit Log.
Example Audit Record #
{
"Actor": [
{
"ID": "Malicious Service Principal",
"Type": 1
},
{
"ID": "b39d63e7-7fa3-4b2b-94ea-ee256fdb8c2f",
"Type": 2
},
{
"ID": "ServicePrincipal_ff45cda2-75e3-4be8-84b7-f5720d42b5b0",
"Type": 2
},
{
"ID": "ff45cda2-75e3-4be8-84b7-f5720d42b5b0",
"Type": 2
},
{
"ID": "ServicePrincipal",
"Type": 2
}
],
"ActorContextId": "6915b1e0-b081-4829-8866-f1a3e883a9ae",
"ActorIpAddress": "52.224.85.250",
"AzureActiveDirectoryEventType": 1,
"ClientIP": "52.224.85.250",
"CreationTime": "2024-03-20T07:51:02",
"ExtendedProperties": [
{
"Name": "additionalDetails",
"Value": {}
},
{
"Name": "extendedAuditEventCategory",
"Value": "CrossTenantAccessSettings"
}
],
"Id": "4923abb2-609c-411e-a685-0c4f0c53ecfb",
"InterSystemsId": "f76baa3e-1207-41fb-b5df-631ceccb9b2e",
"IntraSystemId": "b5ea04c4-e89f-45d6-ad54-9d8ba882e701",
"ModifiedProperties": [
{
"Name": "tenantId",
"NewValue": "141e07d1-6f28-4169-b951-316d5a941d88",
"OldValue": ""
}
],
"ObjectId": "Policy_17c7001d-3a4d-4bf7-9cc6-ee0e40f665da",
"Operation": "Add a partner to cross-tenant access setting.",
"OrganizationId": "6915b1e0-b081-4829-8866-f1a3e883a9ae",
"RecordType": 8,
"ResultStatus": "Success",
"Target": [
{
"ID": "Policy_17c7001d-3a4d-4bf7-9cc6-ee0e40f665da",
"Type": 2
},
{
"ID": "17c7001d-3a4d-4bf7-9cc6-ee0e40f665da",
"Type": 2
},
{
"ID": "Policy",
"Type": 2
},
{
"ID": "CrossTenantAccessPolicy for 6915b1e0-b081-4829-8866-f1a3e883a9ae",
"Type": 1
}
],
"TargetContextId": "6915b1e0-b081-4829-8866-f1a3e883a9ae",
"UserId": "ServicePrincipal_ff45cda2-75e3-4be8-84b7-f5720d42b5b0",
"UserKey": "Not Available",
"UserType": 4,
"Version": 1,
"Workload": "AzureActiveDirectory"
}
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Splunk #
T1484, T1484.002↳ also matches Delete partner specific cross-tenant access setting.
References #
Add administrative unit.
#Description
Add administrative unit. activity in Microsoft Entra ID, recorded in the Unified Audit Log (observed in first-party capture).
Example Audit Record #
{
"Actor": [
{
"ID": "adminuser@example.onmicrosoft.com",
"Type": 5
},
{
"ID": 1111111111111111,
"Type": 3
},
{
"ID": "User_aaaaaaaa-0000-0000-0000-000000000001",
"Type": 2
},
{
"ID": "aaaaaaaa-0000-0000-0000-000000000001",
"Type": 2
},
{
"ID": "User",
"Type": 2
},
{
"ID": "NotAgentic",
"Type": 2
}
],
"ActorContextId": "11111111-1111-1111-1111-111111111111",
"AzureActiveDirectoryEventType": 1,
"CreationDate": "2026-07-03T03:23:03",
"CreationTime": "2026-07-03T03:23:03",
"ExtendedProperties": [
{
"Name": "additionalDetails",
"Value": {
"User-Agent": "python/3.13.9 (Linux-6.1.0-41-amd64-x86_64-with-glibc2.36) AZURECLI/2.82.0 (DEB)"
}
},
{
"Name": "extendedAuditEventCategory",
"Value": "AdministrativeUnit"
}
],
"Id": "78414ede-98e9-417b-acf7-70adc580b052",
"InterSystemsId": "4268eb2a-8263-400f-874c-31ef4dbdf000",
"IntraSystemId": "ac85b254-d400-4f9c-af7a-80f0e1ae6bfd",
"ModifiedProperties": [
{
"Name": "DisplayName",
"NewValue": [
"dw-harness-aum-2fe5ab51"
],
"OldValue": []
},
{
"Name": "Included Updated Properties",
"NewValue": "DisplayName",
"OldValue": ""
}
],
"ObjectId": "AdministrativeUnit_78e00ff9-4f90-4a2d-ba46-416e73ce7793",
"Operation": "Add administrative unit.",
"Operations": "Add administrative unit.",
"OrganizationId": "11111111-1111-1111-1111-111111111111",
"RecordType": "AzureActiveDirectory",
"ResultStatus": "Success",
"Target": [
{
"ID": "AdministrativeUnit_78e00ff9-4f90-4a2d-ba46-416e73ce7793",
"Type": 2
},
{
"ID": "78e00ff9-4f90-4a2d-ba46-416e73ce7793",
"Type": 2
},
{
"ID": "Manager",
"Type": 2
},
{
"ID": "dw-harness-aum-2fe5ab51",
"Type": 1
}
],
"TargetContextId": "11111111-1111-1111-1111-111111111111",
"UserId": "adminuser@example.onmicrosoft.com",
"UserKey": "1111111111111111@example.onmicrosoft.com",
"UserType": "Regular",
"Version": 1,
"Workload": "AzureActiveDirectory"
}
References #
Add app role assignment grant to user.
#Description
An app role assignment was granted to a user in Microsoft Entra ID (an enterprise application role assigned to a user account). A directory operation, so it carries RecordType AzureActiveDirectory (8) like its documented siblings (Add/Remove app role assignment to service principal / from user).
Example Audit Record #
{
"Actor": [
{
"ID": "rodsoto@rodsoto.onmicrosoft.com",
"Type": 5
},
{
"ID": "10037FFEA938FB92",
"Type": 3
},
{
"ID": "74658136-14ec-4630-ad9b-26e160ff0fc6",
"Type": 2
},
{
"ID": "User_bfb8c366-0406-41a5-b3e3-328f4a3b4484",
"Type": 2
},
{
"ID": "bfb8c366-0406-41a5-b3e3-328f4a3b4484",
"Type": 2
},
{
"ID": "User",
"Type": 2
}
],
"ActorContextId": "0e8108b1-18e9-41a4-961b-dfcddf92ef08",
"ActorIpAddress": "40.124.84.4",
"AzureActiveDirectoryEventType": 1,
"ClientIP": "40.124.84.4",
"CreationTime": "2021-01-19T22:21:39",
"ExtendedProperties": [
{
"Name": "additionalDetails",
"Value": {}
},
{
"Name": "extendedAuditEventCategory",
"Value": "User"
}
],
"Id": "8b9e5417-c310-4382-89da-c0f25c5c0576",
"InterSystemsId": "85c80877-c529-4487-8f44-48760767cc6c",
"IntraSystemId": "6fc81447-9c94-4734-8bd7-307bb699c04e",
"ModifiedProperties": [
{
"Name": "AppRole.Id",
"NewValue": "97edced9-9f34-4eef-9b49-84a5ebcd5167",
"OldValue": ""
},
{
"Name": "AppRole.Value",
"NewValue": "arn:aws:iam::111111111111:role/rodonmicrotestrole,arn:aws:iam::111111111111:saml-provider/rodsotoonmicrosoft",
"OldValue": ""
},
{
"Name": "AppRole.DisplayName",
"NewValue": "rodonmicrotestrole,rodsotoonmicrosoft",
"OldValue": ""
},
{
"Name": "User.ObjectID",
"NewValue": "7646f1a9-620c-4630-b5e4-b02838be5562",
"OldValue": ""
},
{
"Name": "User.UPN",
"NewValue": "vagrant@rodsoto.onmicrosoft.com",
"OldValue": ""
},
{
"Name": "User.PUID",
"NewValue": "100320010972E450",
"OldValue": ""
},
{
"Name": "TargetId.ServicePrincipalNames",
"NewValue": "https://signin.aws.amazon.com/saml;3e71560f-3e31-45ab-b439-46328fe55b88",
"OldValue": ""
}
],
"ObjectId": "https://signin.aws.amazon.com/saml;3e71560f-3e31-45ab-b439-46328fe55b88",
"Operation": "Add app role assignment grant to user.",
"OrganizationId": "0e8108b1-18e9-41a4-961b-dfcddf92ef08",
"RecordType": 8,
"ResultStatus": "Success",
"Target": [
{
"ID": "ServicePrincipal_9fd10db9-dfe2-4d74-a724-c837eb8764d9",
"Type": 2
},
{
"ID": "9fd10db9-dfe2-4d74-a724-c837eb8764d9",
"Type": 2
},
{
"ID": "ServicePrincipal",
"Type": 2
},
{
"ID": "Amazon Web Services (AWS)",
"Type": 1
},
{
"ID": "3e71560f-3e31-45ab-b439-46328fe55b88",
"Type": 2
},
{
"ID": "https://signin.aws.amazon.com/saml;3e71560f-3e31-45ab-b439-46328fe55b88",
"Type": 4
}
],
"TargetContextId": "0e8108b1-18e9-41a4-961b-dfcddf92ef08",
"UserId": "rodsoto@rodsoto.onmicrosoft.com",
"UserKey": "10037FFEA938FB92@rodsoto.onmicrosoft.com",
"UserType": 0,
"Version": 1,
"Workload": "AzureActiveDirectory"
}
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Splunk #
o365_management_activity dataset, specifically monitoring the "Add app role assignment grant to user"…T1136, T1136.003
References #
Add app role assignment to service principal.
#Description
Microsoft Entra ID (Azure Active Directory) audit activity in the ApplicationManagement category, recorded in the Office 365 Unified Audit Log.
Example Audit Record #
{
"CreationTime": "2024-04-30T08:22:50",
"Id": "5fd0f419-722d-4fe3-86cd-ce261f32fca7",
"Operation": "Add app role assignment to service principal.",
"OrganizationId": "225e05a1-5914-4688-a404-7030e60f3143",
"RecordType": 8,
"ResultStatus": "Success",
"UserKey": "Not Available",
"UserType": 4,
"Version": 1,
"Workload": "AzureActiveDirectory",
"ObjectId": "https://canary.graph.microsoft.com/;https://graph.microsoft.us/;https://dod-graph.microsoft.us/;https://dod-graph.microsoft.us;https://graph.microsoft.com/;https://graph.microsoft.us;https://canary.graph.microsoft.com;https://graph.microsoft.com;https://ags.windows.net;00000003-0000-0000-c000-000000000000/ags.windows.net;00000003-0000-0000-c000-000000000000",
"UserId": "ServicePrincipal_ffa25d34-fbae-42ec-aa48-bc7e4ff8bf66",
"AzureActiveDirectoryEventType": 1,
"ExtendedProperties": [
{
"Name": "additionalDetails",
"Value": {
"User-Agent": "Mozilla/5.0 (Windows NT 10.0; Microsoft Windows 10.0.19045; en-AU) PowerShell/5.1.19041.4291",
"AppId": "00000003-0000-0000-c000-000000000000"
}
},
{
"Name": "extendedAuditEventCategory",
"Value": "ServicePrincipal"
}
],
"ModifiedProperties": [
{
"Name": "AppRole.Id",
"NewValue": "9e3f62cf-ca93-4989-b6ce-bf83c28f9fe8",
"OldValue": ""
},
{
"Name": "AppRole.Value",
"NewValue": "RoleManagement.ReadWrite.Directory",
"OldValue": ""
},
{
"Name": "AppRole.DisplayName",
"NewValue": "Read and write all directory RBAC settings",
"OldValue": ""
},
{
"Name": "AppRoleAssignment.CreatedDateTime",
"NewValue": "4/30/2024 8:22:50 AM",
"OldValue": ""
},
{
"Name": "AppRoleAssignment.LastModifiedDateTime",
"NewValue": "4/30/2024 8:22:50 AM",
"OldValue": ""
},
{
"Name": "ServicePrincipal.ObjectID",
"NewValue": "ffa25d34-fbae-42ec-aa48-bc7e4ff8bf66",
"OldValue": ""
},
{
"Name": "ServicePrincipal.DisplayName",
"NewValue": "MashAuthTest",
"OldValue": ""
},
{
"Name": "ServicePrincipal.AppId",
"NewValue": "7889f28d-ad42-441e-b1f6-1ad8da2f13e8",
"OldValue": ""
},
{
"Name": "ServicePrincipal.Name",
"NewValue": "7889f28d-ad42-441e-b1f6-1ad8da2f13e8",
"OldValue": ""
},
{
"Name": "TargetId.ServicePrincipalNames",
"NewValue": "https://canary.graph.microsoft.com/;https://graph.microsoft.us/;https://dod-graph.microsoft.us/;https://dod-graph.microsoft.us;https://graph.microsoft.com/;https://graph.microsoft.us;https://canary.graph.microsoft.com;https://graph.microsoft.com;https://ags.windows.net;00000003-0000-0000-c000-000000000000/ags.windows.net;00000003-0000-0000-c000-000000000000",
"OldValue": ""
}
],
"Actor": [
{
"ID": "MashAuthTest",
"Type": 1
},
{
"ID": "7889f28d-ad42-441e-b1f6-1ad8da2f13e8",
"Type": 2
},
{
"ID": "ServicePrincipal_ffa25d34-fbae-42ec-aa48-bc7e4ff8bf66",
"Type": 2
},
{
"ID": "ffa25d34-fbae-42ec-aa48-bc7e4ff8bf66",
"Type": 2
},
{
"ID": "ServicePrincipal",
"Type": 2
}
],
"ActorContextId": "225e05a1-5914-4688-a404-7030e60f3143",
"InterSystemsId": "c967e3a4-9afd-49ee-a68c-bc465aaef2b3",
"IntraSystemId": "00000000-0000-0000-0000-000000000000",
"Target": [
{
"ID": "ServicePrincipal_58c0347e-8f51-49e5-a4db-8b1b857a7ddf",
"Type": 2
},
{
"ID": "58c0347e-8f51-49e5-a4db-8b1b857a7ddf",
"Type": 2
},
{
"ID": "ServicePrincipal",
"Type": 2
},
{
"ID": "Microsoft Graph",
"Type": 1
},
{
"ID": "00000003-0000-0000-c000-000000000000",
"Type": 2
},
{
"ID": "https://canary.graph.microsoft.com/;https://graph.microsoft.us/;https://dod-graph.microsoft.us/;https://dod-graph.microsoft.us;https://graph.microsoft.com/;https://graph.microsoft.us;https://canary.graph.microsoft.com;https://graph.microsoft.com;https://ags.windows.net;00000003-0000-0000-c000-000000000000/ags.windows.net;00000003-0000-0000-c000-000000000000",
"Type": 4
}
],
"TargetContextId": "225e05a1-5914-4688-a404-7030e60f3143"
}
Common Indicators #
Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.
| Field | Kind | Value | Rules | Vendors |
|---|---|---|---|---|
ResultStatus (splunk rule field) | eq | success | 1 rule | splunk |
servicePrincipal (splunk rule field) | cross_field_compare | targetServicePrincipal | 1 rule | splunk |
userType (splunk rule field) | eq | serviceprincipal | 1 rule | splunk |
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Splunk #
o365_management_activity logs, specifically focusing on the 'Add…T1098, T1098.003T1098, T1098.003
References #
Add application.
#Description
An application registration was created in Azure Active Directory (the UAL operation string includes a trailing period).
Example Audit Record #
{
"CreationTime": "2024-02-07T22:31:14",
"Id": "b47e890a-5bc1-4ebd-a8d5-2f4796de80d6",
"Operation": "Add application.",
"OrganizationId": "75243ab2-44f8-435c-a7a6-b479385df6d4",
"RecordType": 8,
"ResultStatus": "Success",
"UserKey": "1003BFFD98415B4E@splunkresearch.onmicrosoft.com",
"UserType": 0,
"Version": 1,
"Workload": "AzureActiveDirectory",
"ObjectId": "Application_aef7a9a6-428e-4f0f-ab09-b0f10b21bda6",
"UserId": "user30@splunkresearch.onmicrosoft.com",
"AzureActiveDirectoryEventType": 1,
"ExtendedProperties": [
{
"Name": "additionalDetails",
"Value": {
"User-Agent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/121.0.0.0 Safari/537.36",
"AppId": "e06366ca-8489-4748-b6a2-d7e4332f45c1"
}
},
{
"Name": "extendedAuditEventCategory",
"Value": "Application"
}
],
"ModifiedProperties": [
{
"Name": "AppId",
"NewValue": [
"e06366ca-8489-4748-b6a2-d7e4332f45c1"
],
"OldValue": []
},
{
"Name": "AvailableToOtherTenants",
"NewValue": [
false
],
"OldValue": []
},
{
"Name": "DisplayName",
"NewValue": [
"Malicious11"
],
"OldValue": []
},
{
"Name": "RequiredResourceAccess",
"NewValue": [
{
"ResourceAppId": "00000003-0000-0000-c000-000000000000",
"RequiredAppPermissions": [
{
"EntitlementId": "e1fe6dd8-ba31-4d61-89e7-88639da4683d",
"DirectAccessGrant": false,
"ImpersonationAccessGrants": [
20
]
}
],
"EncodingVersion": 1
}
],
"OldValue": []
},
{
"Name": "PublisherDomain",
"NewValue": [
"splunkresearch.onmicrosoft.com"
],
"OldValue": []
},
{
"Name": "ServicePrincipalLockConfiguration",
"NewValue": [
{
"IsEnabled": true,
"AllProperties": true,
"CredentialsWithUsageVerify": true,
"CredentialsWithUsageSign": true,
"IdentifierUris": false,
"TokenEncryptionKeyId": true
}
],
"OldValue": []
},
{
"Name": "Included Updated Properties",
"NewValue": "AppId, AvailableToOtherTenants, DisplayName, RequiredResourceAccess, PublisherDomain, ServicePrincipalLockConfiguration",
"OldValue": ""
}
],
"Actor": [
{
"ID": "user30@splunkresearch.onmicrosoft.com",
"Type": 5
},
{
"ID": "1003BFFD98415B4E",
"Type": 3
},
{
"ID": "18ed3507-a475-4ccb-b669-d66bc9f2a36e",
"Type": 2
},
{
"ID": "User_e4c722ac-3b83-478d-8f52-c388885dc30f",
"Type": 2
},
{
"ID": "e4c722ac-3b83-478d-8f52-c388885dc30f",
"Type": 2
},
{
"ID": "User",
"Type": 2
}
],
"ActorContextId": "75243ab2-44f8-435c-a7a6-b479385df6d4",
"InterSystemsId": "9a0d48df-8083-4c2a-9095-5475289fb512",
"IntraSystemId": "00000000-0000-0000-0000-000000000000",
"Target": [
{
"ID": "Application_aef7a9a6-428e-4f0f-ab09-b0f10b21bda6",
"Type": 2
},
{
"ID": "aef7a9a6-428e-4f0f-ab09-b0f10b21bda6",
"Type": 2
},
{
"ID": "Application",
"Type": 2
},
{
"ID": "Malicious11",
"Type": 1
},
{
"ID": "e06366ca-8489-4748-b6a2-d7e4332f45c1",
"Type": 2
}
],
"TargetContextId": "75243ab2-44f8-435c-a7a6-b479385df6d4"
}
Common Indicators #
Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.
| Field | Kind | Value | Rules | Vendors |
|---|---|---|---|---|
target.resource.product_object_id (Chronicle) | eq | 1b730954-1685-4b74-9bfd-dac224a7b894 | 1 rule | chronicle |
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Splunk #
T1098, T1098.003↳ also matches Update application. YARA-L #
T1098, T1098.001↳ also matches Add delegated permission grant., Update application – Certificates and secrets management , Update application.
References #
Add delegated permission grant.
#Description
An OAuth2 delegated permission grant was created for an application.
Example Audit Record #
{
"Actor": [
{
"ID": "adminuser@example.onmicrosoft.com",
"Type": 5
},
{
"ID": "10000000AAAAAAAA",
"Type": 3
},
{
"ID": "User_11111111-1111-1111-1111-111111111111",
"Type": 2
},
{
"ID": "11111111-1111-1111-1111-111111111111",
"Type": 2
},
{
"ID": "User",
"Type": 2
},
{
"ID": "NotAgentic",
"Type": 2
}
],
"ActorContextId": "00000000-0000-0000-0000-000000000001",
"AzureActiveDirectoryEventType": 1,
"CreationTime": "2026-07-02T15:30:12Z",
"ExtendedProperties": [
{
"Name": "additionalDetails",
"Value": {
"User-Agent": "python/3.13.9 (Linux-6.1.0-41-amd64-x86_64-with-glibc2.36) AZURECLI/2.82.0 (DEB)",
"AppId": "00000003-0000-0000-c000-000000000000",
"ServicePrincipalProvisioningType": "Other"
}
},
{
"Name": "extendedAuditEventCategory",
"Value": "ServicePrincipal"
}
],
"Id": "f2665a07-1a1b-4857-a283-f0b4841b7b00",
"InterSystemsId": "08dc6a80-0279-49c9-bf3d-bf9574f77337",
"IntraSystemId": "00000000-0000-0000-0000-000000000000",
"ModifiedProperties": [
{
"Name": "DelegatedPermissionGrant.Scope",
"NewValue": "User.Read"
},
{
"Name": "DelegatedPermissionGrant.ConsentType",
"NewValue": "Principal"
},
{
"Name": "ServicePrincipal.ObjectID",
"NewValue": "af2cee02-3ad4-4486-85a2-e8eafc78cd6e"
},
{
"Name": "ServicePrincipal.DisplayName"
},
{
"Name": "ServicePrincipal.AppId"
},
{
"Name": "ServicePrincipal.Name"
},
{
"Name": "TargetId.ServicePrincipalNames",
"NewValue": "00000003-0000-0000-c000-000000000000/ags.windows.net;00000003-0000-0000-c000-000000000000;https://canary.graph.microsoft.com;https://graph.microsoft.com;https://ags.windows.net;https://graph.microsoft.us;https://graph.microsoft.com/;https://dod-graph.microsoft.us;https://canary.graph.microsoft.com/;https://graph.microsoft.us/;https://dod-graph.microsoft.us/"
}
],
"ObjectId": "00000003-0000-0000-c000-000000000000/ags.windows.net;00000003-0000-0000-c000-000000000000;https://canary.graph.microsoft.com;https://graph.microsoft.com;https://ags.windows.net;https://graph.microsoft.us;https://graph.microsoft.com/;https://dod-graph.microsoft.us;https://canary.graph.microsoft.com/;https://graph.microsoft.us/;https://dod-graph.microsoft.us/",
"Operation": "Add delegated permission grant.",
"OrganizationId": "00000000-0000-0000-0000-000000000001",
"RecordType": 8,
"ResultStatus": "Success",
"Target": [
{
"ID": "ServicePrincipal_2e5ab30e-ae89-43c2-b130-0022f3d655a7",
"Type": 2
},
{
"ID": "2e5ab30e-ae89-43c2-b130-0022f3d655a7",
"Type": 2
},
{
"ID": "ServicePrincipal",
"Type": 2
},
{
"ID": "NotAgentic",
"Type": 2
},
{
"ID": "Microsoft Graph",
"Type": 1
},
{
"ID": "00000003-0000-0000-c000-000000000000",
"Type": 2
},
{
"ID": "00000003-0000-0000-c000-000000000000/ags.windows.net;00000003-0000-0000-c000-000000000000;https://canary.graph.microsoft.com;https://graph.microsoft.com;https://ags.windows.net;https://graph.microsoft.us;https://graph.microsoft.com/;https://dod-graph.microsoft.us;https://canary.graph.microsoft.com/;https://graph.microsoft.us/;https://dod-graph.microsoft.us/",
"Type": 4
},
{
"ID": "Other",
"Type": 2
}
],
"TargetContextId": "00000000-0000-0000-0000-000000000001",
"UserId": "adminuser@example.onmicrosoft.com",
"UserKey": "10000000AAAAAAAA@example.onmicrosoft.com",
"UserType": 0,
"Version": 1,
"Workload": "AzureActiveDirectory"
}
Common Indicators #
Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.
| Field | Kind | Value | Rules | Vendors |
|---|---|---|---|---|
target.resource.product_object_id (Chronicle) | eq | 1b730954-1685-4b74-9bfd-dac224a7b894 | 1 rule | chronicle |
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →YARA-L #
T1098, T1098.001↳ also matches Add application., Update application – Certificates and secrets management , Update application.
References #
Add eligible member to role.
#Description
Microsoft Entra ID (Azure Active Directory) audit activity in the RoleManagement category, recorded in the Office 365 Unified Audit Log.
Common Indicators #
Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.
| Field | Kind | Value | Rules | Vendors |
|---|---|---|---|---|
isprvilegedadrole (splunk rule field) | eq | true | 2 rules | splunk |
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Splunk #
T1098, T1098.003↳ also matches Add member to role. T1098, T1098.003↳ also matches Add member to role.
References #
Add group.
#Description
A group was created in Azure Active Directory (the UAL operation string includes a trailing period).
Example Audit Record #
{
"Actor": [
{
"ID": "adminuser@example.onmicrosoft.com",
"Type": 5
},
{
"ID": 1111111111111111,
"Type": 3
},
{
"ID": "User_11111111-1111-1111-1111-111111111111",
"Type": 2
},
{
"ID": "11111111-1111-1111-1111-111111111111",
"Type": 2
},
{
"ID": "User",
"Type": 2
},
{
"ID": "NotAgentic",
"Type": 2
}
],
"ActorContextId": "00000000-0000-0000-0000-000000000001",
"AzureActiveDirectoryEventType": 1,
"CreationTime": "2026-07-03T01:52:29Z",
"ExtendedProperties": [
{
"Name": "additionalDetails",
"Value": {
"User-Agent": "python/3.13.9 (Linux-6.1.0-41-amd64-x86_64-with-glibc2.36) AZURECLI/2.82.0 (DEB)"
}
},
{
"Name": "extendedAuditEventCategory",
"Value": "Group"
}
],
"Id": "3892d90d-6864-4119-bc44-d3905cdc6ff8",
"InterSystemsId": "402aaf03-a057-42a7-a135-7fb5edc20afc",
"IntraSystemId": "e369da91-5836-470b-85bc-3f07c1f2416b",
"ModifiedProperties": [
{
"Name": "DisplayName",
"NewValue": [
"dw-harness-78619d48"
],
"OldValue": []
},
{
"Name": "MailEnabled",
"NewValue": [
false
],
"OldValue": []
},
{
"Name": "MailNickname",
"NewValue": [
"dwharn78619d48"
],
"OldValue": []
},
{
"Name": "RenewedDateTime",
"NewValue": [
"2026-07-03T01:52:29Z"
],
"OldValue": []
},
{
"Name": "SecurityEnabled",
"NewValue": [
true
],
"OldValue": []
},
{
"Name": "Included Updated Properties",
"NewValue": "DisplayName, MailEnabled, MailNickname, RenewedDateTime, SecurityEnabled",
"OldValue": ""
}
],
"ObjectId": "Group_60a4e99d-f269-49b2-9b9c-b4fc0d4e7f69",
"Operation": "Add group.",
"OrganizationId": "00000000-0000-0000-0000-000000000001",
"RecordType": 8,
"ResultStatus": "Success",
"Target": [
{
"ID": "Group_60a4e99d-f269-49b2-9b9c-b4fc0d4e7f69",
"Type": 2
},
{
"ID": "60a4e99d-f269-49b2-9b9c-b4fc0d4e7f69",
"Type": 2
},
{
"ID": "Group",
"Type": 2
},
{
"ID": "dw-harness-78619d48",
"Type": 1
}
],
"TargetContextId": "00000000-0000-0000-0000-000000000001",
"UserId": "adminuser@example.onmicrosoft.com",
"UserKey": "1111111111111111@example.onmicrosoft.com",
"UserType": 0,
"Version": 1,
"Workload": "AzureActiveDirectory"
}
Common Indicators #
Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.
| Field | Kind | Value | Rules | Vendors |
|---|---|---|---|---|
security_result.action (Chronicle) | eq | BLOCK | 1 rule | chronicle |
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →YARA-L #
References #
Add label.
#Description
Add label. activity in Microsoft Entra ID, recorded in the Unified Audit Log (observed in first-party capture).
Example Audit Record #
{
"Actor": [
{
"ID": "Microsoft Exchange Online Protection",
"Type": 1
},
{
"ID": "00000007-0000-0ff1-ce00-000000000000",
"Type": 2
},
{
"ID": "ServicePrincipal_7346eb28-2787-4db2-8f6e-a9ebdeec5988",
"Type": 2
},
{
"ID": "7346eb28-2787-4db2-8f6e-a9ebdeec5988",
"Type": 2
},
{
"ID": "ServicePrincipal",
"Type": 2
},
{
"ID": "NotAgentic",
"Type": 2
}
],
"ActorContextId": "11111111-1111-1111-1111-111111111111",
"AzureActiveDirectoryEventType": 1,
"CreationDate": "2026-07-03T06:00:18",
"CreationTime": "2026-07-03T06:00:18",
"ExtendedProperties": [
{
"Name": "additionalDetails",
"Value": {}
},
{
"Name": "extendedAuditEventCategory",
"Value": "Label"
}
],
"Id": "0416eba4-a275-4388-a69e-cf02ac17b390",
"InterSystemsId": "ce4fbd01-9437-4653-b3e8-e3e160c50f11",
"IntraSystemId": "00000000-0000-0000-0000-000000000000",
"ModifiedProperties": [
{
"Name": "DisplayName",
"NewValue": [
"dwharnee8749b4 label"
],
"OldValue": []
},
{
"Name": "LabelId",
"NewValue": [
"93b80c3d-9d7c-459f-9ff8-53a551853113"
],
"OldValue": []
},
{
"Name": "Included Updated Properties",
"NewValue": "DisplayName, LabelId",
"OldValue": ""
}
],
"ObjectId": "Label_9ce4f699-9b6f-466b-a698-9da68b7a45b3",
"Operation": "Add label.",
"Operations": "Add label.",
"OrganizationId": "11111111-1111-1111-1111-111111111111",
"RecordType": "AzureActiveDirectory",
"ResultStatus": "Success",
"Target": [
{
"ID": "Label_9ce4f699-9b6f-466b-a698-9da68b7a45b3",
"Type": 2
},
{
"ID": "9ce4f699-9b6f-466b-a698-9da68b7a45b3",
"Type": 2
},
{
"ID": "Other",
"Type": 2
},
{
"ID": "dwharnee8749b4 label",
"Type": 1
}
],
"TargetContextId": "11111111-1111-1111-1111-111111111111",
"UserId": "ServicePrincipal_7346eb28-2787-4db2-8f6e-a9ebdeec5988",
"UserKey": "Not Available",
"UserType": "System",
"Version": 1,
"Workload": "AzureActiveDirectory"
}
References #
Add member to administrative unit.
#Description
Add member to administrative unit. activity in Microsoft Entra ID, recorded in the Unified Audit Log (observed in first-party capture).
Example Audit Record #
{
"Actor": [
{
"ID": "adminuser@example.onmicrosoft.com",
"Type": 5
},
{
"ID": 1111111111111111,
"Type": 3
},
{
"ID": "User_aaaaaaaa-0000-0000-0000-000000000001",
"Type": 2
},
{
"ID": "aaaaaaaa-0000-0000-0000-000000000001",
"Type": 2
},
{
"ID": "User",
"Type": 2
},
{
"ID": "NotAgentic",
"Type": 2
}
],
"ActorContextId": "11111111-1111-1111-1111-111111111111",
"AzureActiveDirectoryEventType": 1,
"CreationDate": "2026-07-03T03:23:05",
"CreationTime": "2026-07-03T03:23:05",
"ExtendedProperties": [
{
"Name": "additionalDetails",
"Value": {
"User-Agent": "python/3.13.9 (Linux-6.1.0-41-amd64-x86_64-with-glibc2.36) AZURECLI/2.82.0 (DEB)"
}
},
{
"Name": "extendedAuditEventCategory",
"Value": "AdministrativeUnit"
}
],
"Id": "78072ba4-e967-4c5e-a116-05bdb3e17fd7",
"InterSystemsId": "25def137-b2ec-414d-94fa-5bc7746bdf42",
"IntraSystemId": "c6d22437-2973-4763-910d-5c99181df2ee",
"ModifiedProperties": [
{
"Name": "AdministrativeUnit.ObjectID",
"NewValue": "78e00ff9-4f90-4a2d-ba46-416e73ce7793",
"OldValue": ""
},
{
"Name": "AdministrativeUnit.DisplayName",
"NewValue": "dw-harness-aum-2fe5ab51",
"OldValue": ""
}
],
"ObjectId": "adminuser@example.onmicrosoft.com",
"Operation": "Add member to administrative unit.",
"Operations": "Add member to administrative unit.",
"OrganizationId": "11111111-1111-1111-1111-111111111111",
"RecordType": "AzureActiveDirectory",
"ResultStatus": "Success",
"Target": [
{
"ID": "User_aaaaaaaa-0000-0000-0000-000000000001",
"Type": 2
},
{
"ID": "aaaaaaaa-0000-0000-0000-000000000001",
"Type": 2
},
{
"ID": "User",
"Type": 2
},
{
"ID": "NotAgentic",
"Type": 2
},
{
"ID": "adminuser@example.onmicrosoft.com",
"Type": 5
},
{
"ID": 1111111111111111,
"Type": 3
}
],
"TargetContextId": "11111111-1111-1111-1111-111111111111",
"UserId": "adminuser@example.onmicrosoft.com",
"UserKey": "1111111111111111@example.onmicrosoft.com",
"UserType": "Regular",
"Version": 1,
"Workload": "AzureActiveDirectory"
}
References #
Add member to group.
#Description
A principal was added to a group in Azure Active Directory (the UAL operation string includes a trailing period).
Example Audit Record #
{
"Actor": [
{
"ID": "adminuser@example.onmicrosoft.com",
"Type": 5
},
{
"ID": 1111111111111111,
"Type": 3
},
{
"ID": "User_11111111-1111-1111-1111-111111111111",
"Type": 2
},
{
"ID": "11111111-1111-1111-1111-111111111111",
"Type": 2
},
{
"ID": "User",
"Type": 2
},
{
"ID": "NotAgentic",
"Type": 2
}
],
"ActorContextId": "00000000-0000-0000-0000-000000000001",
"AzureActiveDirectoryEventType": 1,
"CreationTime": "2026-07-03T03:22:09Z",
"ExtendedProperties": [
{
"Name": "additionalDetails",
"Value": {
"User-Agent": "python/3.13.9 (Linux-6.1.0-41-amd64-x86_64-with-glibc2.36) AZURECLI/2.82.0 (DEB)"
}
},
{
"Name": "extendedAuditEventCategory",
"Value": "Group"
}
],
"Id": "ffe7bece-d342-4429-9a9a-65dc80a52de5",
"InterSystemsId": "a1a73bd6-8cca-4d59-b646-1608ac944b41",
"IntraSystemId": "00000000-0000-0000-0000-000000000000",
"ModifiedProperties": [
{
"Name": "Group.ObjectID",
"NewValue": "6b01a770-1193-453a-b3f4-d9a24a6e7060",
"OldValue": ""
},
{
"Name": "Group.DisplayName",
"NewValue": "dw-harness-2fe5ab51",
"OldValue": ""
}
],
"ObjectId": "adminuser@example.onmicrosoft.com",
"Operation": "Add member to group.",
"OrganizationId": "00000000-0000-0000-0000-000000000001",
"RecordType": 8,
"ResultStatus": "Success",
"Target": [
{
"ID": "User_11111111-1111-1111-1111-111111111111",
"Type": 2
},
{
"ID": "11111111-1111-1111-1111-111111111111",
"Type": 2
},
{
"ID": "User",
"Type": 2
},
{
"ID": "NotAgentic",
"Type": 2
},
{
"ID": "adminuser@example.onmicrosoft.com",
"Type": 5
},
{
"ID": 1111111111111111,
"Type": 3
}
],
"TargetContextId": "00000000-0000-0000-0000-000000000001",
"UserId": "adminuser@example.onmicrosoft.com",
"UserKey": "1111111111111111@example.onmicrosoft.com",
"UserType": 0,
"Version": 1,
"Workload": "AzureActiveDirectory"
}
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →YARA-L #
References #
Add member to role.
#Equivalent operation in the other pipeline: Add member to role (Entra ID directory audit)
Description
A principal was added to an Azure Active Directory directory role (the UAL operation string includes a trailing period).
Example Audit Record #
{
"Actor": [
{
"ID": "MS-PIM",
"Type": 1
},
{
"ID": "01fc33a7-78ba-4d2f-a4b7-768e336e890e",
"Type": 2
},
{
"ID": "ServicePrincipal_34d49b97-725f-480d-8971-89b92df5ca70",
"Type": 2
},
{
"ID": "34d49b97-725f-480d-8971-89b92df5ca70",
"Type": 2
},
{
"ID": "ServicePrincipal",
"Type": 2
}
],
"ActorContextId": "6915b1e0-b081-4829-8866-f1a3e883a9ae",
"ActorIpAddress": "172.170.254.43",
"AzureActiveDirectoryEventType": 1,
"ClientIP": "172.170.254.43",
"CreationTime": "2024-03-21T13:08:48",
"ExtendedProperties": [
{
"Name": "additionalDetails",
"Value": {}
},
{
"Name": "extendedAuditEventCategory",
"Value": "Role"
}
],
"Id": "0bc79ad5-7c63-44ab-9495-f9e08d315e8e",
"InterSystemsId": "636a211d-7b24-448c-b618-04975c7fb2e4",
"IntraSystemId": "3921fc01-d201-471f-baf4-a0becf9257c7",
"ModifiedProperties": [
{
"Name": "Role.ObjectID",
"NewValue": "dc6acb7b-951e-489c-92d5-5b4686ad47d2",
"OldValue": ""
},
{
"Name": "Role.DisplayName",
"NewValue": "Privileged Role Administrator",
"OldValue": ""
},
{
"Name": "Role.TemplateId",
"NewValue": "e8611ab8-c189-46e8-94e1-60213ab1f814",
"OldValue": ""
},
{
"Name": "Role.WellKnownObjectName",
"NewValue": "PrivilegedRoleAdmins",
"OldValue": ""
}
],
"ObjectId": "attacker@attack_range.lan",
"Operation": "Add member to role.",
"OrganizationId": "6915b1e0-b081-4829-8866-f1a3e883a9ae",
"RecordType": 8,
"ResultStatus": "Success",
"Target": [
{
"ID": "User_3921fc01-d201-471f-baf4-a0becf9257c7",
"Type": 2
},
{
"ID": "3921fc01-d201-471f-baf4-a0becf9257c7",
"Type": 2
},
{
"ID": "User",
"Type": 2
},
{
"ID": "attacker_persistence@attack_range",
"Type": 5
},
{
"ID": "10032001C7E04175",
"Type": 3
}
],
"TargetContextId": "6915b1e0-b081-4829-8866-f1a3e883a9ae",
"UserId": "ServicePrincipal_34d49b97-725f-480d-8971-89b92df5ca70",
"UserKey": "Not Available",
"UserType": 4,
"Version": 1,
"Workload": "AzureActiveDirectory"
}
Common Indicators #
Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.
| Field | Kind | Value | Rules | Vendors |
|---|---|---|---|---|
isprvilegedadrole (splunk rule field) | eq | true | 2 rules | splunk |
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Elastic #
T1098, T1098.003Splunk #
T1098, T1098.003T1098, T1098.003↳ also matches Add eligible member to role. T1098, T1098.003↳ also matches Add eligible member to role. YARA-L #
T1098, T1098.003T1098, T1098.003↳ also matches Add user.
References #
Add owner to application.
#Description
Microsoft Entra ID (Azure Active Directory) audit activity in the ApplicationManagement category, recorded in the Office 365 Unified Audit Log.
Example Audit Record #
{
"CreationTime": "2023-09-07T13:42:04",
"Id": "6e2c723b-8f6e-47f4-8c60-fa23ef3fccee",
"Operation": "Add owner to application.",
"OrganizationId": "48203edf-5d2c-45f2-8123-a368cc8b0e51",
"RecordType": 8,
"ResultStatus": "Success",
"UserKey": "1003BFFD98415B4E@contoso.onmicrosoft.com",
"UserType": 0,
"Version": 1,
"Workload": "AzureActiveDirectory",
"ObjectId": "user2@contoso.onmicrosoft.com",
"UserId": "user@contoso.onmicrosoft.com",
"AzureActiveDirectoryEventType": 1,
"ExtendedProperties": [
{
"Name": "additionalDetails",
"Value": {
"User-Agent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Safari/537.36"
}
},
{
"Name": "extendedAuditEventCategory",
"Value": "Application"
}
],
"ModifiedProperties": [
{
"Name": "Application.ObjectID",
"NewValue": "a2d68f8b-ab9f-47ac-934f-b966c3ac134f",
"OldValue": ""
},
{
"Name": "Application.DisplayName",
"NewValue": "TestApp2",
"OldValue": ""
},
{
"Name": "Application.AppId",
"NewValue": "95106c0e-3519-450e-8e38-7f326d873454",
"OldValue": ""
}
],
"Actor": [
{
"ID": "user@contoso.onmicrosoft.com",
"Type": 5
},
{
"ID": "1003BFFD98415B4E",
"Type": 3
},
{
"ID": "18ed3507-a475-4ccb-b669-d66bc9f2a36e",
"Type": 2
},
{
"ID": "User_e4c722ac-3b83-478d-8f52-c388885dc30f",
"Type": 2
},
{
"ID": "e4c722ac-3b83-478d-8f52-c388885dc30f",
"Type": 2
},
{
"ID": "User",
"Type": 2
}
],
"ActorContextId": "48203edf-5d2c-45f2-8123-a368cc8b0e51",
"InterSystemsId": "3f6a58c5-2fba-401d-b137-82b860830213",
"IntraSystemId": "e8034ddc-0ca3-4aca-996c-1dc6dee48679",
"Target": [
{
"ID": "User_57e4bd36-9722-4a4a-9729-7203d8e00b72",
"Type": 2
},
{
"ID": "57e4bd36-9722-4a4a-9729-7203d8e00b72",
"Type": 2
},
{
"ID": "User",
"Type": 2
},
{
"ID": "user2@contoso.onmicrosoft.com",
"Type": 5
},
{
"ID": "10032002CC029AE9",
"Type": 3
}
],
"TargetContextId": "48203edf-5d2c-45f2-8123-a368cc8b0e51"
}
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Splunk #
T1098
References #
Add owner to group.
#Description
An owner was added to a group.
Example Audit Record #
{
"Actor": [
{
"ID": "adminuser@example.onmicrosoft.com",
"Type": 5
},
{
"ID": 1111111111111111,
"Type": 3
},
{
"ID": "Microsoft Teams Services",
"Type": 1
},
{
"ID": "cc15fd57-2c6c-4117-a88c-83b1d56b4bbe",
"Type": 2
},
{
"ID": "User_11111111-1111-1111-1111-111111111111",
"Type": 2
},
{
"ID": "11111111-1111-1111-1111-111111111111",
"Type": 2
},
{
"ID": "User",
"Type": 2
},
{
"ID": "NotAgentic",
"Type": 2
}
],
"ActorContextId": "00000000-0000-0000-0000-000000000001",
"AzureActiveDirectoryEventType": 1,
"CreationTime": "2026-07-03T01:56:53Z",
"ExtendedProperties": [
{
"Name": "additionalDetails",
"Value": {
"User-Agent": "TeamsMiddleTier/1.0a$*+"
}
},
{
"Name": "extendedAuditEventCategory",
"Value": "Group"
}
],
"Id": "752ea005-96c5-4c55-83bb-7f3f6ed2b632",
"InterSystemsId": "5d996715-22d3-4d25-b7ef-6ffae2513809",
"IntraSystemId": "f4df435a-dd38-432e-a44b-e2ceebc83e0c",
"ModifiedProperties": [
{
"Name": "Group.ObjectID",
"NewValue": "324441a1-2f31-4d13-9d24-c24ad8bf950b",
"OldValue": ""
},
{
"Name": "Group.DisplayName",
"NewValue": "dw-harness-a9dd06c7",
"OldValue": ""
},
{
"Name": "ActorId.ServicePrincipalNames",
"NewValue": "cc15fd57-2c6c-4117-a88c-83b1d56b4bbe;https://api.spaces.skype.com/;https://teams.microsoft.com;https://api.spaces.skype.com;https://api.gcc.teams.microsoft.com;https://teams.microsoft.com/;https://middletier.dod.teams.microsoft.us;https://middletier.gov.teams.microsoft.us;https://teams.cloud.microsoft",
"OldValue": ""
},
{
"Name": "SPN",
"NewValue": "cc15fd57-2c6c-4117-a88c-83b1d56b4bbe;https://api.spaces.skype.com/;https://teams.microsoft.com;https://api.spaces.skype.com;https://api.gcc.teams.microsoft.com;https://teams.microsoft.com/;https://middletier.dod.teams.microsoft.us;https://middletier.gov.teams.microsoft.us;https://teams.cloud.microsoft",
"OldValue": ""
}
],
"ObjectId": "adminuser@example.onmicrosoft.com",
"Operation": "Add owner to group.",
"OrganizationId": "00000000-0000-0000-0000-000000000001",
"RecordType": 8,
"ResultStatus": "Success",
"Target": [
{
"ID": "User_11111111-1111-1111-1111-111111111111",
"Type": 2
},
{
"ID": "11111111-1111-1111-1111-111111111111",
"Type": 2
},
{
"ID": "User",
"Type": 2
},
{
"ID": "NotAgentic",
"Type": 2
},
{
"ID": "adminuser@example.onmicrosoft.com",
"Type": 5
},
{
"ID": 1111111111111111,
"Type": 3
}
],
"TargetContextId": "00000000-0000-0000-0000-000000000001",
"UserId": "adminuser@example.onmicrosoft.com",
"UserKey": "1111111111111111@example.onmicrosoft.com",
"UserType": 0,
"Version": 1,
"Workload": "AzureActiveDirectory"
}
References #
Add permission grant policy.
#Description
Add permission grant policy. activity in Microsoft Entra ID, recorded in the Unified Audit Log (observed in first-party capture).
Example Audit Record #
{
"Actor": [
{
"ID": "adminuser@example.onmicrosoft.com",
"Type": 5
},
{
"ID": 1111111111111111,
"Type": 3
},
{
"ID": "User_aaaaaaaa-0000-0000-0000-000000000001",
"Type": 2
},
{
"ID": "aaaaaaaa-0000-0000-0000-000000000001",
"Type": 2
},
{
"ID": "User",
"Type": 2
},
{
"ID": "NotAgentic",
"Type": 2
}
],
"ActorContextId": "11111111-1111-1111-1111-111111111111",
"AzureActiveDirectoryEventType": 1,
"CreationDate": "2026-07-03T01:53:05",
"CreationTime": "2026-07-03T01:53:05",
"ExtendedProperties": [
{
"Name": "additionalDetails",
"Value": {
"User-Agent": "python/3.13.9 (Linux-6.1.0-41-amd64-x86_64-with-glibc2.36) AZURECLI/2.82.0 (DEB)"
}
},
{
"Name": "extendedAuditEventCategory",
"Value": "PermissionGrantPolicy"
}
],
"Id": "370b6676-3b9c-44be-8b4b-632f54c22b5c",
"InterSystemsId": "f964ab16-6186-467a-99c0-ef6fce7d43ff",
"IntraSystemId": "00000000-0000-0000-0000-000000000000",
"ModifiedProperties": [
{
"Name": "PermissionGrantPolicy",
"NewValue": {
"EncodingVersion": 2,
"Id": "dwharn-pgp-78619d48",
"Includes": [],
"Excludes": [],
"DisplayName": "dw-harness-pgp-78619d48",
"Description": "harness",
"IncludeAllPreApprovedApplications": false,
"ConsentResourceScopeType": "tenant"
},
"OldValue": ""
}
],
"ObjectId": "PermissionGrantPolicy_82aca392-bf62-49e7-a864-e071ba0e544d",
"Operation": "Add permission grant policy.",
"Operations": "Add permission grant policy.",
"OrganizationId": "11111111-1111-1111-1111-111111111111",
"RecordType": "AzureActiveDirectory",
"ResultStatus": "Success",
"Target": [
{
"ID": "PermissionGrantPolicy_82aca392-bf62-49e7-a864-e071ba0e544d",
"Type": 2
},
{
"ID": "82aca392-bf62-49e7-a864-e071ba0e544d",
"Type": 2
},
{
"ID": "Other",
"Type": 2
}
],
"TargetContextId": "11111111-1111-1111-1111-111111111111",
"UserId": "adminuser@example.onmicrosoft.com",
"UserKey": "1111111111111111@example.onmicrosoft.com",
"UserType": "Regular",
"Version": 1,
"Workload": "AzureActiveDirectory"
}
References #
Add policy.
#Description
A directory policy object was created.
Example Audit Record #
{
"Actor": [
{
"ID": "adminuser@example.onmicrosoft.com",
"Type": 5
},
{
"ID": 1111111111111111,
"Type": 3
},
{
"ID": "User_11111111-1111-1111-1111-111111111111",
"Type": 2
},
{
"ID": "11111111-1111-1111-1111-111111111111",
"Type": 2
},
{
"ID": "User",
"Type": 2
},
{
"ID": "NotAgentic",
"Type": 2
}
],
"ActorContextId": "00000000-0000-0000-0000-000000000001",
"AzureActiveDirectoryEventType": 1,
"CreationTime": "2026-07-03T03:22:52Z",
"ExtendedProperties": [
{
"Name": "additionalDetails",
"Value": {
"User-Agent": "python/3.13.9 (Linux-6.1.0-41-amd64-x86_64-with-glibc2.36) AZURECLI/2.82.0 (DEB)"
}
},
{
"Name": "extendedAuditEventCategory",
"Value": "Policy"
}
],
"Id": "7738b439-5a87-4fd7-ac1f-d0969ab9a76b",
"InterSystemsId": "5f65aed3-e4d0-4004-8a8b-e5ea8af701ef",
"IntraSystemId": "8f8eb1aa-47fb-42b4-933f-ec8e4d7bd654",
"ModifiedProperties": [
{
"Name": "DisplayName",
"NewValue": [
"dw-harness-cmp-2fe5ab51"
],
"OldValue": []
},
{
"Name": "PolicyType",
"NewValue": [
"ClaimsMappingPolicy"
],
"OldValue": []
},
{
"Name": "Included Updated Properties",
"NewValue": "DisplayName, PolicyType",
"OldValue": ""
}
],
"ObjectId": "Policy_f3feb286-060d-4879-a185-739c2cd4c8f5",
"Operation": "Add policy.",
"OrganizationId": "00000000-0000-0000-0000-000000000001",
"RecordType": 8,
"ResultStatus": "Success",
"Target": [
{
"ID": "Policy_f3feb286-060d-4879-a185-739c2cd4c8f5",
"Type": 2
},
{
"ID": "f3feb286-060d-4879-a185-739c2cd4c8f5",
"Type": 2
},
{
"ID": "Policy",
"Type": 2
},
{
"ID": "dw-harness-cmp-2fe5ab51",
"Type": 1
}
],
"TargetContextId": "00000000-0000-0000-0000-000000000001",
"UserId": "adminuser@example.onmicrosoft.com",
"UserKey": "1111111111111111@example.onmicrosoft.com",
"UserType": 0,
"Version": 1,
"Workload": "AzureActiveDirectory"
}
References #
Add registered users to device.
#Equivalent operation in the other pipeline: Add registered users to device (Entra ID directory audit)
Description
Registered users were added to a device object in Azure Active Directory (the UAL operation string includes a trailing period).
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Elastic #
T1098, T1098.005, T1528, T1566, T1566.002
References #
Add role definition.
#Description
Add role definition. activity in Microsoft Entra ID, recorded in the Unified Audit Log (observed in first-party capture).
Example Audit Record #
{
"Actor": [
{
"ID": "adminuser@example.onmicrosoft.com",
"Type": 5
},
{
"ID": 1111111111111111,
"Type": 3
},
{
"ID": "User_aaaaaaaa-0000-0000-0000-000000000001",
"Type": 2
},
{
"ID": "aaaaaaaa-0000-0000-0000-000000000001",
"Type": 2
},
{
"ID": "User",
"Type": 2
},
{
"ID": "NotAgentic",
"Type": 2
}
],
"ActorContextId": "11111111-1111-1111-1111-111111111111",
"AzureActiveDirectoryEventType": 1,
"CreationDate": "2026-07-03T03:22:47",
"CreationTime": "2026-07-03T03:22:47",
"ExtendedProperties": [
{
"Name": "additionalDetails",
"Value": {
"User-Agent": "python/3.13.9 (Linux-6.1.0-41-amd64-x86_64-with-glibc2.36) AZURECLI/2.82.0 (DEB)"
}
},
{
"Name": "extendedAuditEventCategory",
"Value": "RoleDefinition"
}
],
"Id": "8d7f0c90-5645-4809-9364-66b1ce1abfc4",
"InterSystemsId": "c631a647-66b1-40d3-9a58-7f616841f98f",
"IntraSystemId": "3d6dde62-7d73-4472-b528-c46ec2c4975e",
"ModifiedProperties": [
{
"Name": "DisplayName",
"NewValue": [
"dw-harness-role-2fe5ab51"
],
"OldValue": []
},
{
"Name": "GrantedPermissions",
"NewValue": [
{
"Actions": [
{
"ResourceCategory": "AadDirectory",
"ResourceType": "Group",
"TaskType": "Read",
"ReadPropertySet": "Basic",
"WritePropertySet": "None",
"TaskTypeSubsetName": null
}
],
"Condition": null,
"ScopeConstraints": [],
"IsPrivileged": false
}
],
"OldValue": []
},
{
"Name": "Included Updated Properties",
"NewValue": "DisplayName, GrantedPermissions",
"OldValue": ""
}
],
"ObjectId": "RoleDefinition_799abf44-b19b-4605-9606-2125d16ff1c8",
"Operation": "Add role definition.",
"Operations": "Add role definition.",
"OrganizationId": "11111111-1111-1111-1111-111111111111",
"RecordType": "AzureActiveDirectory",
"ResultStatus": "Success",
"Target": [
{
"ID": "RoleDefinition_799abf44-b19b-4605-9606-2125d16ff1c8",
"Type": 2
},
{
"ID": "799abf44-b19b-4605-9606-2125d16ff1c8",
"Type": 2
},
{
"ID": "Other",
"Type": 2
},
{
"ID": "dw-harness-role-2fe5ab51",
"Type": 1
}
],
"TargetContextId": "11111111-1111-1111-1111-111111111111",
"UserId": "adminuser@example.onmicrosoft.com",
"UserKey": "1111111111111111@example.onmicrosoft.com",
"UserType": "Regular",
"Version": 1,
"Workload": "AzureActiveDirectory"
}
References #
Add service principal credentials.
#Description
Credentials were added to a service principal (common persistence technique).
Example Audit Record #
{
"Actor": [
{
"ID": "rodsoto@rodsoto.onmicrosoft.com",
"Type": 5
},
{
"ID": "10037FFEA938FB92",
"Type": 3
},
{
"ID": "74658136-14ec-4630-ad9b-26e160ff0fc6",
"Type": 2
},
{
"ID": "User_bfb8c366-0406-41a5-b3e3-328f4a3b4484",
"Type": 2
},
{
"ID": "bfb8c366-0406-41a5-b3e3-328f4a3b4484",
"Type": 2
},
{
"ID": "User",
"Type": 2
}
],
"ActorContextId": "0e8108b1-18e9-41a4-961b-dfcddf92ef08",
"ActorIpAddress": "40.124.84.4",
"AzureActiveDirectoryEventType": 1,
"ClientIP": "40.124.84.4",
"CreationTime": "2021-01-20T03:10:09",
"ExtendedProperties": [
{
"Name": "additionalDetails",
"Value": {}
},
{
"Name": "extendedAuditEventCategory",
"Value": "ServicePrincipal"
}
],
"Id": "e312b173-45bb-469f-bf3d-cc8709a14dd6",
"InterSystemsId": "f2a86789-6357-4f08-9ff7-d6d2d86cbde0",
"IntraSystemId": "6fc81447-9c94-4734-8bd7-307bb699c098",
"ModifiedProperties": [
{
"Name": "KeyDescription",
"NewValue": [
"[KeyIdentifier=f4f7a4fb-6445-4b38-885f-fc634a60f805,KeyType=AsymmetricX509Cert,KeyUsage=Verify,DisplayName=CN=Microsoft Azure Federated SSO Certificate]",
"[KeyIdentifier=d90a353c-2b06-44ad-a436-f54e2ba8129c,KeyType=X509CertAndPassword,KeyUsage=Sign,DisplayName=CN=Microsoft Azure Federated SSO Certificate]",
"[KeyIdentifier=c34a9808-c377-47e9-b01f-545ec1129ab2,KeyType=X509CertAndPassword,KeyUsage=Sign,DisplayName=CN=adfs.attackrange.local]",
"[KeyIdentifier=e420d926-6608-4844-9a32-03cc400481c2,KeyType=AsymmetricX509Cert,KeyUsage=Verify,DisplayName=CN=adfs.attackrange.local]"
],
"OldValue": [
"[KeyIdentifier=d90a353c-2b06-44ad-a436-f54e2ba8129c,KeyType=X509CertAndPassword,KeyUsage=Sign,DisplayName=CN=Microsoft Azure Federated SSO Certificate]",
"[KeyIdentifier=f4f7a4fb-6445-4b38-885f-fc634a60f805,KeyType=AsymmetricX509Cert,KeyUsage=Verify,DisplayName=CN=Microsoft Azure Federated SSO Certificate]"
]
},
{
"Name": "Included Updated Properties",
"NewValue": "KeyDescription",
"OldValue": ""
},
{
"Name": "TargetId.ServicePrincipalNames",
"NewValue": "https://signin.aws.amazon.com/saml;3e71560f-3e31-45ab-b439-46328fe55b88",
"OldValue": ""
}
],
"ObjectId": "https://signin.aws.amazon.com/saml;3e71560f-3e31-45ab-b439-46328fe55b88",
"Operation": "Add service principal credentials.",
"OrganizationId": "0e8108b1-18e9-41a4-961b-dfcddf92ef08",
"RecordType": 8,
"ResultStatus": "Success",
"Target": [
{
"ID": "ServicePrincipal_9fd10db9-dfe2-4d74-a724-c837eb8764d9",
"Type": 2
},
{
"ID": "9fd10db9-dfe2-4d74-a724-c837eb8764d9",
"Type": 2
},
{
"ID": "ServicePrincipal",
"Type": 2
},
{
"ID": "Amazon Web Services (AWS)",
"Type": 1
},
{
"ID": "3e71560f-3e31-45ab-b439-46328fe55b88",
"Type": 2
},
{
"ID": "https://signin.aws.amazon.com/saml;3e71560f-3e31-45ab-b439-46328fe55b88",
"Type": 4
}
],
"TargetContextId": "0e8108b1-18e9-41a4-961b-dfcddf92ef08",
"UserId": "rodsoto@rodsoto.onmicrosoft.com",
"UserKey": "10037FFEA938FB92@rodsoto.onmicrosoft.com",
"UserType": 0,
"Version": 1,
"Workload": "AzureActiveDirectory"
}
References #
Add service principal.
#Description
Microsoft Entra ID (Azure Active Directory) audit activity in the ApplicationManagement category, recorded in the Office 365 Unified Audit Log.
Example Audit Record #
{
"CreationTime": "2023-07-20T06:39:58",
"Id": "152e701f-3a83-4553-8ef6-e04cb5691976",
"Operation": "Add service principal.",
"OrganizationId": "a417c578-c7ee-480d-a225-d48057e74df5",
"RecordType": 8,
"ResultStatus": "Success",
"UserKey": "testing@office365.onmicrosoft.com",
"UserType": 0,
"Version": 1,
"Workload": "AzureActiveDirectory",
"ObjectId": "5cde9487-f84d-44c4-9715-2e856b6811ef",
"UserId": "Testeruser@office365.onmicrosoft.com",
"AzureActiveDirectoryEventType": 1,
"ExtendedProperties": [
{
"Name": "additionalDetails",
"Value": {
"User-Agent": "Mozilla/5.0 Test Lab Machine) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/114.0.0.0 Safari/537.36",
"AppId": "5cde9487-f84d-44c4-9715-2e856b6811ef"
}
},
{
"Name": "extendedAuditEventCategory",
"Value": "ServicePrincipal"
}
],
"ModifiedProperties": [
{
"Name": "AccountEnabled",
"NewValue": [
true
],
"OldValue": []
},
{
"Name": "AppAddress",
"NewValue": [
{
"AddressType": 0,
"Address": "https://10.1.67.69/rest/handler/microsoftteams_6ba1906f-5899-44df-bb65-1bee4df8ca3c/test/result",
"ReplyAddressClientType": 1,
"ReplyAddressIndex": null,
"IsReplyAddressDefault": false
}
],
"OldValue": []
},
{
"Name": "AppPrincipalId",
"NewValue": [
"5cde9487-f84d-44c4-9715-2e856b6811ef"
],
"OldValue": []
},
{
"Name": "DisplayName",
"NewValue": [
"test-msteams"
],
"OldValue": []
},
{
"Name": "ServicePrincipalName",
"NewValue": [
"5cde9487-f84d-44c4-9715-2e856b6811ef"
],
"OldValue": []
},
{
"Name": "Credential",
"NewValue": [
{
"CredentialType": 2,
"KeyStoreId": "291154f0-a9f5-45bb-87be-9c8ee5b6d62c",
"KeyGroupId": "291154f0-a9f5-45bb-87be-9c8ee5b6d62c"
}
],
"OldValue": []
},
{
"Name": "Included Updated Properties",
"NewValue": "AccountEnabled, AppAddress, AppPrincipalId, DisplayName, ServicePrincipalName, Credential",
"OldValue": ""
},
{
"Name": "TargetId.ServicePrincipalNames",
"NewValue": "5cde9487-f84d-44c4-9715-2e856b6811ef",
"OldValue": ""
}
],
"Actor": [
{
"ID": "Testeruser@office365.onmicrosoft.com",
"Type": 5
},
{
"ID": "1003BFFD98415B4E",
"Type": 3
},
{
"ID": "18ed3507-a475-4ccb-b669-d66bc9f2a36e",
"Type": 2
},
{
"ID": "User_e4c722ac-3b83-478d-8f52-c388885dc30f",
"Type": 2
},
{
"ID": "e4c722ac-3b83-478d-8f52-c388885dc30f",
"Type": 2
},
{
"ID": "User",
"Type": 2
}
],
"ActorContextId": "a417c578-c7ee-480d-a225-d48057e74df5",
"InterSystemsId": "6dbb2be0-aa75-477d-b231-aaf418c665e7",
"IntraSystemId": "547aa851-c370-4ce7-aa40-47c576a5bcd3",
"Target": [
{
"ID": "ServicePrincipal_9669aa7b-3517-46d5-a7c4-b040de9ee527",
"Type": 2
},
{
"ID": "9669aa7b-3517-46d5-a7c4-b040de9ee527",
"Type": 2
},
{
"ID": "ServicePrincipal",
"Type": 2
},
{
"ID": "test-msteams",
"Type": 1
},
{
"ID": "5cde9487-f84d-44c4-9715-2e856b6811ef",
"Type": 2
},
{
"ID": "5cde9487-f84d-44c4-9715-2e856b6811ef",
"Type": 4
}
],
"TargetContextId": "a417c578-c7ee-480d-a225-d48057e74df5"
}
Common Indicators #
Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.
| Field | Kind | Value | Rules | Vendors |
|---|---|---|---|---|
unique_apps (splunk rule field) | gt | 3 | 2 rules | splunk |
userType (splunk rule field) | eq | serviceprincipal | 1 rule | splunk |
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Splunk #
T1136, T1136.003T1136, T1136.003
References #
Add unverified domain.
#Description
An unverified custom domain was added to the tenant.
Example Audit Record #
{
"CreationTime": "2023-07-04T01:42:56",
"Id": "abfe2230-72b4-4eb1-9361-9d9aee0fcc57",
"Operation": "Add unverified domain.",
"OrganizationId": "a417c578-c7ee-480d-a225-d48057e74df5",
"RecordType": 8,
"ResultStatus": "Success",
"UserKey": "testuser@testazure.onmicrosoft.com",
"UserType": 0,
"Version": 1,
"Workload": "AzureActiveDirectory",
"ObjectId": "Not Available",
"UserId": "Tester@testazure.onmicrosoft.com",
"AzureActiveDirectoryEventType": 1,
"ExtendedProperties": [
{
"Name": "additionalDetails",
"Value": {
"User-Agent": "Mozilla/5.0 (Test Lab - STRT 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/114.0.0.0 Safari/537.36"
}
},
{
"Name": "extendedAuditEventCategory",
"Value": "Domain"
}
],
"ModifiedProperties": [
{
"Name": "Name",
"NewValue": [
"attackrange.local"
],
"OldValue": [
""
]
},
{
"Name": "LiveType",
"NewValue": [
"Managed"
],
"OldValue": [
"None"
]
},
{
"Name": "Included Updated Properties",
"NewValue": "Name,LiveType",
"OldValue": ""
}
],
"Actor": [
{
"ID": "Tester@testazure.onmicrosoft.com",
"Type": 5
},
{
"ID": "1003BFFD98415B4E",
"Type": 3
},
{
"ID": "74658136-14ec-4630-ad9b-26e160ff0fc6",
"Type": 2
},
{
"ID": "User_e4c722ac-3b83-478d-8f52-c388885dc30f",
"Type": 2
},
{
"ID": "e4c722ac-3b83-478d-8f52-c388885dc30f",
"Type": 2
},
{
"ID": "User",
"Type": 2
}
],
"ActorContextId": "a417c578-c7ee-480d-a225-d48057e74df5",
"InterSystemsId": "a8d61658-9949-4dd8-9191-26bf59021da3",
"IntraSystemId": "3031bdcb-6da7-4c15-8546-3cdf51d2400c",
"Target": [
{
"ID": "attackrange.local",
"Type": 1
}
],
"TargetContextId": "a417c578-c7ee-480d-a225-d48057e74df5"
}
References #
Add user.
#Description
A new user account was created in the directory.
Example Audit Record #
{
"Actor": [
{
"ID": "victim@attack_range.lan",
"Type": 5
},
{
"ID": "100300009FBEAAAA",
"Type": 3
},
{
"ID": "Microsoft B2B Admin Worker",
"Type": 1
},
{
"ID": "1e2ca66a-c176-45ea-a877-e87f7231e0ee",
"Type": 2
},
{
"ID": "User_42f229de-3fea-423d-b3aa-23034e486c40",
"Type": 2
},
{
"ID": "42f229de-3fea-423d-b3aa-23034e486c40",
"Type": 2
},
{
"ID": "User",
"Type": 2
}
],
"ActorContextId": "6915b1e0-b081-4829-8866-f1a3e883a9ae",
"ActorIpAddress": "52.252.209.205",
"AzureActiveDirectoryEventType": 1,
"ClientIP": "52.252.209.205",
"CreationTime": "2024-03-20T16:38:17",
"ExtendedProperties": [
{
"Name": "additionalDetails",
"Value": {
"User-Agent": "Microsoft Azure Graph Client Library 1.0"
}
},
{
"Name": "extendedAuditEventCategory",
"Value": "User"
}
],
"Id": "86da0fd3-df67-4d91-b151-d371eca7bd3e",
"InterSystemsId": "fb44cdfe-a07f-4a8e-aebf-90c5799bfed9",
"IntraSystemId": "1916c159-1ad1-44d6-935a-3ee83cafdb4e",
"ModifiedProperties": [
{
"Name": "AccountEnabled",
"NewValue": [
true
],
"OldValue": []
},
{
"Name": "CreationType",
"NewValue": [
"Invitation"
],
"OldValue": []
},
{
"Name": "DisplayName",
"NewValue": [
"attacker"
],
"OldValue": []
},
{
"Name": "InviteTicket",
"NewValue": [
{
"Type": 1,
"Ticket": "c53f6130-9c7b-4670-ba45-a20f4e7001f3"
}
],
"OldValue": []
},
{
"Name": "MailNickname",
"NewValue": [
"attacker_bad_guy.lol#EXT#"
],
"OldValue": []
},
{
"Name": "OtherMail",
"NewValue": [
"attacker@bad_guy.lol"
],
"OldValue": []
},
{
"Name": "ProxyAddresses",
"NewValue": [
"SMTP:attacker@bad_guy.lol"
],
"OldValue": []
},
{
"Name": "StsRefreshTokensValidFrom",
"NewValue": [
"2024-03-20T16:38:17Z"
],
"OldValue": []
},
{
"Name": "UserPrincipalName",
"NewValue": [
"attacker_bad_guy.lol#EXT#@attack_range.onmicrosoft.com"
],
"OldValue": []
},
{
"Name": "UserState",
"NewValue": [
"PendingAcceptance"
],
"OldValue": []
},
{
"Name": "UserStateChangedOn",
"NewValue": [
"2024-03-20T16:38:17Z"
],
"OldValue": []
},
{
"Name": "UserType",
"NewValue": [
"Guest"
],
"OldValue": []
},
{
"Name": "Included Updated Properties",
"NewValue": "AccountEnabled, CreationType, DisplayName, InviteTicket, MailNickname, OtherMail, ProxyAddresses, StsRefreshTokensValidFrom, UserPrincipalName, UserState, UserStateChangedOn, UserType",
"OldValue": ""
},
{
"Name": "ActorId.ServicePrincipalNames",
"NewValue": "https://msb2badminworker.usgovcloudapp.net/;https://msb2badminworker.cloudapp.net/;1e2ca66a-c176-45ea-a877-e87f7231e0ee",
"OldValue": ""
},
{
"Name": "SPN",
"NewValue": "https://msb2badminworker.usgovcloudapp.net/;https://msb2badminworker.cloudapp.net/;1e2ca66a-c176-45ea-a877-e87f7231e0ee",
"OldValue": ""
}
],
"ObjectId": "attacker_bad_guy.lol#EXT#@attack_range.onmicrosoft.com",
"Operation": "Add user.",
"OrganizationId": "6915b1e0-b081-4829-8866-f1a3e883a9ae",
"RecordType": 8,
"ResultStatus": "Success",
"Target": [
{
"ID": "User_001b519f-c2e6-4c5e-946f-85b0bcbeb2fd",
"Type": 2
},
{
"ID": "001b519f-c2e6-4c5e-946f-85b0bcbeb2fd",
"Type": 2
},
{
"ID": "User",
"Type": 2
},
{
"ID": "attacker_bad_guy.lol#EXT#@attack_range.onmicrosoft.com",
"Type": 5
},
{
"ID": "10032003656161CE",
"Type": 3
}
],
"TargetContextId": "6915b1e0-b081-4829-8866-f1a3e883a9ae",
"UserId": "victim@attack_range.lan",
"UserKey": "100300009FBEAAAA@attack_range.lan",
"UserType": 0,
"Version": 1,
"Workload": "AzureActiveDirectory"
}
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Splunk #
T1136, T1136.003YARA-L #
T1098, T1098.003↳ also matches Add member to role.
References #
Change user license.
#Description
Microsoft Entra ID (Azure Active Directory) audit activity in the UserManagement category, recorded in the Office 365 Unified Audit Log.
Example Audit Record #
{
"CreationTime": "2023-09-11T15:55:46",
"Id": "8c9c938b-79d5-44b1-8581-de51fafa8216",
"Operation": "Change user license.",
"OrganizationId": "bbad9541-eb53-4533-bcef-2b76182c3b75",
"RecordType": 8,
"ResultStatus": "Success",
"UserKey": "1003BFFD98415B4E@splunkresearch.onmicrosoft.com",
"UserType": 0,
"Version": 1,
"Workload": "AzureActiveDirectory",
"ObjectId": "victimUser@splunkresearch.onmicrosoft.com",
"UserId": "evilUser@splunkresearch.onmicrosoft.com",
"AzureActiveDirectoryEventType": 1,
"ExtendedProperties": [
{
"Name": "additionalDetails",
"Value": {
"id": "64c07906-cb25-4d37-b38c-a862f2e49671",
"seq": "1",
"b": "{\"targetUpdatedProperties\":\"[{\\\"Name\\\":\\\"AssignedLicense\\\",\\\"OldValue\\\":[\\\"[SkuName=SPE_E5, AccountId=bbad9541-eb53-4533-bcef-2b76182c3b75, SkuId=06ebc4ee-1bb5-47dd-8120-11324bc54e06, DisabledPlans=[M365_ADVANCED_AUDITING]]\\\"],\\\"NewValue\\\":[\\\"[SkuName=SPE_E5, AccountId=bbad9541-eb53-4533-bcef-2b76182c3b75, SkuId=06ebc4ee-1bb5-47dd-8120-11324bc54e06, DisabledPlans=[]]\\\"]},{\\\"Name\\\":\\\"AssignedPlan\\\",\\\"OldValue\\\":[{\\\"SubscribedPlanId\\\":\\\"023234e8-a87e-4ba4-8814-da5609cd4426\\\",\\\"ServiceInstance\\\":\\\"TeamspaceAPI/NA001\\\",\\\"CapabilityStatus\\\":0,\\\"AssignedTimestamp\\\":\\\"2023-07-27T17:47:38Z\\\",\\\"InitialState\\\":null,\\\"Capability\\\":null,\\\"ServicePlanId\\\":\\\"57ff2da0-773e-42df-b2af-ffb7a2317929\\\"},{\\\"SubscribedPlanId\\\":\\\"072b9cb4-3176-43e6-882e-49b8836bf50b\\\",\\\"ServiceInstance\\\":\\\"YammerEnterprise/NA008\\\",\\\"CapabilityStatus\\\":0,\\\"AssignedTimestamp\\\":\\\"2023-07-27T17:47:38Z\\\",\\\"InitialState\\\":null,\\\"Capability\\\":null,\\\"ServicePlanId\\\":\\\"7547a3fe-08ee-4ccb-b430-5077c5041653\\\"},{\\\"SubscribedPlanId\\\":\\\"0a63ee3c-4c54-462d-a1c2-5766416685fb\\\",\\\"ServiceInstance\\\":\\\"YammerEnterprise/NA008\\\",\\\"CapabilityStatus\\\":0,\\\"AssignedTimestamp\\\":\\\"2023-07-27T17:47:38Z\\\",\\\"InitialState\\\":null,\\\"Capability\\\":null,\\\"ServicePlanId\\\":\\\"a82fbf69-b4d7-49f4-83a6-915b2cf354f4\\\"},{\\\"SubscribedPlanId\\\":\\\"0cd40d66-4fdd-4871-9af2-3e383b200b5d\\\",\\\"ServiceInstance\\\":\\\"CRM/NA02\\\",\\\"CapabilityStatus\\\":0,\\\"AssignedTimestamp\\\":\\\"2023-07-27T17:47:38Z\\\",\\\"InitialState\\\":null,\\\"Capability\\\":null,\\\"ServicePlanId\\\":\\\"afa73018-811e-46e9-988f-f75d2b1b8430\\\"},{\\\"SubscribedPlanId\\\":\\\"14faac42-bc6a-4c64-b309-6251c4cb09e2\\\",\\\"ServiceInstance\\\":\\\"exchange/namprd18-002-01\\\",\\\"CapabilityStatus\\\":0,\\\"AssignedTimestamp\\\":\\\"2023-07-27T17:47:38Z\\\",\\\"InitialState\\\":null,\\\"Capability\\\":null,\\\"ServicePlanId\\\":\\\"5136a095-5cf0-4aff-bec3-e84448b38ea5\\\"},{\\\"SubscribedPlanId\\\":\\\"1be931f9-9c0d-4148-a4ad-b61c221bc223\\\",\\\"ServiceInstance\\\":\\\"MicrosoftThreatProtection/NA001\\\",\\\"CapabilityStatus\\\":0,\\\"AssignedTimestamp\\\":\\\"2023-07-27T17:47:38Z\\\",\\\"InitialState\\\":null,\\\"Capability\\\":null,\\\"ServicePlanId\\\":\\\"bf28f719-7844-4079-9c78-c1307898e192\\\"},{\\\"SubscribedPlanId\\\":\\\"1cfbcaa7-abeb-483d-a197-7e36348ed0f8\\\",\\\"ServiceInstance\\\":\\\"exchange/namprd18-002-01\\\",\\\"CapabilityStatus\\\":0,\\\"AssignedTimestamp\\\":\\\"2023-07-27T17:47:38Z\\\",\\\"InitialState\\\":null,\\\"Capability\\\":null,\\\"ServicePlanId\\\":\\\"efb0351d-3b08-4503-993d-383af8de41e3\\\"},{\\\"SubscribedPlanId\\\":\\\"213dbe99-be20-4464-af87-54d0094fd6ce\\\",\\\"ServiceInstance\\\":\\\"AADPremiumService/NA001\\\",\\\"CapabilityStatus\\\":0,\\\"AssignedTimestamp\\\":\\\"2023-07-27T17:47:38Z\\\",\\\"InitialState\\\":null,\\\"Capability\\\":null,\\\"ServicePlanId\\\":\\\"eec0eb4f-6444-4f95-aba0-50c24d67f998\\\"},{\\\"SubscribedPlanId\\\":\\\"21765469-dcd6-4192-ab8a-e3f6bd760822\\\",\\\"ServiceInstance\\\":\\\"WhiteboardServices/NA001\\\",\\\"CapabilityStatus\\\":3,\\\"AssignedTimestamp\\\":\\\"2023-07-27T17:41:21Z\\\",\\\"InitialState\\\":null,\\\"Capability\\\":null,\\\"ServicePlanId\\\":\\\"b8afc642-032e-4de5-8c0a-507a7bba7e5d\\\"},{\\\"SubscribedPlanId\\\":\\\"227b5826-9349-4504-97a3-81b1da2bbfbb\\\",\\\"ServiceInstance\\\":\\\"MicrosoftOffice/NorthAmerica1\\\",\\\"CapabilityStatus\\\":0,\\\"AssignedTimestamp\\\":\\\"2023-07-27T17:47:38Z\\\",\\\"InitialState\\\":null,\\\"Capability\\\":null,\\\"ServicePlanId\\\":\\\"531ee2f8-b1cb-453b-9c21-d2180d014ca5\\\"},{\\\"SubscribedPlanId\\\":\\\"23cab049-6eee-4aac-9595-f9b02af3373b\\\",\\\"ServiceInstance\\\":\\\"AzureAdvancedThreatAnalytics/NA001\\\",\\\"CapabilityStatus\\\":0,\\\"AssignedTimestamp\\\":\\\"2023-07-27T17:47:38Z\\\",\\\"InitialState\\\":null,\\\"Capability\\\":null,\\\"ServicePlanId\\\":\\\"14ab5db5-e6c4-4b20-b4bc-13e36fd2227f\\\"},{\\\"SubscribedPlanId\\\":\\\"26a3d64a-198f-465b-a641-c3f8266f1ea5\\\",\\\"ServiceInstance\\\":\\\"MicrosoftCommunicationsOnline/NOAM-2A-S2\\\",\\\"CapabilityStatus\\\":0,\\\"AssignedTimestamp\\\":\\\"2023-07-27T17:47:38Z\\\",\\\"InitialState\\\":null,\\\"Capability\\\":null,\\\"ServicePlanId\\\":\\\"4828c8ec-dc2e-4779-b502-87ac9ce28ab7\\\"},{\\\"SubscribedPlanId\\\":\\\"2a3c7121-f4fe-46d1-9b5f-e93c865bf6dc\\\",\\\"ServiceInstance\\\":\\\"MicrosoftCommunicationsOnline/NOAM-2A-S2\\\",\\\"CapabilityStatus\\\":0,\\\"AssignedTimestamp\\\":\\\"2023-07-27T17:47:38Z\\\",\\\"InitialState\\\":null,\\\"Capability\\\":null,\\\"ServicePlanId\\\":\\\"3e26ee1f-8a5f-4d52-aee2-b81ce45c8f40\\\"},{\\\"SubscribedPlanId\\\":\\\"2b092686-43fd-40d2-9f20-794390aa1c16\\\",\\\"ServiceInstance\\\":\\\"exchange/namprd18-002-01\\\",\\\"CapabilityStatus\\\":0,\\\"AssignedTimestamp\\\":\\\"2023-07-27T17:47:38Z\\\",\\\"InitialState\\\":null,\\\"Capability\\\":null,\\\"ServicePlanId\\\":\\\"c4801e8a-cb58-4c35-aca6-f2dcc106f287\\\"},{\\\"SubscribedPlanId\\\":\\\"2c310eeb-327e-4bfc-9235-69386c3a8ce1\\\",\\\"ServiceInstance\\\":\\\"Adallom/NA002\\\",\\\"CapabilityStatus\\\":0,\\\"AssignedTimestamp\\\":\\\"2023-07-27T17:47:38Z\\\",\\\"InitialState\\\":null,\\\"Capability\\\":null,\\\"ServicePlanId\\\":\\\"8c098270-9dd4-4350-9b30-ba4703f3b36b\\\"},{\\\"SubscribedPlanId\\\":\\\"378cc2d1-7489-4372-b3c0-2179a6e8c72d\\\",\\\"ServiceInstance\\\":\\\"SCO/PROD_AMSUA0102_02\\\",\\\"CapabilityStatus\\\":0,\\\"AssignedTimestamp\\\":\\\"2023-07-27T17:47:38Z\\\",\\\"InitialState\\\":null,\\\"Capability\\\":null,\\\"ServicePlanId\\\":\\\"c1ec4a95-1f05-45b3-a911-aa3fa01094f5\\\"},{\\\"SubscribedPlanId\\\":\\\"39d44552-2bd6-4599-803e-3ccfd4b6502a\\\",\\\"ServiceInstance\\\":\\\"exchange/namprd18-002-01\\\",\\\"CapabilityStatus\\\":0,\\\"AssignedTimestamp\\\":\\\"2023-07-27T17:47:38Z\\\",\\\"InitialState\\\":null,\\\"Capability\\\":null,\\\"ServicePlanId\\\":\\\"9d0c4ee5-e4a1-4625-ab39-d82b619b1a34\\\"},{\\\"SubscribedPlanId\\\":\\\"39e9d742-53f6-4acc-a844-4fa26478de82\\\",\\\"ServiceInstance\\\":\\\"exchange/namprd18-002-01\\\",\\\"CapabilityStatus\\\":0,\\\"AssignedTimestamp\\\":\\\"2023-07-27T17:47:38Z\\\",\\\"InitialState\\\":null,\\\"Capability\\\":null,\\\"ServicePlanId\\\":\\\"b1188c4c-1b36-4018-b48b-ee07604f6feb\\\"},{\\\"SubscribedPlanId\\\":\\\"3bdaaeba-01a4-4b77-ba29-54845686b4af\\\",\\\"ServiceInstance\\\":\\\"MicrosoftCommunicationsOnline/NOAM-2A-S2\\\",\\\"CapabilityStatus\\\":0,\\\"AssignedTimestamp\\\":\\\"2023-07-27T17:47:38Z\\\",\\\"InitialState\\\":null,\\\"Capability\\\":null,\\\"ServicePlanId\\\":\\\"0feaeb32-d00e-4d66-bd5a-43b5b83db82c\\\"},{\\\"SubscribedPlanId\\\":\\\"3f2de5ba-2779-4e4b-b720-7abc47df4af5\\\",\\\"ServiceInstance\\\":\\\"CRM/NA02\\\",\\\"CapabilityStatus\\\":0,\\\"AssignedTimestamp\\\":\\\"2023-07-27T17:47:38Z\\\",\\\"InitialState\\\":null,\\\"Capability\\\":null,\\\"ServicePlanId\\\":\\\"28b0fa46-c39a-4188-89e2-58e979a6b014\\\"},{\\\"SubscribedPlanId\\\":\\\"426015f6-326a-41d7-bae4-82254ed4578d\\\",\\\"ServiceInstance\\\":\\\"exchange/namprd18-002-01\\\",\\\"CapabilityStatus\\\":3,\\\"AssignedTimestamp\\\":\\\"2023-09-11T15:49:49Z\\\",\\\"InitialState\\\":null,\\\"Capability\\\":null,\\\"ServicePlanId\\\":\\\"2f442157-a11c-46b9-ae5b-6e39ff4e5849\\\"},{\\\"SubscribedPlanId\\\":\\\"42a3adf0-6a2c-44df-b8bc-e435eb6aeb73\\\",\\\"ServiceInstance\\\":\\\"exchange/namprd18-002-01\\\",\\\"CapabilityStatus\\\":0,\\\"AssignedTimestamp\\\":\\\"2023-07-27T17:47:38Z\\\",\\\"InitialState\\\":null,\\\"Capability\\\":null,\\\"ServicePlanId\\\":\\\"d2d51368-76c9-4317-ada2-a12c004c432f\\\"},{\\\"SubscribedPlanId\\\":\\\"4b4b9b47-92ef-462c-aa50-afb777483ef4\\\",\\\"ServiceInstance\\\":\\\"SharePoint/US-105-0015\\\",\\\"CapabilityStatus\\\":0,\\\"AssignedTimestamp\\\":\\\"2023-07-27T17:47:38Z\\\",\\\"InitialState\\\":null,\\\"Capability\\\":null,\\\"ServicePlanId\\\":\\\"e95bec33-7c88-4a70-8e19-b10bd9d0c014\\\"},{\\\"SubscribedPlanId\\\":\\\"4bd6d0f1-692a-4626-b03f-1d72feaa8d7c\\\",\\\"ServiceInstance\\\":\\\"Office365InsiderRisk/NA001\\\",\\\"CapabilityStatus\\\":0,\\\"AssignedTimestamp\\\":\\\"2023-07-27T17:47:38Z\\\",\\\"InitialState\\\":null,\\\"Capability\\\":null,\\\"ServicePlanId\\\":\\\"d587c7a3-bda9-4f99-8776-9bcf59c84f75\\\"},{\\\"SubscribedPlanId\\\":\\\"4fd93da9-971e-45ae-a2dc-51154f0d174e\\\",\\\"ServiceInstance\\\":\\\"SharePoint/US-105-0015\\\",\\\"CapabilityStatus\\\":0,\\\"AssignedTimestamp\\\":\\\"2023-07-27T17:47:38Z\\\",\\\"InitialState\\\":null,\\\"Capability\\\":null,\\\"ServicePlanId\\\":\\\"5dbe027f-2339-4123-9542-606e4d348a72\\\"},{\\\"SubscribedPlanId\\\":\\\"5013f49d-b578-4a2d-9106-4dd025ef97b9\\\",\\\"ServiceInstance\\\":\\\"RMSOnline/NA\\\",\\\"CapabilityStatus\\\":0,\\\"AssignedTimestamp\\\":\\\"2023-07-27T17:47:38Z\\\",\\\"InitialState\\\":null,\\\"Capability\\\":null,\\\"ServicePlanId\\\":\\\"5689bec4-755d-4753-8b61-40975025187c\\\"},{\\\"SubscribedPlanId\\\":\\\"52cc074b-6308-4a8e-9c6c-5d3ac6175b6c\\\",\\\"ServiceInstance\\\":\\\"ccibotsprod/NA001\\\",\\\"CapabilityStatus\\\":3,\\\"AssignedTimestamp\\\":\\\"2023-07-27T17:41:21Z\\\",\\\"InitialState\\\":null,\\\"Capability\\\":null,\\\"ServicePlanId\\\":\\\"0683001c-0492-4d59-9515-d9a6426b5813\\\"},{\\\"SubscribedPlanId\\\":\\\"5638cb0f-dcef-4ee1-977b-7f17c177c847\\\",\\\"ServiceInstance\\\":\\\"SharePoint/US-105-0015\\\",\\\"CapabilityStatus\\\":3,\\\"AssignedTimestamp\\\":\\\"2023-07-27T17:41:21Z\\\",\\\"InitialState\\\":null,\\\"Capability\\\":null,\\\"ServicePlanId\\\":\\\"c7699d2e-19aa-44de-8edf-1736da088ca1\\\"},{\\\"SubscribedPlanId\\\":\\\"5960bdc8-5438-48cd-ab81-9c8815046666\\\",\\\"ServiceInstance\\\":\\\"exchange/namprd18-002-01\\\",\\\"CapabilityStatus\\\":0,\\\"AssignedTimestamp\\\":\\\"2023-07-27T17:47:38Z\\\",\\\"InitialState\\\":null,\\\"Capability\\\":null,\\\"ServicePlanId\\\":\\\"65cc641f-cccd-4643-97e0-a17e3045e541\\\"},{\\\"SubscribedPlanId\\\":\\\"59956027-42b4-4311-b7f3-9de3c2f82f29\\\",\\\"ServiceInstance\\\":\\\"MicrosoftPrint/NA001\\\",\\\"CapabilityStatus\\\":0,\\\"AssignedTimestamp\\\":\\\"2023-07-27T17:47:38Z\\\",\\\"InitialState\\\":null,\\\"Capability\\\":null,\\\"ServicePlanId\\\":\\\"795f6fe0-cc4d-4773-b050-5dde4dc704c9\\\"},{\\\"SubscribedPlanId\\\":\\\"5edcb9dd-550c-4fe7-a208-0e500b1c311c\\\",\\\"ServiceInstance\\\":\\\"PowerAppsService/NA001\\\",\\\"CapabilityStatus\\\":0,\\\"AssignedTimestamp\\\":\\\"2023-07-27T17:47:38Z\\\",\\\"InitialState\\\":null,\\\"Capability\\\":null,\\\"ServicePlanId\\\":\\\"9c0dab89-a30c-4117-86e7-97bda240acd2\\\"},{\\\"SubscribedPlanId\\\":\\\"609eaebf-31a9-49f6-a079-b6b130d4b1f0\\\",\\\"ServiceInstance\\\":\\\"ProjectWorkManagement/PROD_NA_Org_Ring_100\\\",\\\"CapabilityStatus\\\":0,\\\"AssignedTimestamp\\\":\\\"2023-07-27T17:47:38Z\\\",\\\"InitialState\\\":null,\\\"Capability\\\":null,\\\"ServicePlanId\\\":\\\"b737dad2-2f6c-4c65-90e3-ca563267e8b9\\\"},{\\\"SubscribedPlanId\\\":\\\"6632a0f5-bc7a-4c76-8ed9-0ba7b5f279bc\\\",\\\"ServiceInstance\\\":\\\"MicrosoftKaizala/NA001\\\",\\\"CapabilityStatus\\\":0,\\\"AssignedTimestamp\\\":\\\"2023-07-27T17:47:38Z\\\",\\\"InitialState\\\":null,\\\"Capability\\\":null,\\\"ServicePlanId\\\":\\\"0898bdbb-73b0-471a-81e5-20f1fe4dd66e\\\"},{\\\"SubscribedPlanId\\\":\\\"695f03a0-fa15-4b83-b4c5-312936e82361\\\",\\\"ServiceInstance\\\":\\\"ProcessSimple/NA001\\\",\\\"CapabilityStatus\\\":0,\\\"AssignedTimestamp\\\":\\\"2023-07-27T17:47:38Z\\\",\\\"InitialState\\\":null,\\\"Capability\\\"",
"c": "6"
}
},
{
"Name": "extendedAuditEventCategory",
"Value": "User"
}
],
"Actor": [
{
"ID": "evilUser@splunkresearch.onmicrosoft.com",
"Type": 5
},
{
"ID": "1003BFFD98415B4E",
"Type": 3
},
{
"ID": "Microsoft Office 365 Portal",
"Type": 1
},
{
"ID": "00000006-0000-0ff1-ce00-000000000000",
"Type": 2
},
{
"ID": "User_e4c722ac-3b83-478d-8f52-c388885dc30f",
"Type": 2
},
{
"ID": "e4c722ac-3b83-478d-8f52-c388885dc30f",
"Type": 2
},
{
"ID": "User",
"Type": 2
}
],
"ActorContextId": "bbad9541-eb53-4533-bcef-2b76182c3b75",
"InterSystemsId": "0817f79e-f0ea-4518-9c21-7babc9a36a79",
"IntraSystemId": "6ae5503d-8764-4f6f-9547-668f4b2f82ca",
"Target": [
{
"ID": "User_57e4bd36-9722-4a4a-9729-7203d8e00b72",
"Type": 2
},
{
"ID": "57e4bd36-9722-4a4a-9729-7203d8e00b72",
"Type": 2
},
{
"ID": "User",
"Type": 2
},
{
"ID": "victimUser@splunkresearch.onmicrosoft.com",
"Type": 5
},
{
"ID": "10032002CC029AE9",
"Type": 3
}
],
"TargetContextId": "bbad9541-eb53-4533-bcef-2b76182c3b75"
}
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Splunk #
T1685, T1685.002
References #
Change user password.
#Description
A user changed their own password.
Example Audit Record #
{
"Actor": [
{
"ID": "mhaag@rodsoto.onmicrosoft.com",
"Type": 5
},
{
"ID": "100320010405E870",
"Type": 3
},
{
"ID": "User_fc1162cc-eb06-4ee9-b837-2aa840fa3181",
"Type": 2
},
{
"ID": "fc1162cc-eb06-4ee9-b837-2aa840fa3181",
"Type": 2
},
{
"ID": "User",
"Type": 2
}
],
"ActorContextId": "0e8108b1-18e9-41a4-961b-dfcddf92ef08",
"AzureActiveDirectoryEventType": 1,
"CreationTime": "2020-12-16T17:16:58",
"ExtendedProperties": [
{
"Name": "additionalDetails",
"Value": {}
},
{
"Name": "extendedAuditEventCategory",
"Value": "User"
}
],
"Id": "d253db84-7206-4b9a-a6da-15b176cb662e",
"InterSystemsId": "9aa2d0af-ca4a-46cf-900c-619a84b32c5d",
"IntraSystemId": "aa7d9769-a27d-4eed-9d0a-132723084550",
"ObjectId": "mhaag@rodsoto.onmicrosoft.com",
"Operation": "Change user password.",
"OrganizationId": "0e8108b1-18e9-41a4-961b-dfcddf92ef08",
"RecordType": 8,
"ResultStatus": "Success",
"Target": [
{
"ID": "User_fc1162cc-eb06-4ee9-b837-2aa840fa3181",
"Type": 2
},
{
"ID": "fc1162cc-eb06-4ee9-b837-2aa840fa3181",
"Type": 2
},
{
"ID": "User",
"Type": 2
},
{
"ID": "mhaag@rodsoto.onmicrosoft.com",
"Type": 5
},
{
"ID": "100320010405E870",
"Type": 3
}
],
"TargetContextId": "0e8108b1-18e9-41a4-961b-dfcddf92ef08",
"UserId": "mhaag@rodsoto.onmicrosoft.com",
"UserKey": "100320010405E870@rodsoto.onmicrosoft.com",
"UserType": 0,
"Version": 1,
"Workload": "AzureActiveDirectory"
}
References #
Consent to application.
#Equivalent operation in the other pipeline: Consent to application (Entra ID directory audit)
Description
Admin or user consent was granted to an application in Azure Active Directory (the UAL operation string includes a trailing period).
Example Audit Record #
{
"CreationTime": "2023-10-11T16:50:44",
"Id": "5209d852-ba11-4ed5-8a7f-e96e0901718e",
"Operation": "Consent to application.",
"OrganizationId": "1a837aa2-b38c-4c7a-84fe-b831335c17e5",
"RecordType": 8,
"ResultStatus": "Failure",
"UserKey": "10032002CC029AE9@contoso.onmicrosoft.com",
"UserType": 0,
"Version": 1,
"Workload": "AzureActiveDirectory",
"ObjectId": "Application_c3aa78b0-3046-44bf-b7fe-6d7cba3e5c4a",
"UserId": "mauricio@contoso.onmicrosoft.com",
"AzureActiveDirectoryEventType": 1,
"ExtendedProperties": [
{
"Name": "additionalDetails",
"Value": {
"User-Agent": "EvoSTS",
"AppId": "d47d9dee-7d6f-4f2d-942a-4266b23eeb3e"
}
},
{
"Name": "extendedAuditEventCategory",
"Value": "ServicePrincipal"
}
],
"ModifiedProperties": [
{
"Name": "ConsentContext.IsAdminConsent",
"NewValue": "False",
"OldValue": ""
},
{
"Name": "ConsentContext.IsAppOnly",
"NewValue": "False",
"OldValue": ""
},
{
"Name": "ConsentContext.OnBehalfOfAll",
"NewValue": "False",
"OldValue": ""
},
{
"Name": "ConsentContext.Tags",
"NewValue": "WindowsAzureActiveDirectoryIntegratedApp",
"OldValue": ""
},
{
"Name": "ConsentAction.Permissions",
"NewValue": "[] => [[Id: AAAAAAAAAAAAAAAAAAAAALSZcc5Sj_NGtUtP2B3pYeI2veRXIpdKSpcpcgPY4Aty, ClientId: 00000000-0000-0000-0000-000000000000, PrincipalId: 57e4bd36-9722-4a4a-9729-7203d8e00b72, ResourceId: ce7199b4-8f52-46f3-b54b-4fd81de961e2, ConsentType: Principal, Scope: Mail.Read User.Read Mail.Send Contacts.Read, CreatedDateTime: , LastModifiedDateTime ]]; ",
"OldValue": ""
},
{
"Name": "ConsentAction.Reason",
"NewValue": "Risky application detected",
"OldValue": ""
},
{
"Name": "MethodExecutionResult.",
"NewValue": "Microsoft.Online.Security.UserConsentBlockedForRiskyAppsException",
"OldValue": ""
}
],
"Actor": [
{
"ID": "mauricio@contoso.onmicrosoft.com",
"Type": 5
},
{
"ID": "10032002CC029AE9",
"Type": 3
},
{
"ID": "User_57e4bd36-9722-4a4a-9729-7203d8e00b72",
"Type": 2
},
{
"ID": "57e4bd36-9722-4a4a-9729-7203d8e00b72",
"Type": 2
},
{
"ID": "User",
"Type": 2
}
],
"ActorContextId": "1a837aa2-b38c-4c7a-84fe-b831335c17e5",
"InterSystemsId": "c12e7f68-a5ea-4e05-982a-358b28e7e76e",
"IntraSystemId": "0a9e300e-81ce-4a35-bc61-392d5612bd0d",
"Target": [
{
"ID": "Application_c3aa78b0-3046-44bf-b7fe-6d7cba3e5c4a",
"Type": 2
},
{
"ID": "c3aa78b0-3046-44bf-b7fe-6d7cba3e5c4a",
"Type": 2
},
{
"ID": "Application",
"Type": 2
},
{
"ID": "Super Legit",
"Type": 1
},
{
"ID": "d47d9dee-7d6f-4f2d-942a-4266b23eeb3e",
"Type": 2
}
],
"TargetContextId": "1a837aa2-b38c-4c7a-84fe-b831335c17e5"
}
Common Indicators #
Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.
| Field | Kind | Value | Rules | Vendors |
|---|---|---|---|---|
ResultStatus (splunk rule field) | eq | success | 2 rules | splunk |
admin_consent (splunk rule field) | eq | false | 2 rules | splunk |
m365::ObjectId (elastic rule field) | is_not_null | | 1 rule | elastic |
m365::Target.Type (elastic rule field) | in | 0 | 1 rule | elastic |
m365::Target.Type (elastic rule field) | in | 10 | 1 rule | elastic |
m365::Target.Type (elastic rule field) | in | 2 | 1 rule | elastic |
m365::Target.Type (elastic rule field) | in | 3 | 1 rule | elastic |
m365::UserId (elastic rule field) | is_not_null | | 1 rule | elastic |
reason (splunk rule field) | eq | risky application detected | 1 rule | splunk |
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Elastic #
T1098, T1528, T1566, T1566.002Splunk #
T1528T1528T1098, T1098.003
References #
Create application password for user.
#Description
An app password was created for a user, letting a legacy client sign in without completing MFA.
Example Audit Record #
{
"Actor": [
{
"ID": "rodsoto@rodsoto.onmicrosoft.com",
"Type": 5
},
{
"ID": "10037FFEA938FB92",
"Type": 3
},
{
"ID": "User_bfb8c366-0406-41a5-b3e3-328f4a3b4484",
"Type": 2
},
{
"ID": "bfb8c366-0406-41a5-b3e3-328f4a3b4484",
"Type": 2
},
{
"ID": "User",
"Type": 2
}
],
"ActorContextId": "0e8108b1-18e9-41a4-961b-dfcddf92ef08",
"AzureActiveDirectoryEventType": 1,
"CreationTime": "2020-12-15T20:49:58",
"ExtendedProperties": [
{
"Name": "additionalDetails",
"Value": {}
},
{
"Name": "extendedAuditEventCategory",
"Value": "User"
}
],
"Id": "aa3b475f-c5d0-4af5-9ad6-40b0cf144a2c",
"InterSystemsId": "a1f4e2f1-be7a-425d-bdc2-22828cedf9ce",
"IntraSystemId": "d44a9c8a-7dee-4fb8-9d79-6e9ad50fc61d",
"ObjectId": "rodsoto@rodsoto.onmicrosoft.com",
"Operation": "Create application password for user.",
"OrganizationId": "0e8108b1-18e9-41a4-961b-dfcddf92ef08",
"RecordType": 8,
"ResultStatus": "Success",
"Target": [
{
"ID": "User_bfb8c366-0406-41a5-b3e3-328f4a3b4484",
"Type": 2
},
{
"ID": "bfb8c366-0406-41a5-b3e3-328f4a3b4484",
"Type": 2
},
{
"ID": "User",
"Type": 2
},
{
"ID": "rodsoto@rodsoto.onmicrosoft.com",
"Type": 5
},
{
"ID": "10037FFEA938FB92",
"Type": 3
}
],
"TargetContextId": "0e8108b1-18e9-41a4-961b-dfcddf92ef08",
"UserId": "rodsoto@rodsoto.onmicrosoft.com",
"UserKey": "10037FFEA938FB92@rodsoto.onmicrosoft.com",
"UserType": 0,
"Version": 1,
"Workload": "AzureActiveDirectory"
}
References #
Create application – Certificates and secrets management
#Description
Create application – Certificates and secrets management activity in Microsoft Entra ID, recorded in the Unified Audit Log (observed in first-party capture).
Example Audit Record #
{
"Actor": [
{
"ID": "adminuser@example.onmicrosoft.com",
"Type": 5
},
{
"ID": "10000000AAAAAAAA",
"Type": 3
},
{
"ID": "User_11111111-1111-1111-1111-111111111111",
"Type": 2
},
{
"ID": "11111111-1111-1111-1111-111111111111",
"Type": 2
},
{
"ID": "User",
"Type": 2
},
{
"ID": "NotAgentic",
"Type": 2
}
],
"ActorContextId": "00000000-0000-0000-0000-000000000001",
"AzureActiveDirectoryEventType": 1,
"CreationTime": "2026-07-02T16:41:44Z",
"ExtendedProperties": [
{
"Name": "additionalDetails",
"Value": {
"User-Agent": "python/3.13.9 (Linux-6.1.0-41-amd64-x86_64-with-glibc2.36) AZURECLI/2.82.0 (DEB)",
"AppId": "92274755-5861-4d35-a89e-c84961929883"
}
},
{
"Name": "extendedAuditEventCategory",
"Value": "Application"
}
],
"Id": "9479a6f5-8f4f-4eef-914f-76fdc8b27b84",
"InterSystemsId": "45cf671d-2f15-420d-8b0a-aa99f1956268",
"IntraSystemId": "00000000-0000-0000-0000-000000000000",
"ModifiedProperties": [
{
"Name": "KeyDescription",
"NewValue": [],
"OldValue": []
},
{
"Name": "Included Updated Properties",
"NewValue": "KeyDescription"
}
],
"ObjectId": "Application_5bb4d314-9a25-4a5c-861c-8fac7de88dc2",
"Operation": "Create application – Certificates and secrets management ",
"OrganizationId": "00000000-0000-0000-0000-000000000001",
"RecordType": 8,
"ResultStatus": "Success",
"Target": [
{
"ID": "Application_5bb4d314-9a25-4a5c-861c-8fac7de88dc2",
"Type": 2
},
{
"ID": "5bb4d314-9a25-4a5c-861c-8fac7de88dc2",
"Type": 2
},
{
"ID": "Application",
"Type": 2
},
{
"ID": "NotAgentic",
"Type": 2
},
{
"ID": "dw-harness-app-980a2377",
"Type": 1
},
{
"ID": "92274755-5861-4d35-a89e-c84961929883",
"Type": 2
}
],
"TargetContextId": "00000000-0000-0000-0000-000000000001",
"UserId": "adminuser@example.onmicrosoft.com",
"UserKey": "10000000AAAAAAAA@example.onmicrosoft.com",
"UserType": 0,
"Version": 1,
"Workload": "AzureActiveDirectory"
}
References #
Create company settings
#Description
Create company settings activity in Microsoft Entra ID, recorded in the Unified Audit Log (observed in first-party capture).
Example Audit Record #
{
"Actor": [
{
"ID": "adminuser@example.onmicrosoft.com",
"Type": 5
},
{
"ID": 1111111111111111,
"Type": 3
},
{
"ID": "User_aaaaaaaa-0000-0000-0000-000000000001",
"Type": 2
},
{
"ID": "aaaaaaaa-0000-0000-0000-000000000001",
"Type": 2
},
{
"ID": "User",
"Type": 2
},
{
"ID": "NotAgentic",
"Type": 2
}
],
"ActorContextId": "11111111-1111-1111-1111-111111111111",
"AzureActiveDirectoryEventType": 1,
"CreationDate": "2026-07-03T03:22:33",
"CreationTime": "2026-07-03T03:22:33",
"ExtendedProperties": [
{
"Name": "additionalDetails",
"Value": {
"User-Agent": "python/3.13.9 (Linux-6.1.0-41-amd64-x86_64-with-glibc2.36) AZURECLI/2.82.0 (DEB)"
}
},
{
"Name": "extendedAuditEventCategory",
"Value": "Company"
}
],
"Id": "32d6405e-7965-491d-aba6-b05c20377d2b",
"InterSystemsId": "c0a4e8d4-d41f-4bbc-ad88-25f2181ee7ee",
"IntraSystemId": "00000000-0000-0000-0000-000000000000",
"ModifiedProperties": [
{
"Name": "ObjectSettings",
"NewValue": [
{
"Settings": [
{
"Id": "dd8b601a-a235-4858-8c92-4d2aafb7826e",
"ObjectSettingTemplateId": "62375ab9-6b52-47ed-826b-58e47e0e304b",
"Properties": [
{
"Key": "EnableMSStandardBlockedWords",
"Value": "false"
}
]
}
]
}
],
"OldValue": [
{
"Settings": []
}
]
},
{
"Name": "Included Updated Properties",
"NewValue": "ObjectSettings",
"OldValue": ""
}
],
"ObjectId": "Company_11111111-1111-1111-1111-111111111111",
"Operation": "Create company settings",
"Operations": "Create company settings",
"OrganizationId": "11111111-1111-1111-1111-111111111111",
"RecordType": "AzureActiveDirectory",
"ResultStatus": "Success",
"Target": [
{
"ID": "Company_11111111-1111-1111-1111-111111111111",
"Type": 2
},
{
"ID": "11111111-1111-1111-1111-111111111111",
"Type": 2
},
{
"ID": "Directory",
"Type": 2
},
{
"ID": "NCT",
"Type": 1
}
],
"TargetContextId": "11111111-1111-1111-1111-111111111111",
"UserId": "adminuser@example.onmicrosoft.com",
"UserKey": "1111111111111111@example.onmicrosoft.com",
"UserType": "Regular",
"Version": 1,
"Workload": "AzureActiveDirectory"
}
References #
Delete administrative unit.
#Description
Delete administrative unit. activity in Microsoft Entra ID, recorded in the Unified Audit Log (observed in first-party capture).
Example Audit Record #
{
"Actor": [
{
"ID": "adminuser@example.onmicrosoft.com",
"Type": 5
},
{
"ID": 1111111111111111,
"Type": 3
},
{
"ID": "User_aaaaaaaa-0000-0000-0000-000000000001",
"Type": 2
},
{
"ID": "aaaaaaaa-0000-0000-0000-000000000001",
"Type": 2
},
{
"ID": "User",
"Type": 2
},
{
"ID": "NotAgentic",
"Type": 2
}
],
"ActorContextId": "11111111-1111-1111-1111-111111111111",
"AzureActiveDirectoryEventType": 1,
"CreationDate": "2026-07-03T03:23:07",
"CreationTime": "2026-07-03T03:23:07",
"ExtendedProperties": [
{
"Name": "additionalDetails",
"Value": {
"User-Agent": "python/3.13.9 (Linux-6.1.0-41-amd64-x86_64-with-glibc2.36) AZURECLI/2.82.0 (DEB)"
}
},
{
"Name": "extendedAuditEventCategory",
"Value": "AdministrativeUnit"
}
],
"Id": "0919b200-4c2f-4766-b2ca-c807386d3a18",
"InterSystemsId": "99b2da51-6799-4f66-abf1-3bd37bb1e413",
"IntraSystemId": "8a546fed-abb3-4a11-90d0-ba48a316ad7d",
"ObjectId": "AdministrativeUnit_78e00ff9-4f90-4a2d-ba46-416e73ce7793",
"Operation": "Delete administrative unit.",
"Operations": "Delete administrative unit.",
"OrganizationId": "11111111-1111-1111-1111-111111111111",
"RecordType": "AzureActiveDirectory",
"ResultStatus": "Success",
"Target": [
{
"ID": "AdministrativeUnit_78e00ff9-4f90-4a2d-ba46-416e73ce7793",
"Type": 2
},
{
"ID": "78e00ff9-4f90-4a2d-ba46-416e73ce7793",
"Type": 2
},
{
"ID": "Manager",
"Type": 2
},
{
"ID": "dw-harness-aum-2fe5ab51",
"Type": 1
}
],
"TargetContextId": "11111111-1111-1111-1111-111111111111",
"UserId": "adminuser@example.onmicrosoft.com",
"UserKey": "1111111111111111@example.onmicrosoft.com",
"UserType": "Regular",
"Version": 1,
"Workload": "AzureActiveDirectory"
}
References #
Delete application password for user.
#Description
An app-password credential was deleted for a user, revoking a legacy non-MFA sign-in credential.
Example Audit Record #
{
"Actor": [
{
"ID": "rodsoto@rodsoto.onmicrosoft.com",
"Type": 5
},
{
"ID": "10037FFEA938FB92",
"Type": 3
},
{
"ID": "User_bfb8c366-0406-41a5-b3e3-328f4a3b4484",
"Type": 2
},
{
"ID": "bfb8c366-0406-41a5-b3e3-328f4a3b4484",
"Type": 2
},
{
"ID": "User",
"Type": 2
}
],
"ActorContextId": "0e8108b1-18e9-41a4-961b-dfcddf92ef08",
"AzureActiveDirectoryEventType": 1,
"CreationTime": "2020-12-15T22:35:20",
"ExtendedProperties": [
{
"Name": "additionalDetails",
"Value": {}
},
{
"Name": "extendedAuditEventCategory",
"Value": "User"
}
],
"Id": "d4c0430f-34ea-43c7-b7eb-d8cd99e20e7f",
"InterSystemsId": "9d18b521-23df-4130-99e2-1ff2eee13333",
"IntraSystemId": "7d96ab40-6e16-48e5-bf78-677c89683775",
"ObjectId": "rodsoto@rodsoto.onmicrosoft.com",
"Operation": "Delete application password for user.",
"OrganizationId": "0e8108b1-18e9-41a4-961b-dfcddf92ef08",
"RecordType": 8,
"ResultStatus": "Success",
"Target": [
{
"ID": "User_bfb8c366-0406-41a5-b3e3-328f4a3b4484",
"Type": 2
},
{
"ID": "bfb8c366-0406-41a5-b3e3-328f4a3b4484",
"Type": 2
},
{
"ID": "User",
"Type": 2
},
{
"ID": "rodsoto@rodsoto.onmicrosoft.com",
"Type": 5
},
{
"ID": "10037FFEA938FB92",
"Type": 3
}
],
"TargetContextId": "0e8108b1-18e9-41a4-961b-dfcddf92ef08",
"UserId": "rodsoto@rodsoto.onmicrosoft.com",
"UserKey": "10037FFEA938FB92@rodsoto.onmicrosoft.com",
"UserType": 0,
"Version": 1,
"Workload": "AzureActiveDirectory"
}
References #
Delete application.
#Description
An application registration was deleted.
Example Audit Record #
{
"CreationTime": "2023-09-01T17:10:56",
"Id": "43581925-c9c0-4cf0-8f14-83853ec1e63d",
"Operation": "Delete application.",
"OrganizationId": "58aee3b9-7433-46a0-b54e-2429487992a0",
"RecordType": 8,
"ResultStatus": "Success",
"UserKey": "1003BFFD98415B4E@contoso.onmicrosoft.com",
"UserType": 0,
"Version": 1,
"Workload": "AzureActiveDirectory",
"ObjectId": "Application_acdcd612-0053-407b-88f1-ebe32e193cee",
"UserId": "attacker@contoso.onmicrosoft.com",
"AzureActiveDirectoryEventType": 1,
"ExtendedProperties": [
{
"Name": "additionalDetails",
"Value": {
"User-Agent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Safari/537.36",
"AppId": "c1d6e216-dfbf-4c1f-818d-d6bfc99f0694"
}
},
{
"Name": "extendedAuditEventCategory",
"Value": "Application"
}
],
"Actor": [
{
"ID": "attacker@contoso.onmicrosoft.com",
"Type": 5
},
{
"ID": "1003BFFD98415B4E",
"Type": 3
},
{
"ID": "18ed3507-a475-4ccb-b669-d66bc9f2a36e",
"Type": 2
},
{
"ID": "User_e4c722ac-3b83-478d-8f52-c388885dc30f",
"Type": 2
},
{
"ID": "e4c722ac-3b83-478d-8f52-c388885dc30f",
"Type": 2
},
{
"ID": "User",
"Type": 2
}
],
"ActorContextId": "58aee3b9-7433-46a0-b54e-2429487992a0",
"InterSystemsId": "12534c88-4425-477a-a40f-ea74457a7c9b",
"IntraSystemId": "a2d4d7c4-727c-401b-9e6c-70413a080855",
"Target": [
{
"ID": "Application_acdcd612-0053-407b-88f1-ebe32e193cee",
"Type": 2
},
{
"ID": "acdcd612-0053-407b-88f1-ebe32e193cee",
"Type": 2
},
{
"ID": "Application",
"Type": 2
},
{
"ID": "TestApp1",
"Type": 1
},
{
"ID": "c1d6e216-dfbf-4c1f-818d-d6bfc99f0694",
"Type": 2
}
],
"TargetContextId": "58aee3b9-7433-46a0-b54e-2429487992a0"
}
References #
Delete company settings
#Description
Delete company settings activity in Microsoft Entra ID, recorded in the Unified Audit Log (observed in first-party capture).
Example Audit Record #
{
"Actor": [
{
"ID": "adminuser@example.onmicrosoft.com",
"Type": 5
},
{
"ID": 1111111111111111,
"Type": 3
},
{
"ID": "User_aaaaaaaa-0000-0000-0000-000000000001",
"Type": 2
},
{
"ID": "aaaaaaaa-0000-0000-0000-000000000001",
"Type": 2
},
{
"ID": "User",
"Type": 2
},
{
"ID": "NotAgentic",
"Type": 2
}
],
"ActorContextId": "11111111-1111-1111-1111-111111111111",
"AzureActiveDirectoryEventType": 1,
"CreationDate": "2026-07-03T03:22:35",
"CreationTime": "2026-07-03T03:22:35",
"ExtendedProperties": [
{
"Name": "additionalDetails",
"Value": {
"User-Agent": "python/3.13.9 (Linux-6.1.0-41-amd64-x86_64-with-glibc2.36) AZURECLI/2.82.0 (DEB)"
}
},
{
"Name": "extendedAuditEventCategory",
"Value": "Company"
}
],
"Id": "e35b05e3-a203-4832-a53f-fd9eea108bfb",
"InterSystemsId": "06236982-a2ab-4284-97f3-8d5821dca5b7",
"IntraSystemId": "00000000-0000-0000-0000-000000000000",
"ModifiedProperties": [
{
"Name": "ObjectSettings",
"NewValue": [
{
"Settings": []
}
],
"OldValue": [
{
"Settings": [
{
"Id": "dd8b601a-a235-4858-8c92-4d2aafb7826e",
"ObjectSettingTemplateId": "62375ab9-6b52-47ed-826b-58e47e0e304b",
"Properties": [
{
"Key": "EnableMSStandardBlockedWords",
"Value": "true"
}
]
}
]
}
]
},
{
"Name": "Included Updated Properties",
"NewValue": "ObjectSettings",
"OldValue": ""
}
],
"ObjectId": "Company_11111111-1111-1111-1111-111111111111",
"Operation": "Delete company settings",
"Operations": "Delete company settings",
"OrganizationId": "11111111-1111-1111-1111-111111111111",
"RecordType": "AzureActiveDirectory",
"ResultStatus": "Success",
"Target": [
{
"ID": "Company_11111111-1111-1111-1111-111111111111",
"Type": 2
},
{
"ID": "11111111-1111-1111-1111-111111111111",
"Type": 2
},
{
"ID": "Directory",
"Type": 2
},
{
"ID": "NCT",
"Type": 1
}
],
"TargetContextId": "11111111-1111-1111-1111-111111111111",
"UserId": "adminuser@example.onmicrosoft.com",
"UserKey": "1111111111111111@example.onmicrosoft.com",
"UserType": "Regular",
"Version": 1,
"Workload": "AzureActiveDirectory"
}
References #
Delete group.
#Description
A group was deleted in Azure Active Directory (the UAL operation string includes a trailing period).
Example Audit Record #
{
"Actor": [
{
"ID": "adminuser@example.onmicrosoft.com",
"Type": 5
},
{
"ID": "10000000AAAAAAAA",
"Type": 3
},
{
"ID": "dw-activity-gen",
"Type": 1
},
{
"ID": "22222222-2222-2222-2222-222222222222",
"Type": 2
},
{
"ID": "User_11111111-1111-1111-1111-111111111111",
"Type": 2
},
{
"ID": "11111111-1111-1111-1111-111111111111",
"Type": 2
},
{
"ID": "User",
"Type": 2
},
{
"ID": "NotAgentic",
"Type": 2
}
],
"ActorContextId": "00000000-0000-0000-0000-000000000001",
"AzureActiveDirectoryEventType": 1,
"CreationTime": "2026-07-02T02:10:51Z",
"ExtendedProperties": [
{
"Name": "additionalDetails",
"Value": {
"User-Agent": "python-requests/2.34.2"
}
},
{
"Name": "extendedAuditEventCategory",
"Value": "Group"
}
],
"Id": "51c24454-8f68-45ac-a504-30d4d4ab1c98",
"InterSystemsId": "38e9e4c1-c82d-4f05-867d-94557529faf5",
"IntraSystemId": "00000000-0000-0000-0000-000000000000",
"ModifiedProperties": [
{
"Name": "DeletionType",
"OldValue": "SoftDelete"
},
{
"Name": "GroupType",
"OldValue": "M365 group with static membership"
},
{
"Name": "CreatedDateTime",
"OldValue": "7/2/2026 2:10:45 AM"
},
{
"Name": "LastUpdatedDateTime",
"OldValue": "7/2/2026 2:10:45 AM"
}
],
"ObjectId": "Group_72ff2416-ca78-4443-8b25-800823d06143",
"Operation": "Delete group.",
"OrganizationId": "00000000-0000-0000-0000-000000000001",
"RecordType": 8,
"ResultStatus": "Success",
"Target": [
{
"ID": "Group_72ff2416-ca78-4443-8b25-800823d06143",
"Type": 2
},
{
"ID": "72ff2416-ca78-4443-8b25-800823d06143",
"Type": 2
},
{
"ID": "Group",
"Type": 2
},
{
"ID": "dw-harness-60974bd7-group",
"Type": 1
}
],
"TargetContextId": "00000000-0000-0000-0000-000000000001",
"UserId": "adminuser@example.onmicrosoft.com",
"UserKey": "10000000AAAAAAAA@example.onmicrosoft.com",
"UserType": 0,
"Version": 1,
"Workload": "AzureActiveDirectory"
}
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →YARA-L #
References #
Delete label.
#Description
Delete label. activity in Microsoft Entra ID, recorded in the Unified Audit Log (observed in first-party capture).
Example Audit Record #
{
"Actor": [
{
"ID": "Microsoft Exchange Online Protection",
"Type": 1
},
{
"ID": "00000007-0000-0ff1-ce00-000000000000",
"Type": 2
},
{
"ID": "ServicePrincipal_7346eb28-2787-4db2-8f6e-a9ebdeec5988",
"Type": 2
},
{
"ID": "7346eb28-2787-4db2-8f6e-a9ebdeec5988",
"Type": 2
},
{
"ID": "ServicePrincipal",
"Type": 2
},
{
"ID": "NotAgentic",
"Type": 2
}
],
"ActorContextId": "11111111-1111-1111-1111-111111111111",
"AzureActiveDirectoryEventType": 1,
"CreationDate": "2026-07-03T05:56:17",
"CreationTime": "2026-07-03T05:56:17",
"ExtendedProperties": [
{
"Name": "additionalDetails",
"Value": {}
},
{
"Name": "extendedAuditEventCategory",
"Value": "Label"
}
],
"Id": "dae1f8a3-a8fd-46c9-b8c8-8192cdd5853c",
"InterSystemsId": "60856770-4c0f-4eab-bcea-4b00af3af49d",
"IntraSystemId": "00000000-0000-0000-0000-000000000000",
"ObjectId": "Label_6f3246c9-cb0a-478b-82c7-09d34f9603cc",
"Operation": "Delete label.",
"Operations": "Delete label.",
"OrganizationId": "11111111-1111-1111-1111-111111111111",
"RecordType": "AzureActiveDirectory",
"ResultStatus": "Success",
"Target": [
{
"ID": "Label_6f3246c9-cb0a-478b-82c7-09d34f9603cc",
"Type": 2
},
{
"ID": "6f3246c9-cb0a-478b-82c7-09d34f9603cc",
"Type": 2
},
{
"ID": "Other",
"Type": 2
},
{
"ID": "dwharn9babc3 label",
"Type": 1
}
],
"TargetContextId": "11111111-1111-1111-1111-111111111111",
"UserId": "ServicePrincipal_7346eb28-2787-4db2-8f6e-a9ebdeec5988",
"UserKey": "Not Available",
"UserType": "System",
"Version": 1,
"Workload": "AzureActiveDirectory"
}
References #
Delete partner specific cross-tenant access setting.
#Description
Microsoft Entra ID (Azure Active Directory) audit activity in the CrossTenantAccessSettings category, recorded in the Office 365 Unified Audit Log.
Example Audit Record #
{
"Actor": [
{
"ID": "attacker@attack_range.lan",
"Type": 5
},
{
"ID": "10037FFEAA5FB8A0",
"Type": 3
},
{
"ID": "User_91ec8a8a-88b4-4159-9a36-acdf37ef17b2",
"Type": 2
},
{
"ID": "91ec8a8a-88b4-4159-9a36-acdf37ef17b2",
"Type": 2
},
{
"ID": "User",
"Type": 2
}
],
"ActorContextId": "6915b1e0-b081-4829-8866-f1a3e883a9ae",
"AzureActiveDirectoryEventType": 1,
"CreationTime": "2024-02-22T21:09:46",
"ExtendedProperties": [
{
"Name": "additionalDetails",
"Value": {}
},
{
"Name": "extendedAuditEventCategory",
"Value": "CrossTenantAccessSettings"
}
],
"Id": "e9881eef-97df-4fda-aa53-bf3aaf35f7aa",
"InterSystemsId": "abb242e5-b3e2-4d8d-9d26-4d74f494f888",
"IntraSystemId": "a5fedd23-0e60-4326-bfda-1cd5909ba68f",
"ModifiedProperties": [
{
"Name": "tenantId",
"NewValue": "341dac3b-34e1-4b06-a4df-5c0259946074",
"OldValue": "341dac3b-34e1-4b06-a4df-5c0259946074"
}
],
"ObjectId": "Policy_17c7001d-3a4d-4bf7-9cc6-ee0e40f665da",
"Operation": "Delete partner specific cross-tenant access setting.",
"OrganizationId": "6915b1e0-b081-4829-8866-f1a3e883a9ae",
"RecordType": 8,
"ResultStatus": "Success",
"Target": [
{
"ID": "Policy_17c7001d-3a4d-4bf7-9cc6-ee0e40f665da",
"Type": 2
},
{
"ID": "17c7001d-3a4d-4bf7-9cc6-ee0e40f665da",
"Type": 2
},
{
"ID": "Policy",
"Type": 2
},
{
"ID": "CrossTenantAccessPolicy for 6915b1e0-b081-4829-8866-f1a3e883a9ae",
"Type": 1
}
],
"TargetContextId": "6915b1e0-b081-4829-8866-f1a3e883a9ae",
"UserId": "attacker@attack_range.lan",
"UserKey": "10037FFEAA5FB8A0@attack_range.lan",
"UserType": 0,
"Version": 1,
"Workload": "AzureActiveDirectory"
}
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Splunk #
T1484, T1484.002↳ also matches Add a partner to cross-tenant access setting.
References #
Delete permission grant policy.
#Description
Delete permission grant policy. activity in Microsoft Entra ID, recorded in the Unified Audit Log (observed in first-party capture).
Example Audit Record #
{
"Actor": [
{
"ID": "adminuser@example.onmicrosoft.com",
"Type": 5
},
{
"ID": 1111111111111111,
"Type": 3
},
{
"ID": "User_aaaaaaaa-0000-0000-0000-000000000001",
"Type": 2
},
{
"ID": "aaaaaaaa-0000-0000-0000-000000000001",
"Type": 2
},
{
"ID": "User",
"Type": 2
},
{
"ID": "NotAgentic",
"Type": 2
}
],
"ActorContextId": "11111111-1111-1111-1111-111111111111",
"AzureActiveDirectoryEventType": 1,
"CreationDate": "2026-07-03T03:22:51",
"CreationTime": "2026-07-03T03:22:51",
"ExtendedProperties": [
{
"Name": "additionalDetails",
"Value": {
"User-Agent": "python/3.13.9 (Linux-6.1.0-41-amd64-x86_64-with-glibc2.36) AZURECLI/2.82.0 (DEB)"
}
},
{
"Name": "extendedAuditEventCategory",
"Value": "PermissionGrantPolicy"
}
],
"Id": "2dd84ef4-b42e-4cbe-9f5b-8dce6a978b85",
"InterSystemsId": "34de479f-5633-4e29-8f7d-6a8f9f34c245",
"IntraSystemId": "00000000-0000-0000-0000-000000000000",
"ModifiedProperties": [
{
"Name": "PermissionGrantPolicy",
"NewValue": "",
"OldValue": {
"EncodingVersion": 2,
"Id": "dwharn-pgp-2fe5ab51",
"Includes": [],
"Excludes": [],
"DisplayName": "dw-harness-pgp-2fe5ab51",
"Description": "harness",
"IncludeAllPreApprovedApplications": false,
"ConsentResourceScopeType": "tenant"
}
}
],
"ObjectId": "PermissionGrantPolicy_82aca392-bf62-49e7-a864-e071ba0e544d",
"Operation": "Delete permission grant policy.",
"Operations": "Delete permission grant policy.",
"OrganizationId": "11111111-1111-1111-1111-111111111111",
"RecordType": "AzureActiveDirectory",
"ResultStatus": "Success",
"Target": [
{
"ID": "PermissionGrantPolicy_82aca392-bf62-49e7-a864-e071ba0e544d",
"Type": 2
},
{
"ID": "82aca392-bf62-49e7-a864-e071ba0e544d",
"Type": 2
},
{
"ID": "Other",
"Type": 2
}
],
"TargetContextId": "11111111-1111-1111-1111-111111111111",
"UserId": "adminuser@example.onmicrosoft.com",
"UserKey": "1111111111111111@example.onmicrosoft.com",
"UserType": "Regular",
"Version": 1,
"Workload": "AzureActiveDirectory"
}
References #
Delete policy.
#Description
Delete policy. activity in Microsoft Entra ID, recorded in the Unified Audit Log (observed in first-party capture).
Example Audit Record #
{
"Actor": [
{
"ID": "adminuser@example.onmicrosoft.com",
"Type": 5
},
{
"ID": 1111111111111111,
"Type": 3
},
{
"ID": "User_aaaaaaaa-0000-0000-0000-000000000001",
"Type": 2
},
{
"ID": "aaaaaaaa-0000-0000-0000-000000000001",
"Type": 2
},
{
"ID": "User",
"Type": 2
},
{
"ID": "NotAgentic",
"Type": 2
}
],
"ActorContextId": "11111111-1111-1111-1111-111111111111",
"AzureActiveDirectoryEventType": 1,
"CreationDate": "2026-07-03T03:22:54",
"CreationTime": "2026-07-03T03:22:54",
"ExtendedProperties": [
{
"Name": "additionalDetails",
"Value": {
"User-Agent": "python/3.13.9 (Linux-6.1.0-41-amd64-x86_64-with-glibc2.36) AZURECLI/2.82.0 (DEB)"
}
},
{
"Name": "extendedAuditEventCategory",
"Value": "Policy"
}
],
"Id": "18bc263b-0f43-4a56-a142-6a4fb1275d19",
"InterSystemsId": "9fee2c11-e301-4f12-b6ef-6a1a2a57baf1",
"IntraSystemId": "af472d78-b9b1-411d-90b4-12fe51b42379",
"ObjectId": "Policy_61f14cb5-4392-4980-ac03-bb056999ff98",
"Operation": "Delete policy.",
"Operations": "Delete policy.",
"OrganizationId": "11111111-1111-1111-1111-111111111111",
"RecordType": "AzureActiveDirectory",
"ResultStatus": "Success",
"Target": [
{
"ID": "Policy_61f14cb5-4392-4980-ac03-bb056999ff98",
"Type": 2
},
{
"ID": "61f14cb5-4392-4980-ac03-bb056999ff98",
"Type": 2
},
{
"ID": "Policy",
"Type": 2
},
{
"ID": "dw-harness-hrd-2fe5ab51",
"Type": 1
}
],
"TargetContextId": "11111111-1111-1111-1111-111111111111",
"UserId": "adminuser@example.onmicrosoft.com",
"UserKey": "1111111111111111@example.onmicrosoft.com",
"UserType": "Regular",
"Version": 1,
"Workload": "AzureActiveDirectory"
}
References #
Delete role definition.
#Description
Delete role definition. activity in Microsoft Entra ID, recorded in the Unified Audit Log (observed in first-party capture).
Example Audit Record #
{
"Actor": [
{
"ID": "adminuser@example.onmicrosoft.com",
"Type": 5
},
{
"ID": 1111111111111111,
"Type": 3
},
{
"ID": "User_aaaaaaaa-0000-0000-0000-000000000001",
"Type": 2
},
{
"ID": "aaaaaaaa-0000-0000-0000-000000000001",
"Type": 2
},
{
"ID": "User",
"Type": 2
},
{
"ID": "NotAgentic",
"Type": 2
}
],
"ActorContextId": "11111111-1111-1111-1111-111111111111",
"AzureActiveDirectoryEventType": 1,
"CreationDate": "2026-07-03T03:22:49",
"CreationTime": "2026-07-03T03:22:49",
"ExtendedProperties": [
{
"Name": "additionalDetails",
"Value": {
"User-Agent": "python/3.13.9 (Linux-6.1.0-41-amd64-x86_64-with-glibc2.36) AZURECLI/2.82.0 (DEB)"
}
},
{
"Name": "extendedAuditEventCategory",
"Value": "RoleDefinition"
}
],
"Id": "7560b4f3-a087-4fbe-a6d6-c8051e8a07fd",
"InterSystemsId": "909994a4-f186-42b8-b5b7-b18b18460859",
"IntraSystemId": "de2a4893-f197-47ce-96cf-6b31c14b6f98",
"ModifiedProperties": [
{
"Name": "Included Updated Properties",
"NewValue": "",
"OldValue": ""
}
],
"ObjectId": "RoleDefinition_799abf44-b19b-4605-9606-2125d16ff1c8",
"Operation": "Delete role definition.",
"Operations": "Delete role definition.",
"OrganizationId": "11111111-1111-1111-1111-111111111111",
"RecordType": "AzureActiveDirectory",
"ResultStatus": "Success",
"Target": [
{
"ID": "RoleDefinition_799abf44-b19b-4605-9606-2125d16ff1c8",
"Type": 2
},
{
"ID": "799abf44-b19b-4605-9606-2125d16ff1c8",
"Type": 2
},
{
"ID": "Other",
"Type": 2
},
{
"ID": "dw-harness-role-2fe5ab51",
"Type": 1
}
],
"TargetContextId": "11111111-1111-1111-1111-111111111111",
"UserId": "adminuser@example.onmicrosoft.com",
"UserKey": "1111111111111111@example.onmicrosoft.com",
"UserType": "Regular",
"Version": 1,
"Workload": "AzureActiveDirectory"
}
References #
Delete user.
#Description
A user account was deleted.
Example Audit Record #
{
"Actor": [
{
"ID": "Microsoft Substrate Management",
"Type": 1
},
{
"ID": "98db8bd6-0cc0-4e67-9de5-f187f1cd1b41",
"Type": 2
},
{
"ID": "ServicePrincipal_414635d2-0108-489f-8a72-0a53de565cf9",
"Type": 2
},
{
"ID": "414635d2-0108-489f-8a72-0a53de565cf9",
"Type": 2
},
{
"ID": "ServicePrincipal",
"Type": 2
},
{
"ID": "NotAgentic",
"Type": 2
}
],
"ActorContextId": "00000000-0000-0000-0000-000000000001",
"AzureActiveDirectoryEventType": 1,
"CreationTime": "2026-07-02T15:32:11Z",
"ExtendedProperties": [
{
"Name": "additionalDetails",
"Value": {}
},
{
"Name": "extendedAuditEventCategory",
"Value": "User"
}
],
"Id": "1d34e995-ca6e-49ad-a4ca-303c9318a8f1",
"InterSystemsId": "441498ec-92e2-4235-9e7b-df017ac32fcb",
"IntraSystemId": "344ba01a-f37f-49c2-8ad0-89c7802a1c0a",
"ModifiedProperties": [
{
"Name": "Is Hard Deleted",
"NewValue": "False"
}
],
"ObjectId": "5a110d55d6e040faa887b35f60262a12ExRemoved-48b8bcaf80964ac399523a64d64bd0b2@example.onmicrosoft.com",
"Operation": "Delete user.",
"OrganizationId": "00000000-0000-0000-0000-000000000001",
"RecordType": 8,
"ResultStatus": "Success",
"Target": [
{
"ID": "User_5a110d55-d6e0-40fa-a887-b35f60262a12",
"Type": 2
},
{
"ID": "5a110d55-d6e0-40fa-a887-b35f60262a12",
"Type": 2
},
{
"ID": "User",
"Type": 2
},
{
"ID": "NotAgentic",
"Type": 2
},
{
"ID": "5a110d55d6e040faa887b35f60262a12ExRemoved-48b8bcaf80964ac399523a64d64bd0b2@example.onmicrosoft.com",
"Type": 5
},
{
"ID": "100320060FE64721",
"Type": 3
}
],
"TargetContextId": "00000000-0000-0000-0000-000000000001",
"UserId": "ServicePrincipal_414635d2-0108-489f-8a72-0a53de565cf9",
"UserKey": "Not Available",
"UserType": 4,
"Version": 1,
"Workload": "AzureActiveDirectory"
}
References #
Disable Strong Authentication.
#Description
Microsoft Entra ID (Azure Active Directory) audit activity in the UserManagement category, recorded in the Office 365 Unified Audit Log.
Example Audit Record #
{
"Actor": [
{
"ID": "rodsoto@rodsoto.onmicrosoft.com",
"Type": 5
},
{
"ID": "10037FFEA938FB92",
"Type": 3
},
{
"ID": "User_bfb8c366-0406-41a5-b3e3-328f4a3b4484",
"Type": 2
},
{
"ID": "bfb8c366-0406-41a5-b3e3-328f4a3b4484",
"Type": 2
},
{
"ID": "User",
"Type": 2
}
],
"ActorContextId": "0e8108b1-18e9-41a4-961b-dfcddf92ef08",
"AzureActiveDirectoryEventType": 1,
"CreationTime": "2020-12-15T22:35:20",
"ExtendedProperties": [
{
"Name": "additionalDetails",
"Value": {}
},
{
"Name": "extendedAuditEventCategory",
"Value": "User"
}
],
"Id": "a5aea9c5-b879-495a-b764-119b2bd54d80",
"InterSystemsId": "9d18b521-23df-4130-99e2-1ff2eee13333",
"IntraSystemId": "7d96ab40-6e16-48e5-bf78-677c89683775",
"ModifiedProperties": [
{
"Name": "StrongAuthenticationRequirement",
"NewValue": [],
"OldValue": [
{
"RelyingParty": "*",
"State": 0,
"RememberDevicesNotIssuedBefore": "2020-12-15T20:47:57+00:00"
}
]
},
{
"Name": "Included Updated Properties",
"NewValue": "StrongAuthenticationRequirement",
"OldValue": ""
}
],
"ObjectId": "rodsoto@rodsoto.onmicrosoft.com",
"Operation": "Disable Strong Authentication.",
"OrganizationId": "0e8108b1-18e9-41a4-961b-dfcddf92ef08",
"RecordType": 8,
"ResultStatus": "Success",
"Target": [
{
"ID": "User_bfb8c366-0406-41a5-b3e3-328f4a3b4484",
"Type": 2
},
{
"ID": "bfb8c366-0406-41a5-b3e3-328f4a3b4484",
"Type": 2
},
{
"ID": "User",
"Type": 2
},
{
"ID": "rodsoto@rodsoto.onmicrosoft.com",
"Type": 5
},
{
"ID": "10037FFEA938FB92",
"Type": 3
}
],
"TargetContextId": "0e8108b1-18e9-41a4-961b-dfcddf92ef08",
"UserId": "rodsoto@rodsoto.onmicrosoft.com",
"UserKey": "10037FFEA938FB92@rodsoto.onmicrosoft.com",
"UserType": 0,
"Version": 1,
"Workload": "AzureActiveDirectory"
}
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Sigma #
T1556, T1556.006Splunk #
T1556
References #
Enable Strong Authentication.
#Description
Records strong authentication (multifactor authentication) being enabled for a directory user.
Example Audit Record #
{
"Actor": [
{
"ID": "rodsoto@rodsoto.onmicrosoft.com",
"Type": 5
},
{
"ID": "10037FFEA938FB92",
"Type": 3
},
{
"ID": "User_bfb8c366-0406-41a5-b3e3-328f4a3b4484",
"Type": 2
},
{
"ID": "bfb8c366-0406-41a5-b3e3-328f4a3b4484",
"Type": 2
},
{
"ID": "User",
"Type": 2
}
],
"ActorContextId": "0e8108b1-18e9-41a4-961b-dfcddf92ef08",
"AzureActiveDirectoryEventType": 1,
"CreationTime": "2020-12-15T23:35:08",
"ExtendedProperties": [
{
"Name": "additionalDetails",
"Value": {}
},
{
"Name": "extendedAuditEventCategory",
"Value": "User"
}
],
"Id": "6aeb7062-8f6e-41d6-9b67-70b6a0c6a8f4",
"InterSystemsId": "c3628235-f9cb-447b-bcba-9d1d4fba74e7",
"IntraSystemId": "b4d02b98-f28e-4adf-b205-65167c2458c2",
"ModifiedProperties": [
{
"Name": "StrongAuthenticationRequirement",
"NewValue": [
{
"RelyingParty": "*",
"State": 1,
"RememberDevicesNotIssuedBefore": "2020-12-15T23:35:08.1700786Z"
}
],
"OldValue": []
},
{
"Name": "Included Updated Properties",
"NewValue": "StrongAuthenticationRequirement",
"OldValue": ""
}
],
"ObjectId": "rodsoto@rodsoto.onmicrosoft.com",
"Operation": "Enable Strong Authentication.",
"OrganizationId": "0e8108b1-18e9-41a4-961b-dfcddf92ef08",
"RecordType": 8,
"ResultStatus": "Success",
"Target": [
{
"ID": "User_bfb8c366-0406-41a5-b3e3-328f4a3b4484",
"Type": 2
},
{
"ID": "bfb8c366-0406-41a5-b3e3-328f4a3b4484",
"Type": 2
},
{
"ID": "User",
"Type": 2
},
{
"ID": "rodsoto@rodsoto.onmicrosoft.com",
"Type": 5
},
{
"ID": "10037FFEA938FB92",
"Type": 3
}
],
"TargetContextId": "0e8108b1-18e9-41a4-961b-dfcddf92ef08",
"UserId": "rodsoto@rodsoto.onmicrosoft.com",
"UserKey": "10037FFEA938FB92@rodsoto.onmicrosoft.com",
"UserType": 0,
"Version": 1,
"Workload": "AzureActiveDirectory"
}
References #
Remove app role assignment from service principal.
#Description
An app role assignment was removed from a service principal, revoking an application's granted app role.
Example Audit Record #
{
"CreationTime": "2024-02-08T21:45:53",
"Id": "1b1c4d79-2b3a-4f7b-9947-04cc5abbbfc4",
"Operation": "Remove app role assignment from service principal.",
"OrganizationId": "75243ab2-44f8-435c-a7a6-b479385df6d4",
"RecordType": 8,
"ResultStatus": "Success",
"UserKey": "1003BFFD98415B4E@splunkresearch.onmicrosoft.com",
"UserType": 0,
"Version": 1,
"Workload": "AzureActiveDirectory",
"ObjectId": "https://outlook.office.com;Microsoft.Exchange;00000002-0000-0ff1-ce00-000000000000;00000002-0000-0ff1-ce00-000000000000/*.outlook.com;00000002-0000-0ff1-ce00-000000000000/outlook.com;00000002-0000-0ff1-ce00-000000000000/mail.office365.com;00000002-0000-0ff1-ce00-000000000000/outlook.office365.com;https://webmail.apps.mil/;https://ps.protection.outlook.com/;https://outlook-dod.office365.us/;https://outlook.com/;https://outlook.office365.com/;https://outlook.office.com/;https://outlook.office365.com:443/;https://outlook-sdf.office365.com/;https://outlook-sdf.office.com/;https://outlook.office365.us/;https://autodiscover-s.office365.us/;https://ps.compliance.protection.outlook.com;https://manage.protection.apps.mil;https://outlook-tdf.office.com/;https://outlook-tdf-2.office.com/;https://ps.outlook.com",
"UserId": "user30@splunkresearch.onmicrosoft.com",
"AzureActiveDirectoryEventType": 1,
"ExtendedProperties": [
{
"Name": "additionalDetails",
"Value": {
"User-Agent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/121.0.0.0 Safari/537.36",
"AppId": "00000002-0000-0ff1-ce00-000000000000"
}
},
{
"Name": "extendedAuditEventCategory",
"Value": "ServicePrincipal"
}
],
"ModifiedProperties": [
{
"Name": "AppRole.Id",
"NewValue": "",
"OldValue": "dc890d15-9560-4a4c-9b7f-a736ec74ec40"
},
{
"Name": "AppRole.Value",
"NewValue": "",
"OldValue": ""
},
{
"Name": "AppRole.DisplayName",
"NewValue": "",
"OldValue": ""
},
{
"Name": "AppRoleAssignment.CreatedDateTime",
"NewValue": "",
"OldValue": "2/8/2024 9:40:19 PM"
},
{
"Name": "AppRoleAssignment.LastModifiedDateTime",
"NewValue": "",
"OldValue": "2/8/2024 9:40:19 PM"
},
{
"Name": "ServicePrincipal.ObjectID",
"NewValue": "",
"OldValue": "2e5c2fd0-cca4-452c-9891-a07c0dafd964"
},
{
"Name": "ServicePrincipal.DisplayName",
"NewValue": "",
"OldValue": "STRT_Oauth"
},
{
"Name": "ServicePrincipal.AppId",
"NewValue": "5f91ce94-4cc5-4ebe-aeb6-f074e57201bb",
"OldValue": ""
},
{
"Name": "ServicePrincipal.Name",
"NewValue": "5f91ce94-4cc5-4ebe-aeb6-f074e57201bb",
"OldValue": ""
},
{
"Name": "TargetId.ServicePrincipalNames",
"NewValue": "https://outlook.office.com;Microsoft.Exchange;00000002-0000-0ff1-ce00-000000000000;00000002-0000-0ff1-ce00-000000000000/*.outlook.com;00000002-0000-0ff1-ce00-000000000000/outlook.com;00000002-0000-0ff1-ce00-000000000000/mail.office365.com;00000002-0000-0ff1-ce00-000000000000/outlook.office365.com;https://webmail.apps.mil/;https://ps.protection.outlook.com/;https://outlook-dod.office365.us/;https://outlook.com/;https://outlook.office365.com/;https://outlook.office.com/;https://outlook.office365.com:443/;https://outlook-sdf.office365.com/;https://outlook-sdf.office.com/;https://outlook.office365.us/;https://autodiscover-s.office365.us/;https://ps.compliance.protection.outlook.com;https://manage.protection.apps.mil;https://outlook-tdf.office.com/;https://outlook-tdf-2.office.com/;https://ps.outlook.com",
"OldValue": ""
}
],
"Actor": [
{
"ID": "user30@splunkresearch.onmicrosoft.com",
"Type": 5
},
{
"ID": "1003BFFD98415B4E",
"Type": 3
},
{
"ID": "18ed3507-a475-4ccb-b669-d66bc9f2a36e",
"Type": 2
},
{
"ID": "User_e4c722ac-3b83-478d-8f52-c388885dc30f",
"Type": 2
},
{
"ID": "e4c722ac-3b83-478d-8f52-c388885dc30f",
"Type": 2
},
{
"ID": "User",
"Type": 2
}
],
"ActorContextId": "75243ab2-44f8-435c-a7a6-b479385df6d4",
"InterSystemsId": "4bb4393b-41c8-477a-8e78-e51760ed6748",
"IntraSystemId": "00000000-0000-0000-0000-000000000000",
"Target": [
{
"ID": "ServicePrincipal_8429eb5c-faeb-4ade-8eac-acc003790769",
"Type": 2
},
{
"ID": "8429eb5c-faeb-4ade-8eac-acc003790769",
"Type": 2
},
{
"ID": "ServicePrincipal",
"Type": 2
},
{
"ID": "Office 365 Exchange Online",
"Type": 1
},
{
"ID": "00000002-0000-0ff1-ce00-000000000000",
"Type": 2
},
{
"ID": "https://outlook.office.com;Microsoft.Exchange;00000002-0000-0ff1-ce00-000000000000;00000002-0000-0ff1-ce00-000000000000/*.outlook.com;00000002-0000-0ff1-ce00-000000000000/outlook.com;00000002-0000-0ff1-ce00-000000000000/mail.office365.com;00000002-0000-0ff1-ce00-000000000000/outlook.office365.com;https://webmail.apps.mil/;https://ps.protection.outlook.com/;https://outlook-dod.office365.us/;https://outlook.com/;https://outlook.office365.com/;https://outlook.office.com/;https://outlook.office365.com:443/;https://outlook-sdf.office365.com/;https://outlook-sdf.office.com/;https://outlook.office365.us/;https://autodiscover-s.office365.us/;https://ps.compliance.protection.outlook.com;https://manage.protection.apps.mil;https://outlook-tdf.office.com/;https://outlook-tdf-2.office.com/;https://ps.outlook.com",
"Type": 4
}
],
"TargetContextId": "75243ab2-44f8-435c-a7a6-b479385df6d4"
}
References #
Remove delegated permission grant.
#Description
An OAuth2 delegated permission grant was deleted, revoking the delegated API permissions granted to an application.
Example Audit Record #
{
"Actor": [
{
"ID": "adminuser@example.onmicrosoft.com",
"Type": 5
},
{
"ID": "10000000AAAAAAAA",
"Type": 3
},
{
"ID": "User_11111111-1111-1111-1111-111111111111",
"Type": 2
},
{
"ID": "11111111-1111-1111-1111-111111111111",
"Type": 2
},
{
"ID": "User",
"Type": 2
},
{
"ID": "NotAgentic",
"Type": 2
}
],
"ActorContextId": "00000000-0000-0000-0000-000000000001",
"AzureActiveDirectoryEventType": 1,
"CreationTime": "2026-07-02T15:30:16Z",
"ExtendedProperties": [
{
"Name": "additionalDetails",
"Value": {
"User-Agent": "python/3.13.9 (Linux-6.1.0-41-amd64-x86_64-with-glibc2.36) AZURECLI/2.82.0 (DEB)",
"AppId": "00000003-0000-0000-c000-000000000000",
"ServicePrincipalProvisioningType": "Other"
}
},
{
"Name": "extendedAuditEventCategory",
"Value": "ServicePrincipal"
}
],
"Id": "35e1ed1f-a18c-4d6b-a55b-0755ec0dffb2",
"InterSystemsId": "ec463a89-5e9f-4c18-8bf9-a2796a0371cc",
"IntraSystemId": "00000000-0000-0000-0000-000000000000",
"ModifiedProperties": [
{
"Name": "DelegatedPermissionGrant.Scope",
"OldValue": "User.Read"
},
{
"Name": "DelegatedPermissionGrant.ConsentType",
"OldValue": "Principal"
},
{
"Name": "ServicePrincipal.ObjectID",
"OldValue": "af2cee02-3ad4-4486-85a2-e8eafc78cd6e"
},
{
"Name": "ServicePrincipal.DisplayName"
},
{
"Name": "ServicePrincipal.AppId"
},
{
"Name": "ServicePrincipal.Name"
},
{
"Name": "TargetId.ServicePrincipalNames",
"NewValue": "00000003-0000-0000-c000-000000000000/ags.windows.net;00000003-0000-0000-c000-000000000000;https://canary.graph.microsoft.com;https://graph.microsoft.com;https://ags.windows.net;https://graph.microsoft.us;https://graph.microsoft.com/;https://dod-graph.microsoft.us;https://canary.graph.microsoft.com/;https://graph.microsoft.us/;https://dod-graph.microsoft.us/"
}
],
"ObjectId": "00000003-0000-0000-c000-000000000000/ags.windows.net;00000003-0000-0000-c000-000000000000;https://canary.graph.microsoft.com;https://graph.microsoft.com;https://ags.windows.net;https://graph.microsoft.us;https://graph.microsoft.com/;https://dod-graph.microsoft.us;https://canary.graph.microsoft.com/;https://graph.microsoft.us/;https://dod-graph.microsoft.us/",
"Operation": "Remove delegated permission grant.",
"OrganizationId": "00000000-0000-0000-0000-000000000001",
"RecordType": 8,
"ResultStatus": "Success",
"Target": [
{
"ID": "ServicePrincipal_2e5ab30e-ae89-43c2-b130-0022f3d655a7",
"Type": 2
},
{
"ID": "2e5ab30e-ae89-43c2-b130-0022f3d655a7",
"Type": 2
},
{
"ID": "ServicePrincipal",
"Type": 2
},
{
"ID": "NotAgentic",
"Type": 2
},
{
"ID": "Microsoft Graph",
"Type": 1
},
{
"ID": "00000003-0000-0000-c000-000000000000",
"Type": 2
},
{
"ID": "00000003-0000-0000-c000-000000000000/ags.windows.net;00000003-0000-0000-c000-000000000000;https://canary.graph.microsoft.com;https://graph.microsoft.com;https://ags.windows.net;https://graph.microsoft.us;https://graph.microsoft.com/;https://dod-graph.microsoft.us;https://canary.graph.microsoft.com/;https://graph.microsoft.us/;https://dod-graph.microsoft.us/",
"Type": 4
},
{
"ID": "Other",
"Type": 2
}
],
"TargetContextId": "00000000-0000-0000-0000-000000000001",
"UserId": "adminuser@example.onmicrosoft.com",
"UserKey": "10000000AAAAAAAA@example.onmicrosoft.com",
"UserType": 0,
"Version": 1,
"Workload": "AzureActiveDirectory"
}
References #
Remove member from administrative unit.
#Description
Remove member from administrative unit. activity in Microsoft Entra ID, recorded in the Unified Audit Log (observed in first-party capture).
Example Audit Record #
{
"Actor": [
{
"ID": "adminuser@example.onmicrosoft.com",
"Type": 5
},
{
"ID": 1111111111111111,
"Type": 3
},
{
"ID": "User_aaaaaaaa-0000-0000-0000-000000000001",
"Type": 2
},
{
"ID": "aaaaaaaa-0000-0000-0000-000000000001",
"Type": 2
},
{
"ID": "User",
"Type": 2
},
{
"ID": "NotAgentic",
"Type": 2
}
],
"ActorContextId": "11111111-1111-1111-1111-111111111111",
"AzureActiveDirectoryEventType": 1,
"CreationDate": "2026-07-03T03:23:06",
"CreationTime": "2026-07-03T03:23:06",
"ExtendedProperties": [
{
"Name": "additionalDetails",
"Value": {
"User-Agent": "python/3.13.9 (Linux-6.1.0-41-amd64-x86_64-with-glibc2.36) AZURECLI/2.82.0 (DEB)"
}
},
{
"Name": "extendedAuditEventCategory",
"Value": "AdministrativeUnit"
}
],
"Id": "ca5cb0c3-fa64-4ed9-82e7-581b5d9ee8fe",
"InterSystemsId": "726ef9b3-5df3-49dd-93ad-bf105a018fce",
"IntraSystemId": "9498d6b1-eb7d-4421-9748-cfa1ca5a103a",
"ModifiedProperties": [
{
"Name": "AdministrativeUnit.ObjectID",
"NewValue": "",
"OldValue": "78e00ff9-4f90-4a2d-ba46-416e73ce7793"
},
{
"Name": "AdministrativeUnit.DisplayName",
"NewValue": "",
"OldValue": "dw-harness-aum-2fe5ab51"
}
],
"ObjectId": "adminuser@example.onmicrosoft.com",
"Operation": "Remove member from administrative unit.",
"Operations": "Remove member from administrative unit.",
"OrganizationId": "11111111-1111-1111-1111-111111111111",
"RecordType": "AzureActiveDirectory",
"ResultStatus": "Success",
"Target": [
{
"ID": "User_aaaaaaaa-0000-0000-0000-000000000001",
"Type": 2
},
{
"ID": "aaaaaaaa-0000-0000-0000-000000000001",
"Type": 2
},
{
"ID": "User",
"Type": 2
},
{
"ID": "NotAgentic",
"Type": 2
},
{
"ID": "adminuser@example.onmicrosoft.com",
"Type": 5
},
{
"ID": 1111111111111111,
"Type": 3
}
],
"TargetContextId": "11111111-1111-1111-1111-111111111111",
"UserId": "adminuser@example.onmicrosoft.com",
"UserKey": "1111111111111111@example.onmicrosoft.com",
"UserType": "Regular",
"Version": 1,
"Workload": "AzureActiveDirectory"
}
References #
Remove member from group.
#Description
A principal was removed from a group in Azure Active Directory (the UAL operation string includes a trailing period).
Example Audit Record #
{
"Actor": [
{
"ID": "adminuser@example.onmicrosoft.com",
"Type": 5
},
{
"ID": "10000000AAAAAAAA",
"Type": 3
},
{
"ID": "dw-activity-gen",
"Type": 1
},
{
"ID": "22222222-2222-2222-2222-222222222222",
"Type": 2
},
{
"ID": "User_11111111-1111-1111-1111-111111111111",
"Type": 2
},
{
"ID": "11111111-1111-1111-1111-111111111111",
"Type": 2
},
{
"ID": "User",
"Type": 2
},
{
"ID": "NotAgentic",
"Type": 2
}
],
"ActorContextId": "00000000-0000-0000-0000-000000000001",
"AzureActiveDirectoryEventType": 1,
"CreationTime": "2026-07-02T02:10:50Z",
"ExtendedProperties": [
{
"Name": "additionalDetails",
"Value": {
"User-Agent": "python-requests/2.34.2"
}
},
{
"Name": "extendedAuditEventCategory",
"Value": "Group"
}
],
"Id": "6af15b64-c0a6-4170-a570-5b1dbdb4f71b",
"InterSystemsId": "0a9a66d0-cf43-4033-b845-b1ffdf639ce8",
"IntraSystemId": "00000000-0000-0000-0000-000000000000",
"ModifiedProperties": [
{
"Name": "Group.ObjectID",
"OldValue": "72ff2416-ca78-4443-8b25-800823d06143"
},
{
"Name": "Group.DisplayName",
"OldValue": "dw-harness-60974bd7-group"
}
],
"ObjectId": "adminuser@example.onmicrosoft.com",
"Operation": "Remove member from group.",
"OrganizationId": "00000000-0000-0000-0000-000000000001",
"RecordType": 8,
"ResultStatus": "Success",
"Target": [
{
"ID": "User_11111111-1111-1111-1111-111111111111",
"Type": 2
},
{
"ID": "11111111-1111-1111-1111-111111111111",
"Type": 2
},
{
"ID": "User",
"Type": 2
},
{
"ID": "NotAgentic",
"Type": 2
},
{
"ID": "adminuser@example.onmicrosoft.com",
"Type": 5
},
{
"ID": "10000000AAAAAAAA",
"Type": 3
}
],
"TargetContextId": "00000000-0000-0000-0000-000000000001",
"UserId": "adminuser@example.onmicrosoft.com",
"UserKey": "10000000AAAAAAAA@example.onmicrosoft.com",
"UserType": 0,
"Version": 1,
"Workload": "AzureActiveDirectory"
}
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →YARA-L #
References #
Remove member from role.
#Description
A principal was removed from a directory role.
Example Audit Record #
{
"Actor": [
{
"ID": "adminuser@example.onmicrosoft.com",
"Type": 5
},
{
"ID": "10000000AAAAAAAA",
"Type": 3
},
{
"ID": "User_11111111-1111-1111-1111-111111111111",
"Type": 2
},
{
"ID": "11111111-1111-1111-1111-111111111111",
"Type": 2
},
{
"ID": "User",
"Type": 2
},
{
"ID": "NotAgentic",
"Type": 2
}
],
"ActorContextId": "00000000-0000-0000-0000-000000000001",
"AzureActiveDirectoryEventType": 1,
"CreationTime": "2026-07-02T15:30:07Z",
"ExtendedProperties": [
{
"Name": "additionalDetails",
"Value": {
"User-Agent": "python/3.13.9 (Linux-6.1.0-41-amd64-x86_64-with-glibc2.36) AZURECLI/2.82.0 (DEB)"
}
},
{
"Name": "extendedAuditEventCategory",
"Value": "Role"
}
],
"Id": "7104b5e7-9dd6-44dc-a644-0e160c40cdf0",
"InterSystemsId": "11141a75-f187-43d5-96e9-74c3b6c2c937",
"IntraSystemId": "6860ba53-8504-4b16-b3e4-3b20b7f29417",
"ModifiedProperties": [
{
"Name": "Role.ObjectID",
"OldValue": "ba4b3989-6c3a-4095-bec6-a973070cfa28"
},
{
"Name": "Role.DisplayName",
"OldValue": "Directory Readers"
},
{
"Name": "Role.TemplateId",
"OldValue": "88d8e3e3-8f55-4a1e-953a-9b9898b8876b"
},
{
"Name": "Role.WellKnownObjectName",
"OldValue": "DirectoryReaders"
}
],
"ObjectId": "dwtestuser@example.onmicrosoft.com",
"Operation": "Remove member from role.",
"OrganizationId": "00000000-0000-0000-0000-000000000001",
"RecordType": 8,
"ResultStatus": "Success",
"Target": [
{
"ID": "User_6b8aef40-5bf4-449f-8164-c2ae9affa2df",
"Type": 2
},
{
"ID": "6b8aef40-5bf4-449f-8164-c2ae9affa2df",
"Type": 2
},
{
"ID": "User",
"Type": 2
},
{
"ID": "NotAgentic",
"Type": 2
},
{
"ID": "dwtestuser@example.onmicrosoft.com",
"Type": 5
},
{
"ID": "10032006100D3C25",
"Type": 3
}
],
"TargetContextId": "00000000-0000-0000-0000-000000000001",
"UserId": "adminuser@example.onmicrosoft.com",
"UserKey": "10000000AAAAAAAA@example.onmicrosoft.com",
"UserType": 0,
"Version": 1,
"Workload": "AzureActiveDirectory"
}
References #
Remove service principal.
#Description
A service principal was removed.
Example Audit Record #
{
"CreationTime": "2023-09-01T17:10:56",
"Id": "730cbb8e-962e-43e6-b442-aaf3bc8dfece",
"Operation": "Remove service principal.",
"OrganizationId": "58aee3b9-7433-46a0-b54e-2429487992a0",
"RecordType": 8,
"ResultStatus": "Success",
"UserKey": "1003BFFD98415B4E@contoso.onmicrosoft.com",
"UserType": 0,
"Version": 1,
"Workload": "AzureActiveDirectory",
"ObjectId": "c1d6e216-dfbf-4c1f-818d-d6bfc99f0694",
"UserId": "attacker@contoso.onmicrosoft.com",
"AzureActiveDirectoryEventType": 1,
"ExtendedProperties": [
{
"Name": "additionalDetails",
"Value": {
"User-Agent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Safari/537.36",
"AppId": "c1d6e216-dfbf-4c1f-818d-d6bfc99f0694"
}
},
{
"Name": "extendedAuditEventCategory",
"Value": "ServicePrincipal"
}
],
"ModifiedProperties": [
{
"Name": "TargetId.ServicePrincipalNames",
"NewValue": "c1d6e216-dfbf-4c1f-818d-d6bfc99f0694",
"OldValue": ""
}
],
"Actor": [
{
"ID": "attacker@contoso.onmicrosoft.com",
"Type": 5
},
{
"ID": "1003BFFD98415B4E",
"Type": 3
},
{
"ID": "18ed3507-a475-4ccb-b669-d66bc9f2a36e",
"Type": 2
},
{
"ID": "User_e4c722ac-3b83-478d-8f52-c388885dc30f",
"Type": 2
},
{
"ID": "e4c722ac-3b83-478d-8f52-c388885dc30f",
"Type": 2
},
{
"ID": "User",
"Type": 2
}
],
"ActorContextId": "58aee3b9-7433-46a0-b54e-2429487992a0",
"InterSystemsId": "12534c88-4425-477a-a40f-ea74457a7c9b",
"IntraSystemId": "a2d4d7c4-727c-401b-9e6c-70413a080855",
"Target": [
{
"ID": "ServicePrincipal_01b95e22-4308-41f0-abec-9c49aa213698",
"Type": 2
},
{
"ID": "01b95e22-4308-41f0-abec-9c49aa213698",
"Type": 2
},
{
"ID": "ServicePrincipal",
"Type": 2
},
{
"ID": "TestApp1",
"Type": 1
},
{
"ID": "c1d6e216-dfbf-4c1f-818d-d6bfc99f0694",
"Type": 2
},
{
"ID": "c1d6e216-dfbf-4c1f-818d-d6bfc99f0694",
"Type": 4
}
],
"TargetContextId": "58aee3b9-7433-46a0-b54e-2429487992a0"
}
References #
Reset user password.
#Description
An administrator reset a user's password.
Example Audit Record #
{
"Actor": [
{
"ID": "adminuser@example.onmicrosoft.com",
"Type": 5
},
{
"ID": "10000000AAAAAAAA",
"Type": 3
},
{
"ID": "User_11111111-1111-1111-1111-111111111111",
"Type": 2
},
{
"ID": "11111111-1111-1111-1111-111111111111",
"Type": 2
},
{
"ID": "User",
"Type": 2
},
{
"ID": "NotAgentic",
"Type": 2
}
],
"ActorContextId": "00000000-0000-0000-0000-000000000001",
"AzureActiveDirectoryEventType": 1,
"CreationTime": "2026-07-02T15:29:59Z",
"ExtendedProperties": [
{
"Name": "additionalDetails",
"Value": {
"User-Agent": "python/3.13.9 (Linux-6.1.0-41-amd64-x86_64-with-glibc2.36) AZURECLI/2.82.0 (DEB)"
}
},
{
"Name": "extendedAuditEventCategory",
"Value": "User"
}
],
"Id": "34d94b27-3857-4c87-80e5-f6c60d8b5d7b",
"InterSystemsId": "884ecd76-2d50-48e7-b8de-af4fb379eaf9",
"IntraSystemId": "9c60102e-f8d1-40d4-b9ee-f9cd71600ece",
"ObjectId": "dwtestuser@example.onmicrosoft.com",
"Operation": "Reset user password.",
"OrganizationId": "00000000-0000-0000-0000-000000000001",
"RecordType": 8,
"ResultStatus": "Success",
"Target": [
{
"ID": "User_6b8aef40-5bf4-449f-8164-c2ae9affa2df",
"Type": 2
},
{
"ID": "6b8aef40-5bf4-449f-8164-c2ae9affa2df",
"Type": 2
},
{
"ID": "User",
"Type": 2
},
{
"ID": "NotAgentic",
"Type": 2
},
{
"ID": "dwtestuser@example.onmicrosoft.com",
"Type": 5
},
{
"ID": "10032006100D3C25",
"Type": 3
}
],
"TargetContextId": "00000000-0000-0000-0000-000000000001",
"UserId": "adminuser@example.onmicrosoft.com",
"UserKey": "10000000AAAAAAAA@example.onmicrosoft.com",
"UserType": 0,
"Version": 1,
"Workload": "AzureActiveDirectory"
}
References #
Set Company Information.
#Description
Microsoft Entra ID (Azure Active Directory) audit activity in the DirectoryManagement category, recorded in the Office 365 Unified Audit Log.
Example Audit Record #
{
"Actor": [
{
"ID": "bpatel@rodsoto.onmicrosoft.com",
"Type": 5
},
{
"ID": "100320010208B5DC",
"Type": 3
},
{
"ID": "User_425b75db-38be-4c7b-a474-5f0709247370",
"Type": 2
},
{
"ID": "425b75db-38be-4c7b-a474-5f0709247370",
"Type": 2
},
{
"ID": "User",
"Type": 2
}
],
"ActorContextId": "0e8108b1-18e9-41a4-961b-dfcddf92ef08",
"AzureActiveDirectoryEventType": 1,
"CreationTime": "2021-01-13T22:57:21",
"ExtendedProperties": [
{
"Name": "additionalDetails",
"Value": {}
},
{
"Name": "extendedAuditEventCategory",
"Value": "Company"
}
],
"Id": "50a62783-f9d7-472c-9e44-f4f3d346e53c",
"InterSystemsId": "6f435e84-e95b-44da-820f-2d2c9c237293",
"IntraSystemId": "1163f0db-2241-4689-8486-b15c7812bbe0",
"ModifiedProperties": [
{
"Name": "StrongAuthenticationPolicy",
"NewValue": [
{
"RelyingPartyStrongAuthenticationPolicies": [
{
"RelyingParties": [
"*"
],
"Rules": [
{
"SelectionConditions": [
{
"Claim": 1,
"Operator": 0,
"Values": [
"73.15.72.101/32",
"66.176.252.11/32"
]
}
]
}
],
"Enabled": true
}
]
}
],
"OldValue": [
{
"RelyingPartyStrongAuthenticationPolicies": [
{
"RelyingParties": [
"*"
],
"Rules": [
{
"SelectionConditions": [
{
"Claim": 1,
"Operator": 0,
"Values": [
"73.15.72.101/32",
"66.176.252.11/32"
]
}
]
},
{
"SelectionConditions": [
{
"Claim": 2,
"Operator": 0,
"Values": [
"insidecorporatenetwork--true"
]
}
]
}
],
"Enabled": true
}
]
}
]
},
{
"Name": "Included Updated Properties",
"NewValue": "StrongAuthenticationPolicy",
"OldValue": ""
}
],
"ObjectId": "Company_0e8108b1-18e9-41a4-961b-dfcddf92ef08",
"Operation": "Set Company Information.",
"OrganizationId": "0e8108b1-18e9-41a4-961b-dfcddf92ef08",
"RecordType": 8,
"ResultStatus": "Success",
"Target": [
{
"ID": "Company_0e8108b1-18e9-41a4-961b-dfcddf92ef08",
"Type": 2
},
{
"ID": "0e8108b1-18e9-41a4-961b-dfcddf92ef08",
"Type": 2
},
{
"ID": "Directory",
"Type": 2
},
{
"ID": "Emergency Information Technology Services LLC",
"Type": 1
}
],
"TargetContextId": "0e8108b1-18e9-41a4-961b-dfcddf92ef08",
"UserId": "bpatel@rodsoto.onmicrosoft.com",
"UserKey": "100320010208B5DC@rodsoto.onmicrosoft.com",
"UserType": 0,
"Version": 1,
"Workload": "AzureActiveDirectory"
}
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Splunk #
T1686, T1686.001
References #
Set-MsolDomainFederationSettings
#Description
Federation settings for a domain were changed via the MSOnline module (a directory operation, not an Exchange cmdlet); abused to add a backdoor federation trust.
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Elastic #
T1484, T1484.002
References #
Update administrative unit.
#Description
Update administrative unit. activity in Microsoft Entra ID, recorded in the Unified Audit Log (observed in first-party capture).
Example Audit Record #
{
"Actor": [
{
"ID": "adminuser@example.onmicrosoft.com",
"Type": 5
},
{
"ID": 1111111111111111,
"Type": 3
},
{
"ID": "User_aaaaaaaa-0000-0000-0000-000000000001",
"Type": 2
},
{
"ID": "aaaaaaaa-0000-0000-0000-000000000001",
"Type": 2
},
{
"ID": "User",
"Type": 2
},
{
"ID": "NotAgentic",
"Type": 2
}
],
"ActorContextId": "11111111-1111-1111-1111-111111111111",
"AzureActiveDirectoryEventType": 1,
"CreationDate": "2026-07-03T03:22:26",
"CreationTime": "2026-07-03T03:22:26",
"ExtendedProperties": [
{
"Name": "additionalDetails",
"Value": {
"User-Agent": "python/3.13.9 (Linux-6.1.0-41-amd64-x86_64-with-glibc2.36) AZURECLI/2.82.0 (DEB)"
}
},
{
"Name": "extendedAuditEventCategory",
"Value": "AdministrativeUnit"
}
],
"Id": "f6522d70-5658-44f7-8f41-f875ffc187a3",
"InterSystemsId": "a4938fd1-cdc7-4231-b6a2-dc01f7e9753c",
"IntraSystemId": "b4076f75-40d6-418c-986f-c4aa7fae04ff",
"ModifiedProperties": [
{
"Name": "Description",
"NewValue": [
"harness"
],
"OldValue": []
},
{
"Name": "Included Updated Properties",
"NewValue": "Description",
"OldValue": ""
}
],
"ObjectId": "AdministrativeUnit_7e05260c-9113-4f21-832d-52289dfbea92",
"Operation": "Update administrative unit.",
"Operations": "Update administrative unit.",
"OrganizationId": "11111111-1111-1111-1111-111111111111",
"RecordType": "AzureActiveDirectory",
"ResultStatus": "Success",
"Target": [
{
"ID": "AdministrativeUnit_7e05260c-9113-4f21-832d-52289dfbea92",
"Type": 2
},
{
"ID": "7e05260c-9113-4f21-832d-52289dfbea92",
"Type": 2
},
{
"ID": "Manager",
"Type": 2
},
{
"ID": "dw-harness-au-2fe5ab51",
"Type": 1
}
],
"TargetContextId": "11111111-1111-1111-1111-111111111111",
"UserId": "adminuser@example.onmicrosoft.com",
"UserKey": "1111111111111111@example.onmicrosoft.com",
"UserType": "Regular",
"Version": 1,
"Workload": "AzureActiveDirectory"
}
References #
Update application – Certificates and secrets management
#Description
Update application – Certificates and secrets management activity in Microsoft Entra ID, recorded in the Unified Audit Log (observed in first-party capture).
Example Audit Record #
{
"Actor": [
{
"ID": "adminuser@example.onmicrosoft.com",
"Type": 5
},
{
"ID": 1111111111111111,
"Type": 3
},
{
"ID": "User_aaaaaaaa-0000-0000-0000-000000000001",
"Type": 2
},
{
"ID": "aaaaaaaa-0000-0000-0000-000000000001",
"Type": 2
},
{
"ID": "User",
"Type": 2
},
{
"ID": "NotAgentic",
"Type": 2
}
],
"ActorContextId": "11111111-1111-1111-1111-111111111111",
"AzureActiveDirectoryEventType": 1,
"CreationDate": "2026-07-03T01:41:35",
"CreationTime": "2026-07-03T01:41:35",
"ExtendedProperties": [
{
"Name": "additionalDetails",
"Value": {
"User-Agent": "python/3.13.9 (Linux-6.1.0-41-amd64-x86_64-with-glibc2.36) AZURECLI/2.82.0 (DEB)",
"AppId": "22222222-2222-2222-2222-222222222222"
}
},
{
"Name": "extendedAuditEventCategory",
"Value": "Application"
}
],
"Id": "59870a3a-48ba-4acc-ab0c-cc757d59d436",
"InterSystemsId": "f88fbfc5-4409-4f78-8235-a91af522f219",
"IntraSystemId": "00000000-0000-0000-0000-000000000000",
"ModifiedProperties": [
{
"Name": "KeyDescription",
"NewValue": [
"[KeyIdentifier=c628b892-73f9-4045-927c-48934ab19b20,KeyType=AsymmetricX509Cert,KeyUsage=Verify,DisplayName=CN=dw-activity-gen]",
"[KeyIdentifier=47646249-73bb-41e2-9bdd-3d1b3984acc5,KeyType=AsymmetricX509Cert,KeyUsage=Verify,DisplayName=CN=dw-activity-gen-harness]"
],
"OldValue": [
"[KeyIdentifier=c628b892-73f9-4045-927c-48934ab19b20,KeyType=AsymmetricX509Cert,KeyUsage=Verify,DisplayName=CN=dw-activity-gen]"
]
},
{
"Name": "Included Updated Properties",
"NewValue": "KeyDescription",
"OldValue": ""
}
],
"ObjectId": "Application_5da95dd1-8642-48d8-86c1-5f3fc4e7dd64",
"Operation": "Update application – Certificates and secrets management ",
"Operations": "Update application – Certificates and secrets management ",
"OrganizationId": "11111111-1111-1111-1111-111111111111",
"RecordType": "AzureActiveDirectory",
"ResultStatus": "Success",
"Target": [
{
"ID": "Application_5da95dd1-8642-48d8-86c1-5f3fc4e7dd64",
"Type": 2
},
{
"ID": "5da95dd1-8642-48d8-86c1-5f3fc4e7dd64",
"Type": 2
},
{
"ID": "Application",
"Type": 2
},
{
"ID": "NotAgentic",
"Type": 2
},
{
"ID": "dw-activity-gen",
"Type": 1
},
{
"ID": "22222222-2222-2222-2222-222222222222",
"Type": 2
}
],
"TargetContextId": "11111111-1111-1111-1111-111111111111",
"UserId": "adminuser@example.onmicrosoft.com",
"UserKey": "1111111111111111@example.onmicrosoft.com",
"UserType": "Regular",
"Version": 1,
"Workload": "AzureActiveDirectory"
}
Common Indicators #
Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.
| Field | Kind | Value | Rules | Vendors |
|---|---|---|---|---|
target.resource.product_object_id (Chronicle) | eq | 1b730954-1685-4b74-9bfd-dac224a7b894 | 1 rule | chronicle |
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →YARA-L #
T1098, T1098.001T1098, T1098.001↳ also matches Add application., Add delegated permission grant., Update application.
References #
Update application.
#Description
An application registration was modified in Azure Active Directory (the UAL operation string includes a trailing period).
Example Audit Record #
{
"Actor": [
{
"ID": "adminuser@example.onmicrosoft.com",
"Type": 5
},
{
"ID": 1111111111111111,
"Type": 3
},
{
"ID": "User_11111111-1111-1111-1111-111111111111",
"Type": 2
},
{
"ID": "11111111-1111-1111-1111-111111111111",
"Type": 2
},
{
"ID": "User",
"Type": 2
},
{
"ID": "NotAgentic",
"Type": 2
}
],
"ActorContextId": "00000000-0000-0000-0000-000000000001",
"AzureActiveDirectoryEventType": 1,
"CreationTime": "2026-07-03T01:52:35Z",
"ExtendedProperties": [
{
"Name": "additionalDetails",
"Value": {
"User-Agent": "python/3.13.9 (Linux-6.1.0-41-amd64-x86_64-with-glibc2.36) AZURECLI/2.82.0 (DEB)",
"AppId": "82f6bc24-719b-4329-a62c-e20d64c1ed9b"
}
},
{
"Name": "extendedAuditEventCategory",
"Value": "Application"
}
],
"Id": "d369b34f-2e4f-474a-8673-2449e37b9efe",
"InterSystemsId": "6f53ee1a-4999-4e13-b4b1-fe2738b6364a",
"IntraSystemId": "00000000-0000-0000-0000-000000000000",
"ModifiedProperties": [
{
"Name": "Included Updated Properties",
"NewValue": "",
"OldValue": ""
}
],
"ObjectId": "Application_7de47a5c-1afd-4428-b11c-b9359b8380f6",
"Operation": "Update application.",
"OrganizationId": "00000000-0000-0000-0000-000000000001",
"RecordType": 8,
"ResultStatus": "Success",
"Target": [
{
"ID": "Application_7de47a5c-1afd-4428-b11c-b9359b8380f6",
"Type": 2
},
{
"ID": "7de47a5c-1afd-4428-b11c-b9359b8380f6",
"Type": 2
},
{
"ID": "Application",
"Type": 2
},
{
"ID": "NotAgentic",
"Type": 2
},
{
"ID": "dw-harness-app-78619d48",
"Type": 1
},
{
"ID": "82f6bc24-719b-4329-a62c-e20d64c1ed9b",
"Type": 2
}
],
"TargetContextId": "00000000-0000-0000-0000-000000000001",
"UserId": "adminuser@example.onmicrosoft.com",
"UserKey": "1111111111111111@example.onmicrosoft.com",
"UserType": 0,
"Version": 1,
"Workload": "AzureActiveDirectory"
}
Common Indicators #
Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.
| Field | Kind | Value | Rules | Vendors |
|---|---|---|---|---|
target.resource.attribute.labels.key (Chronicle) | regex_match | NewValue_EntitlementId- | 3 rules | chronicle |
target.resource.attribute.labels.key (Chronicle) | regex_match | OldValue_EntitlementId- | 3 rules | chronicle |
target.resource.product_object_id (Chronicle) | eq | 1b730954-1685-4b74-9bfd-dac224a7b894 | 1 rule | chronicle |
{}.RequiredAppPermissions{}.EntitlementId (splunk rule field) | eq | 06b708a9-e830-4db3-a914-8e69da51d44f | 1 rule | splunk |
{}.RequiredAppPermissions{}.EntitlementId (splunk rule field) | eq | 9e3f62cf-ca93-4989-b6ce-bf83c28f9fe8 | 1 rule | splunk |
{}.RequiredAppPermissions{}.EntitlementId (splunk rule field) | eq | dc890d15-9560-4a4c-9b7f-a736ec74ec40 | 1 rule | splunk |
{}.ResourceAppId (splunk rule field) | eq | 00000002-0000-0ff1-ce00-000000000000 | 1 rule | splunk |
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Splunk #
T1098, T1098.002, T1098.003T1098, T1098.003, T1114, T1114.002T1003, T1003.002YARA-L #
References #
Update company settings
#Description
Update company settings activity in Microsoft Entra ID, recorded in the Unified Audit Log (observed in first-party capture).
Example Audit Record #
{
"Actor": [
{
"ID": "adminuser@example.onmicrosoft.com",
"Type": 5
},
{
"ID": 1111111111111111,
"Type": 3
},
{
"ID": "User_aaaaaaaa-0000-0000-0000-000000000001",
"Type": 2
},
{
"ID": "aaaaaaaa-0000-0000-0000-000000000001",
"Type": 2
},
{
"ID": "User",
"Type": 2
},
{
"ID": "NotAgentic",
"Type": 2
}
],
"ActorContextId": "11111111-1111-1111-1111-111111111111",
"AzureActiveDirectoryEventType": 1,
"CreationDate": "2026-07-03T01:52:56",
"CreationTime": "2026-07-03T01:52:56",
"ExtendedProperties": [
{
"Name": "additionalDetails",
"Value": {
"User-Agent": "python/3.13.9 (Linux-6.1.0-41-amd64-x86_64-with-glibc2.36) AZURECLI/2.82.0 (DEB)"
}
},
{
"Name": "extendedAuditEventCategory",
"Value": "Company"
}
],
"Id": "f3e66cd3-18c8-4fd8-b03f-c03be7b96baf",
"InterSystemsId": "3cd323b3-3000-4a06-b9de-43a8557c95e0",
"IntraSystemId": "00000000-0000-0000-0000-000000000000",
"ModifiedProperties": [
{
"Name": "ObjectSettings",
"NewValue": [
{
"Settings": [
{
"Id": "7052686f-501a-40f5-9d7d-4e2a36372a6d",
"ObjectSettingTemplateId": "62375ab9-6b52-47ed-826b-58e47e0e304b",
"Properties": [
{
"Key": "EnableMSStandardBlockedWords",
"Value": "true"
}
]
}
]
}
],
"OldValue": [
{
"Settings": [
{
"Id": "7052686f-501a-40f5-9d7d-4e2a36372a6d",
"ObjectSettingTemplateId": "62375ab9-6b52-47ed-826b-58e47e0e304b",
"Properties": [
{
"Key": "EnableMSStandardBlockedWords",
"Value": "false"
}
]
}
]
}
]
},
{
"Name": "Included Updated Properties",
"NewValue": "ObjectSettings",
"OldValue": ""
}
],
"ObjectId": "Company_11111111-1111-1111-1111-111111111111",
"Operation": "Update company settings",
"Operations": "Update company settings",
"OrganizationId": "11111111-1111-1111-1111-111111111111",
"RecordType": "AzureActiveDirectory",
"ResultStatus": "Success",
"Target": [
{
"ID": "Company_11111111-1111-1111-1111-111111111111",
"Type": 2
},
{
"ID": "11111111-1111-1111-1111-111111111111",
"Type": 2
},
{
"ID": "Directory",
"Type": 2
},
{
"ID": "NCT",
"Type": 1
}
],
"TargetContextId": "11111111-1111-1111-1111-111111111111",
"UserId": "adminuser@example.onmicrosoft.com",
"UserKey": "1111111111111111@example.onmicrosoft.com",
"UserType": "Regular",
"Version": 1,
"Workload": "AzureActiveDirectory"
}
References #
Update device.
#Description
Update device. activity in Microsoft Entra ID, recorded in the Unified Audit Log (observed in first-party capture).
Example Audit Record #
{
"Actor": [
{
"ID": "Device Registration Service",
"Type": 1
},
{
"ID": "01cb2876-7ebd-4aa4-9cc9-d28bd4d359a9",
"Type": 2
},
{
"ID": "ServicePrincipal_9611bdea-8105-4fd4-9a4a-14f1681a57cf",
"Type": 2
},
{
"ID": "9611bdea-8105-4fd4-9a4a-14f1681a57cf",
"Type": 2
},
{
"ID": "ServicePrincipal",
"Type": 2
},
{
"ID": "NotAgentic",
"Type": 2
}
],
"ActorContextId": "11111111-1111-1111-1111-111111111111",
"AzureActiveDirectoryEventType": 1,
"CreationDate": "2026-07-03T05:46:30",
"CreationTime": "2026-07-03T05:46:30",
"ExtendedProperties": [
{
"Name": "additionalDetails",
"Value": {
"DeviceId": "ef01b99d-7f4f-4ca5-a03c-956e8fa7f2a1",
"DeviceOSType": "Windows",
"DeviceTrustType": "Workplace"
}
},
{
"Name": "extendedAuditEventCategory",
"Value": "Device"
}
],
"Id": "ca3630e8-446e-439a-977c-5840388b4fb9",
"InterSystemsId": "c27ab2f6-16e5-44c6-adf3-b62869e29055",
"IntraSystemId": "00000000-0000-0000-0000-000000000000",
"ModifiedProperties": [
{
"Name": "Included Updated Properties",
"NewValue": "",
"OldValue": ""
},
{
"Name": "TargetId.DeviceId",
"NewValue": "ef01b99d-7f4f-4ca5-a03c-956e8fa7f2a1",
"OldValue": ""
},
{
"Name": "TargetId.DeviceOSType",
"NewValue": "Windows",
"OldValue": ""
},
{
"Name": "TargetId.DeviceTrustType",
"NewValue": "Workplace",
"OldValue": ""
}
],
"ObjectId": "Device_9b9ec43f-cf91-456d-85cf-7d2c5ee3b666",
"Operation": "Update device.",
"Operations": "Update device.",
"OrganizationId": "11111111-1111-1111-1111-111111111111",
"RecordType": "AzureActiveDirectory",
"ResultStatus": "Success",
"Target": [
{
"ID": "Device_9b9ec43f-cf91-456d-85cf-7d2c5ee3b666",
"Type": 2
},
{
"ID": "9b9ec43f-cf91-456d-85cf-7d2c5ee3b666",
"Type": 2
},
{
"ID": "Device",
"Type": 2
},
{
"ID": "JD-DC01-2022",
"Type": 1
}
],
"TargetContextId": "11111111-1111-1111-1111-111111111111",
"UserId": "ServicePrincipal_9611bdea-8105-4fd4-9a4a-14f1681a57cf",
"UserKey": "Not Available",
"UserType": "System",
"Version": 1,
"Workload": "AzureActiveDirectory"
}
References #
Update group.
#Description
Update group. activity in Microsoft Entra ID, recorded in the Unified Audit Log (observed in first-party capture).
Example Audit Record #
{
"Actor": [
{
"ID": "adminuser@example.onmicrosoft.com",
"Type": 5
},
{
"ID": "10000000AAAAAAAA",
"Type": 3
},
{
"ID": "Groups Service",
"Type": 1
},
{
"ID": "86b4b4b4-db10-481c-876b-07447e7f204f",
"Type": 2
},
{
"ID": "User_11111111-1111-1111-1111-111111111111",
"Type": 2
},
{
"ID": "11111111-1111-1111-1111-111111111111",
"Type": 2
},
{
"ID": "User",
"Type": 2
},
{
"ID": "NotAgentic",
"Type": 2
}
],
"ActorContextId": "00000000-0000-0000-0000-000000000001",
"AzureActiveDirectoryEventType": 1,
"CreationTime": "2026-07-02T02:10:29Z",
"ExtendedProperties": [
{
"Name": "additionalDetails",
"Value": {
"GroupType": "Unified"
}
},
{
"Name": "extendedAuditEventCategory",
"Value": "Group"
}
],
"Id": "24583057-7f57-4802-8d63-3225b7c0f2d4",
"InterSystemsId": "05cc70aa-f45d-431e-922d-80f284086ca6",
"IntraSystemId": "00000000-0000-0000-0000-000000000000",
"ModifiedProperties": [
{
"Name": "Included Updated Properties"
},
{
"Name": "MethodExecutionResult.",
"NewValue": "Microsoft.Online.Workflows.ObjectNotFoundException"
},
{
"Name": "TargetId.GroupType",
"NewValue": "Unified"
}
],
"ObjectId": "Group_ca5d50d9-83af-43d6-8a3a-4f3c00590bec",
"Operation": "Update group.",
"OrganizationId": "00000000-0000-0000-0000-000000000001",
"RecordType": 8,
"ResultStatus": "Failure",
"Target": [
{
"ID": "Group_ca5d50d9-83af-43d6-8a3a-4f3c00590bec",
"Type": 2
},
{
"ID": "ca5d50d9-83af-43d6-8a3a-4f3c00590bec",
"Type": 2
},
{
"ID": "Group",
"Type": 2
},
{
"ID": "dw-harness-60974bd7",
"Type": 1
}
],
"TargetContextId": "00000000-0000-0000-0000-000000000001",
"UserId": "adminuser@example.onmicrosoft.com",
"UserKey": "10000000AAAAAAAA@example.onmicrosoft.com",
"UserType": 0,
"Version": 1,
"Workload": "AzureActiveDirectory"
}
References #
Update PasswordProfile.
#Description
Update Password Profile. activity in Microsoft Entra ID, recorded in the Unified Audit Log (observed in first-party capture).
Example Audit Record #
{
"Actor": [
{
"ID": "adminuser@example.onmicrosoft.com",
"Type": 5
},
{
"ID": "10000000AAAAAAAA",
"Type": 3
},
{
"ID": "User_11111111-1111-1111-1111-111111111111",
"Type": 2
},
{
"ID": "11111111-1111-1111-1111-111111111111",
"Type": 2
},
{
"ID": "User",
"Type": 2
},
{
"ID": "NotAgentic",
"Type": 2
}
],
"ActorContextId": "00000000-0000-0000-0000-000000000001",
"AzureActiveDirectoryEventType": 1,
"CreationTime": "2026-07-02T15:29:58Z",
"ExtendedProperties": [
{
"Name": "additionalDetails",
"Value": {
"User-Agent": "python/3.13.9 (Linux-6.1.0-41-amd64-x86_64-with-glibc2.36) AZURECLI/2.82.0 (DEB)"
}
},
{
"Name": "extendedAuditEventCategory",
"Value": "User"
}
],
"Id": "6ba071d4-2868-45cc-8288-f5ba26662d30",
"InterSystemsId": "884ecd76-2d50-48e7-b8de-af4fb379eaf9",
"IntraSystemId": "9c60102e-f8d1-40d4-b9ee-f9cd71600ece",
"ModifiedProperties": [
{
"Name": "Password"
}
],
"ObjectId": "dwtestuser@example.onmicrosoft.com",
"Operation": "Update PasswordProfile.",
"OrganizationId": "00000000-0000-0000-0000-000000000001",
"RecordType": 8,
"ResultStatus": "Success",
"Target": [
{
"ID": "User_6b8aef40-5bf4-449f-8164-c2ae9affa2df",
"Type": 2
},
{
"ID": "6b8aef40-5bf4-449f-8164-c2ae9affa2df",
"Type": 2
},
{
"ID": "User",
"Type": 2
},
{
"ID": "NotAgentic",
"Type": 2
},
{
"ID": "dwtestuser@example.onmicrosoft.com",
"Type": 5
},
{
"ID": "10032006100D3C25",
"Type": 3
}
],
"TargetContextId": "00000000-0000-0000-0000-000000000001",
"UserId": "adminuser@example.onmicrosoft.com",
"UserKey": "10000000AAAAAAAA@example.onmicrosoft.com",
"UserType": 0,
"Version": 1,
"Workload": "AzureActiveDirectory"
}
References #
Update policy.
#Description
Microsoft Entra ID (Azure Active Directory) audit activity in the Policy category, recorded in the Office 365 Unified Audit Log.
Example Audit Record #
{
"Actor": [
{
"ID": "adminuser@example.onmicrosoft.com",
"Type": 5
},
{
"ID": 1111111111111111,
"Type": 3
},
{
"ID": "User_11111111-1111-1111-1111-111111111111",
"Type": 2
},
{
"ID": "11111111-1111-1111-1111-111111111111",
"Type": 2
},
{
"ID": "User",
"Type": 2
},
{
"ID": "NotAgentic",
"Type": 2
}
],
"ActorContextId": "00000000-0000-0000-0000-000000000001",
"AzureActiveDirectoryEventType": 1,
"CreationTime": "2026-07-03T03:22:44Z",
"ExtendedProperties": [
{
"Name": "additionalDetails",
"Value": {}
},
{
"Name": "extendedAuditEventCategory",
"Value": "Policy"
}
],
"Id": "a08bf4fb-ca71-4654-8b7c-a867aa8086fc",
"InterSystemsId": "6b2594ae-7def-4bf0-8a34-f5b48b22cbf4",
"IntraSystemId": "c4aa92a3-ce9f-41bd-a57a-16bcad716c99",
"ModifiedProperties": [
{
"Name": "Included Updated Properties",
"NewValue": "",
"OldValue": ""
}
],
"ObjectId": "Policy_ad962b47-fdc9-48fe-8178-52f5a356ad51",
"Operation": "Update policy.",
"OrganizationId": "00000000-0000-0000-0000-000000000001",
"RecordType": 8,
"ResultStatus": "Success",
"Target": [
{
"ID": "Policy_ad962b47-fdc9-48fe-8178-52f5a356ad51",
"Type": 2
},
{
"ID": "ad962b47-fdc9-48fe-8178-52f5a356ad51",
"Type": 2
},
{
"ID": "Policy",
"Type": 2
},
{
"ID": "Default Policy",
"Type": 1
}
],
"TargetContextId": "00000000-0000-0000-0000-000000000001",
"UserId": "adminuser@example.onmicrosoft.com",
"UserKey": "1111111111111111@example.onmicrosoft.com",
"UserType": 0,
"Version": 1,
"Workload": "AzureActiveDirectory"
}
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Splunk #
T1136, T1136.003YARA-L #
T1484
References #
Update role definition.
#Description
Update role definition. activity in Microsoft Entra ID, recorded in the Unified Audit Log (observed in first-party capture).
Example Audit Record #
{
"Actor": [
{
"ID": "adminuser@example.onmicrosoft.com",
"Type": 5
},
{
"ID": 1111111111111111,
"Type": 3
},
{
"ID": "User_aaaaaaaa-0000-0000-0000-000000000001",
"Type": 2
},
{
"ID": "aaaaaaaa-0000-0000-0000-000000000001",
"Type": 2
},
{
"ID": "User",
"Type": 2
},
{
"ID": "NotAgentic",
"Type": 2
}
],
"ActorContextId": "11111111-1111-1111-1111-111111111111",
"AzureActiveDirectoryEventType": 1,
"CreationDate": "2026-07-03T03:22:48",
"CreationTime": "2026-07-03T03:22:48",
"ExtendedProperties": [
{
"Name": "additionalDetails",
"Value": {
"User-Agent": "python/3.13.9 (Linux-6.1.0-41-amd64-x86_64-with-glibc2.36) AZURECLI/2.82.0 (DEB)"
}
},
{
"Name": "extendedAuditEventCategory",
"Value": "RoleDefinition"
}
],
"Id": "f7bab2dc-d2d9-400c-9011-1a8f0b8d27cb",
"InterSystemsId": "78b47f4b-0cc1-4586-a9fc-8851f81c6692",
"IntraSystemId": "3520a8f7-7840-406e-a6a3-ac991aed68b6",
"ModifiedProperties": [
{
"Name": "Included Updated Properties",
"NewValue": "",
"OldValue": ""
}
],
"ObjectId": "RoleDefinition_799abf44-b19b-4605-9606-2125d16ff1c8",
"Operation": "Update role definition.",
"Operations": "Update role definition.",
"OrganizationId": "11111111-1111-1111-1111-111111111111",
"RecordType": "AzureActiveDirectory",
"ResultStatus": "Success",
"Target": [
{
"ID": "RoleDefinition_799abf44-b19b-4605-9606-2125d16ff1c8",
"Type": 2
},
{
"ID": "799abf44-b19b-4605-9606-2125d16ff1c8",
"Type": 2
},
{
"ID": "Other",
"Type": 2
},
{
"ID": "dw-harness-role-2fe5ab51",
"Type": 1
}
],
"TargetContextId": "11111111-1111-1111-1111-111111111111",
"UserId": "adminuser@example.onmicrosoft.com",
"UserKey": "1111111111111111@example.onmicrosoft.com",
"UserType": "Regular",
"Version": 1,
"Workload": "AzureActiveDirectory"
}
References #
Update role.
#Description
Update role. activity in Microsoft Entra ID, recorded in the Unified Audit Log (observed in first-party capture).
Example Audit Record #
{
"Actor": [
{
"ID": "adminuser@example.onmicrosoft.com",
"Type": 5
},
{
"ID": 1111111111111111,
"Type": 3
},
{
"ID": "User_aaaaaaaa-0000-0000-0000-000000000001",
"Type": 2
},
{
"ID": "aaaaaaaa-0000-0000-0000-000000000001",
"Type": 2
},
{
"ID": "User",
"Type": 2
},
{
"ID": "NotAgentic",
"Type": 2
}
],
"ActorContextId": "11111111-1111-1111-1111-111111111111",
"AzureActiveDirectoryEventType": 1,
"CreationDate": "2026-07-03T03:22:33",
"CreationTime": "2026-07-03T03:22:33",
"ExtendedProperties": [
{
"Name": "additionalDetails",
"Value": {
"User-Agent": "python/3.13.9 (Linux-6.1.0-41-amd64-x86_64-with-glibc2.36) AZURECLI/2.82.0 (DEB)"
}
},
{
"Name": "extendedAuditEventCategory",
"Value": "Role"
}
],
"Id": "1f9fd9ea-556f-4b4d-a730-1eb56a015ca9",
"InterSystemsId": "c0a4e8d4-d41f-4bbc-ad88-25f2181ee7ee",
"IntraSystemId": "00000000-0000-0000-0000-000000000000",
"ModifiedProperties": [
{
"Name": "Included Updated Properties",
"NewValue": "",
"OldValue": ""
},
{
"Name": "TargetId.RoleTemplateId",
"NewValue": "a0b1b346-4d3e-4e8b-98f8-753987be4970",
"OldValue": ""
},
{
"Name": "TargetId.RoleWellKnownObjectName",
"NewValue": "Users",
"OldValue": ""
}
],
"ObjectId": "Role_d0d8ab1f-38e0-4911-96ba-2a01f139862b",
"Operation": "Update role.",
"Operations": "Update role.",
"OrganizationId": "11111111-1111-1111-1111-111111111111",
"RecordType": "AzureActiveDirectory",
"ResultStatus": "Success",
"Target": [
{
"ID": "Role_d0d8ab1f-38e0-4911-96ba-2a01f139862b",
"Type": 2
},
{
"ID": "d0d8ab1f-38e0-4911-96ba-2a01f139862b",
"Type": 2
},
{
"ID": "Role",
"Type": 2
},
{
"ID": "User",
"Type": 1
},
{
"ID": "a0b1b346-4d3e-4e8b-98f8-753987be4970",
"Type": 2
},
{
"ID": "Users",
"Type": 2
}
],
"TargetContextId": "11111111-1111-1111-1111-111111111111",
"UserId": "adminuser@example.onmicrosoft.com",
"UserKey": "1111111111111111@example.onmicrosoft.com",
"UserType": "Regular",
"Version": 1,
"Workload": "AzureActiveDirectory"
}
References #
Update service principal.
#Description
A service principal object was modified (properties, credentials, or tags).
Example Audit Record #
{
"Actor": [
{
"ID": "adminuser@example.onmicrosoft.com",
"Type": 5
},
{
"ID": 1111111111111111,
"Type": 3
},
{
"ID": "User_11111111-1111-1111-1111-111111111111",
"Type": 2
},
{
"ID": "11111111-1111-1111-1111-111111111111",
"Type": 2
},
{
"ID": "User",
"Type": 2
},
{
"ID": "NotAgentic",
"Type": 2
}
],
"ActorContextId": "00000000-0000-0000-0000-000000000001",
"AzureActiveDirectoryEventType": 1,
"CreationTime": "2026-07-03T05:27:27Z",
"ExtendedProperties": [
{
"Name": "additionalDetails",
"Value": {
"User-Agent": "python/3.13.9 (Linux-6.1.0-41-amd64-x86_64-with-glibc2.36) AZURECLI/2.82.0 (DEB)",
"AppId": "22222222-2222-2222-2222-222222222222",
"AppOwnerOrganizationId": "00000000-0000-0000-0000-000000000001",
"ServicePrincipalProvisioningType": "Other"
}
},
{
"Name": "extendedAuditEventCategory",
"Value": "ServicePrincipal"
}
],
"Id": "fe73a39b-cd76-40bf-bbda-43d3323a9c1f",
"InterSystemsId": "434c435d-00fe-4b82-a00c-ea865443dc62",
"IntraSystemId": "00000000-0000-0000-0000-000000000000",
"ModifiedProperties": [
{
"Name": "Included Updated Properties",
"NewValue": "",
"OldValue": ""
}
],
"ObjectId": "22222222-2222-2222-2222-222222222222",
"Operation": "Update service principal.",
"OrganizationId": "00000000-0000-0000-0000-000000000001",
"RecordType": 8,
"ResultStatus": "Success",
"Target": [
{
"ID": "ServicePrincipal_af2cee02-3ad4-4486-85a2-e8eafc78cd6e",
"Type": 2
},
{
"ID": "af2cee02-3ad4-4486-85a2-e8eafc78cd6e",
"Type": 2
},
{
"ID": "ServicePrincipal",
"Type": 2
},
{
"ID": "NotAgentic",
"Type": 2
},
{
"ID": "dw-activity-gen",
"Type": 1
},
{
"ID": "22222222-2222-2222-2222-222222222222",
"Type": 2
},
{
"ID": "22222222-2222-2222-2222-222222222222",
"Type": 4
},
{
"ID": "00000000-0000-0000-0000-000000000001",
"Type": 2
},
{
"ID": "Other",
"Type": 2
}
],
"TargetContextId": "00000000-0000-0000-0000-000000000001",
"UserId": "adminuser@example.onmicrosoft.com",
"UserKey": "1111111111111111@example.onmicrosoft.com",
"UserType": 0,
"Version": 1,
"Workload": "AzureActiveDirectory"
}
References #
Update StsRefreshTokenValidFrom Timestamp.
#Description
A user's refresh tokens were invalidated (revoke sessions); also set silently by some attacks.
Example Audit Record #
{
"Actor": [
{
"ID": "adminuser@example.onmicrosoft.com",
"Type": 5
},
{
"ID": 1111111111111111,
"Type": 3
},
{
"ID": "User_11111111-1111-1111-1111-111111111111",
"Type": 2
},
{
"ID": "11111111-1111-1111-1111-111111111111",
"Type": 2
},
{
"ID": "User",
"Type": 2
},
{
"ID": "NotAgentic",
"Type": 2
}
],
"ActorContextId": "00000000-0000-0000-0000-000000000001",
"AzureActiveDirectoryEventType": 1,
"CreationTime": "2026-07-03T03:22:05Z",
"ExtendedProperties": [
{
"Name": "additionalDetails",
"Value": {
"User-Agent": "python/3.13.9 (Linux-6.1.0-41-amd64-x86_64-with-glibc2.36) AZURECLI/2.82.0 (DEB)"
}
},
{
"Name": "extendedAuditEventCategory",
"Value": "User"
}
],
"Id": "f88fba2a-c324-4549-940a-3928db20821b",
"InterSystemsId": "04ff1d88-7781-44a8-8f2e-d3246297f07c",
"IntraSystemId": "3a161d99-ddfb-4961-be6c-f56c153f613f",
"ObjectId": "dwharn-2fe5ab51@example.onmicrosoft.com",
"Operation": "Update StsRefreshTokenValidFrom Timestamp.",
"OrganizationId": "00000000-0000-0000-0000-000000000001",
"RecordType": 8,
"ResultStatus": "Success",
"Target": [
{
"ID": "User_cb2e74f0-ecab-4632-8779-2523b77641f4",
"Type": 2
},
{
"ID": "cb2e74f0-ecab-4632-8779-2523b77641f4",
"Type": 2
},
{
"ID": "User",
"Type": 2
},
{
"ID": "NotAgentic",
"Type": 2
},
{
"ID": "dwharn-2fe5ab51@example.onmicrosoft.com",
"Type": 5
},
{
"ID": "1003200610B1FC81",
"Type": 3
}
],
"TargetContextId": "00000000-0000-0000-0000-000000000001",
"UserId": "adminuser@example.onmicrosoft.com",
"UserKey": "1111111111111111@example.onmicrosoft.com",
"UserType": 0,
"Version": 1,
"Workload": "AzureActiveDirectory"
}
References #
Update user.
#Description
Microsoft Entra ID (Azure Active Directory) audit activity in the UserManagement category, recorded in the Office 365 Unified Audit Log.
Example Audit Record #
{
"Actor": [
{
"ID": "Microsoft Substrate Management",
"Type": 1
},
{
"ID": "98db8bd6-0cc0-4e67-9de5-f187f1cd1b41",
"Type": 2
},
{
"ID": "ServicePrincipal_414635d2-0108-489f-8a72-0a53de565cf9",
"Type": 2
},
{
"ID": "414635d2-0108-489f-8a72-0a53de565cf9",
"Type": 2
},
{
"ID": "ServicePrincipal",
"Type": 2
},
{
"ID": "NotAgentic",
"Type": 2
}
],
"ActorContextId": "00000000-0000-0000-0000-000000000001",
"AzureActiveDirectoryEventType": 1,
"CreationTime": "2026-07-02T15:39:15Z",
"ExtendedProperties": [
{
"Name": "additionalDetails",
"Value": {
"UserType": "Member"
}
},
{
"Name": "extendedAuditEventCategory",
"Value": "User"
}
],
"Id": "38596428-ed2a-4227-90a4-c6c6e2eb4f2f",
"InterSystemsId": "3dbe0d9b-837d-4569-8aa8-632d86c2eac3",
"IntraSystemId": "8b32b9b0-9dc1-4580-9de6-1d8996e9dcba",
"ModifiedProperties": [
{
"Name": "ProxyAddresses",
"NewValue": [
"SMTP:ExRemoved-be5e8f8fcdbc486d907c247a75839e1c@example.onmicrosoft.com",
"smtp:dwshared2@example.onmicrosoft.com"
],
"OldValue": [
"SMTP:dwshared2@example.onmicrosoft.com"
]
},
{
"Name": "UserPrincipalName",
"NewValue": [
"ExRemoved-be5e8f8fcdbc486d907c247a75839e1c@example.onmicrosoft.com"
],
"OldValue": [
"dwshared2@example.onmicrosoft.com"
]
},
{
"Name": "Included Updated Properties",
"NewValue": "ProxyAddresses, UserPrincipalName",
"OldValue": ""
},
{
"Name": "TargetId.UserType",
"NewValue": "Member",
"OldValue": ""
}
],
"ObjectId": "ExRemoved-be5e8f8fcdbc486d907c247a75839e1c@example.onmicrosoft.com",
"Operation": "Update user.",
"OrganizationId": "00000000-0000-0000-0000-000000000001",
"RecordType": 8,
"ResultStatus": "Success",
"Target": [
{
"ID": "User_60d98188-8dac-4658-b257-8094fa03147e",
"Type": 2
},
{
"ID": "60d98188-8dac-4658-b257-8094fa03147e",
"Type": 2
},
{
"ID": "User",
"Type": 2
},
{
"ID": "NotAgentic",
"Type": 2
},
{
"ID": "ExRemoved-be5e8f8fcdbc486d907c247a75839e1c@example.onmicrosoft.com",
"Type": 5
},
{
"ID": "100320060FE65D06",
"Type": 3
}
],
"TargetContextId": "00000000-0000-0000-0000-000000000001",
"UserId": "ServicePrincipal_414635d2-0108-489f-8a72-0a53de565cf9",
"UserKey": "Not Available",
"UserType": 4,
"Version": 1,
"Workload": "AzureActiveDirectory"
}
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Splunk #
T1098, T1098.005Panther #
T1556
References #
M365 audit records use different field names on each surface #
The same Unified Audit Log record uses different field names on each surface. A query built for one surface can silently miss on another. These pages document the Management Activity API JSON names, the same names Search-UnifiedAuditLog and the Office 365 Management Activity API return.
- Purview CSV export flattens each record to four columns (
CreationDate,UserIds,Operations,AuditData). The API field names live only inside theAuditDataJSON blob. Expand it withConvertFrom-Json. The wrapper columns are renamed too:CreationDatenotCreationTime,UserIdsnotUserId,OperationsnotOperation. - Sentinel's
OfficeActivitytable renames several fields and turns two integer enum columns into strings. The table below maps them.
| API JSON (event pages) | OfficeActivity column | Note |
|---|---|---|
Id | OfficeId | Renamed. |
Workload | OfficeWorkload | Renamed. |
ObjectId | OfficeObjectId | Renamed. |
CreationTime | TimeGenerated | Renamed. OfficeActivity has no CreationTime column. |
SiteUrl | Site_Url | Renamed (SharePoint family). |
RecordType | RecordType | Same name; the Int32 enum becomes its string enum name. |
UserType | UserType | Same name; the Int32 enum becomes a string. |
ClientIP | ClientIP, Client_IPAddress | Both columns present on OfficeActivity. |
Scope | (none) | No OfficeActivity equivalent under any name. Recover it from the API JSON or the Purview AuditData blob. |
Operation, UserId, ResultStatus, UserKey, AppAccessContext, OrganizationId | same names | Unchanged. No _s / _d suffixes (a native table, not a custom log). |
Mapping verified against the OfficeActivity table reference, the Management Activity API schema, and the Purview audit-record export format.