Detection rules › Sigma
Azure Device No Longer Managed or Compliant
Identifies when a device in azure is no longer managed or compliant
Known false positives
- Administrator may have forgotten to review the device.
MITRE ATT&CK coverage
| Tactic | Techniques |
|---|---|
| Impact | No specific technique |
Telemetry coverage
| Platform | Record / event type |
|---|---|
| Azure | Device no longer compliant |
| Azure | Device no longer managed |
Rules detecting the same action
These rules filter on the same operation.
- Azure Device or Configuration Modified or Deleted (Sigma)
- Entra ID AiTM Phishing-Kit Chain Detected (Elastic)
- Entra ID Device Registration with Phishing Kit Default OS Build (Elastic)
- Entra ID Device Registration with ROADtools Default OS Build (Elastic)
- Entra ID Multiple Device Registrations by a Single User (Elastic)
- Entra ID Protection User Alert and Device Registration (Elastic)
- Entra ID Register Device with Unusual User Agent (Azure AD Join) (Elastic)
- Entra ID Unusual Cloud Device Registration (Elastic)
Rule body
title: Azure Device No Longer Managed or Compliant
id: 542b9912-c01f-4e3f-89a8-014c48cdca7d
status: test
description: Identifies when a device in azure is no longer managed or compliant
references:
- https://learn.microsoft.com/en-us/entra/identity/monitoring-health/reference-audit-activities#core-directory
author: Austin Songer @austinsonger
date: 2021-09-03
modified: 2026-04-30
tags:
- attack.impact
logsource:
product: azure
service: auditlogs
detection:
selection:
operationName:
- 'Device no longer compliant'
- 'Device no longer managed'
condition: selection
falsepositives:
- Administrator may have forgotten to review the device.
level: medium
Stages and Predicates
Stage 0: condition
selectionStage 1: selection
selection:
operationName:
- 'Device no longer compliant'
- 'Device no longer managed'
Indicators
These rows show field, operator, and value matches.
| Field | Kind | Values | Search |
|---|---|---|---|
operationName | eq |
| field:"operationName" kind:eq |