Detection rules › Sigma
User Risk and MFA Registration Policy Updated
Detects changes and updates to the user risk and MFA registration policy. Attackers can modified the policies to Bypass MFA, weaken security thresholds, facilitate further attacks, maintain persistence.
MITRE ATT&CK coverage
| Tactic | Techniques |
|---|---|
| Persistence | No specific technique |
Event coverage
Rules detecting the same action
Other rules on this platform that filter on the same API call or operation.
- Azure Policy Violation Detected (Panther)
- Changes to Device Registration Policy (Sigma)
Rule body yaml
title: User Risk and MFA Registration Policy Updated
id: d4c7758e-9417-4f2e-9109-6125d66dabef
status: test
description: |
Detects changes and updates to the user risk and MFA registration policy.
Attackers can modified the policies to Bypass MFA, weaken security thresholds, facilitate further attacks, maintain persistence.
references:
- https://learn.microsoft.com/en-us/entra/id-protection/howto-identity-protection-configure-mfa-policy
- https://learn.microsoft.com/en-us/entra/identity/monitoring-health/reference-audit-activities
author: Harjot Singh (@cyb3rjy0t)
date: 2024-08-13
tags:
- attack.persistence
logsource:
product: azure
service: auditlogs
detection:
selection:
LoggedByService: 'AAD Management UX'
Category: 'Policy'
OperationName: 'Update User Risk and MFA Registration Policy'
condition: selection
falsepositives:
- Known updates by administrators.
level: high
Stages and Predicates
Stage 0: condition
selectionStage 1: selection
selection:
LoggedByService: 'AAD Management UX'
Category: 'Policy'
OperationName: 'Update User Risk and MFA Registration Policy'
Indicators
Each row is a field, operator, and value that the rule matches. The corpus column counts how many other rules in the catalog look for the same combination: high numbers point to widely-used, community-vetted indicators. Blank or 1 shows that the indicator is specific to this rule.
| Field | Kind | Values |
|---|---|---|
Category | eq |
|
LoggedByService | eq |
|
OperationName | eq |
|