Title:
New CA Policy by Non-approved Actor
Status:
test
Description:Monitor and alert on conditional access changes.
References:
-https://learn.microsoft.com/en-us/entra/architecture/security-operations-infrastructure
Author: Corissa Koopmans, '@corissalea'
Date: 2022-07-18
modified:None
Tags:
- -'attack.privilege-escalation'
- -'attack.t1548'
Logsource:
- product: azure
- service: auditlogs
Detection:
selection:
properties.message:
'Add conditional access policy'
condition:
selection
Falsepositives:
-Misconfigured role permissions
-Verify whether the user identity, user agent, and/or hostname should be making changes in your environment.
Level:
medium