App Assigned To Azure RBAC/Microsoft Entra Role

 Original Source: [Sigma source]
Title: App Assigned To Azure RBAC/Microsoft Entra Role
Status: test
Description:Detects when an app is assigned Azure AD roles, such as global administrator, or Azure RBAC roles, such as subscription owner.
References:
  -https://learn.microsoft.com/en-us/entra/architecture/security-operations-applications#service-principal-assigned-to-a-role
Author: Bailey Bercik '@baileybercik', Mark Morowczynski '@markmorow'
Date: 2022-07-19
modified:2024-11-04
Tags:
  • -'attack.persistence'
  • -'attack.privilege-escalation'
  • -'attack.t1098.003'
Logsource:
  • product: azure
  • service: auditlogs
Detection:
  selection:
    targetResources.type: 'Service Principal'
    properties.message:
      -'Add member to role'
      -'Add eligible member to role'
      -'Add scoped member to role'

  condition:selection
Falsepositives:
  -When the permission is legitimately needed for the app
Level: medium