splApache-2.0from splunk/security_content
Azure AD Global Administrator Role Assigned
The following analytic detects the assignment of the Azure AD Global Administrator role to a user. It leverages Azure Active Directory AuditLogs to identify when the "Add member to role" operation includes the "Global Administrator" role. This activity is significant because the Global Administrator role grants extensive access to data, resources, and settings, similar to a Domain Administrator in traditional AD environments. If confirmed malicious, this could allow an attacker to establish persistence, escalate privileges, and potentially gain control over Azure resources, posing a severe security risk.
Quality
59
FP risk
โ
Forks
0
Views
0
Rule source๐ locked
๐
Sign in to view the rule source
Free accounts can view the source for the top-ranked rules. Create one in seconds โ no credit card required.
Sign in โ