Skip to content

Commit

Permalink
Merge PR #4977 from @cyb3rjy0t - Add `User Risk and MFA Registration …
Browse files Browse the repository at this point in the history
…Policy Updated`

new: User Risk and MFA Registration Policy Updated

---------

Co-authored-by: nasbench <[email protected]>
  • Loading branch information
cyb3rjy0t and nasbench authored Aug 21, 2024
1 parent d114395 commit 78abfd5
Showing 1 changed file with 25 additions and 0 deletions.
Original file line number Diff line number Diff line change
@@ -0,0 +1,25 @@
title: User Risk and MFA Registration Policy Updated
id: d4c7758e-9417-4f2e-9109-6125d66dabef
status: experimental
description: |
Detects changes and updates to the user risk and MFA registration policy.
Attackers can modified the policies to Bypass MFA, weaken security thresholds, facilitate further attacks, maintain persistence.
references:
- https://learn.microsoft.com/en-us/entra/id-protection/howto-identity-protection-configure-mfa-policy
- https://learn.microsoft.com/en-us/entra/identity/monitoring-health/reference-audit-activities
author: Harjot Singh (@cyb3rjy0t)
date: 2024-08-13
tags:
- attack.persistence
logsource:
product: azure
service: auditlogs
detection:
selection:
LoggedByService: 'AAD Management UX'
Category: 'Policy'
OperationName: 'Update User Risk and MFA Registration Policy'
condition: selection
falsepositives:
- Known updates by administrators.
level: high

0 comments on commit 78abfd5

Please sign in to comment.