Azure Audit Logs: Application AppID URI Updates via App or Service Principal Changes

Alerts on Azure audit log entries indicating updates to an application or service principal AppID URI configuration.

FreeReviewedSigma · High · v5
Product
azure
Service
auditlogs
Author
Mark Morowczynski '@markmorow', Bailey Bercik '@baileybercik' (SigmaHQ), DRL 1.1
Published
2022-06-02
Updated
2026-07-31

ATT&CK techniques

Initial Access → Cred Access
  1. Recon

  2. Resource Dev

  3. Execution

  4. Discovery

  5. Lateral Movement

  6. Collection

  7. C2

  8. Exfiltration

  9. Impact

What it detects

This rule identifies events where an application or service principal is updated, specifically when the AppID URI configuration is changed. Attackers may alter AppID URI values to redirect authentication flows or maintain persistence by changing how identities are recognized. Detection relies on Azure audit log entries that contain the update message indicating an application or service principal was updated.

Related detections9 linkedT1078.004 — drag to rearrange
Malicious SD-WAN Compromise Credential Theft via loot_run.sh
Suspicious Google Cloud Function Create or Update Triggering Build
Possible SSRF via VMware Workspace One Access instanceHealth CVE-2021-22056
Possible Credential Stuffing Blocked by Conditional Access in Microsoft 365
Suspicious SES Account Sending Enablement and Identity Verification via CloudTrail
Possible Stolen AWS Credential Validation via STS GetCallerIdentity
Suspicious AWS Federated Console Login From Programmatic Credentials
Suspicious M365 Legacy Authentication via BAV2ROPC Client via m365
Suspicious STS AssumeRole With Exfil Session Name via CloudTrail (via cloudtrail)
Azure Audit Logs: Application AppID URI Updates via App or Service Principal Changes
Pivot detection · T1078.004 · 9 related

Changelog

v5
  1. v5
    Candidate ingested via manual entry.2026-07-31
  2. v4
    Candidate ingested via manual entry.2026-07-31
  3. v3
    Candidate ingested via manual entry.2026-07-31
  4. v2
    Candidate ingested via manual entry.2026-07-31
  5. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.