Azure AD Audit: Trusted Root CA Added for Passwordless Certificate Authentication

Alerts on Azure AD changes that add a new trusted root CA for passwordless certificate-based authentication.

FreeReviewedSigma · Medium · v5
Product
azure
Service
auditlogs
Author
Harjot Shah Singh, '@cyb3rjy0t' (SigmaHQ), DRL 1.1
Published
2024-03-26
Updated
2026-07-31

ATT&CK techniques

Persistence → Cred Access
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Priv Esc

  6. Discovery

  7. Lateral Movement

  8. Collection

  9. C2

  10. Exfiltration

  11. Impact

What it detects

This rule flags when an Azure AD tenant updates the company information to include a new trusted certificate authority value under TrustedCAsForPasswordlessAuth. Adding or changing a trusted root CA can enable certificate-based authentication paths and may support persistence by expanding what certificates the tenant will trust. It relies on Azure AD audit log events for the specific operation (Set Company Information) and the presence of the TrustedCAsForPasswordlessAuth value in the modified property newValue.

Related detections9 linkedT1556 — drag to rearrange
Suspicious XZ Utils Backdoor Kill-Switch Environment String via process_creation
Suspicious AWS SAML Identity Provider Creation
Suspicious Okta Sign-On Policy Lifecycle Modification
Possible Shadow Credentials Abuse via msDS-KeyCredentialLink Modification
Windows Registry Tampering: DsrmAdminLogonBehavior Value Changes (DSRM)
Azure AD Audit Logs: Certificate-based authentication enabled via AuthenticationMethodsPolicy update
AWS CloudTrail: AWS Identity Center Identity Provider Configuration Changes
GitHub Audit: High-Risk Security Controls Disabled
Windows Security Event 5136: msDS-KeyCredentialLink Shadow Credential Added to AD Object
Azure AD Audit: Trusted Root CA Added for Passwordless Certificate Authentication
Pivot detection · T1556 · 9 related

Changelog

v5
  1. v5
    Candidate ingested via manual entry.2026-07-31
  2. v4
    Candidate ingested via manual entry.2026-07-31
  3. v3
    Candidate ingested via manual entry.2026-07-31
  4. v2
    Candidate ingested via manual entry.2026-07-31
  5. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.