Azure AD/Entra Audit Logs: Device Registration Policy Changes

Alerts on Azure audit log events that set or modify the device registration policy.

FreeReviewedSigma · High · v5
Product
azure
Service
auditlogs
Author
Michael Epping, '@mepples21' (SigmaHQ), DRL 1.1
Published
2022-06-28
Updated
2026-07-31

ATT&CK techniques

Priv Esc → Defense Evasion
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Cred Access

  7. Discovery

  8. Lateral Movement

  9. Collection

  10. C2

  11. Exfiltration

  12. Impact

What it detects

This rule identifies audit log events where the device registration policy is set or modified. Attackers may change device registration settings to weaken security controls, enabling unauthorized device joins or registrations. It relies on Azure audit log entries that record the policy change activity category and display name.

Changelog

v5
  1. v5
    Candidate ingested via manual entry.2026-07-31
  2. v4
    Candidate ingested via manual entry.2026-07-31
  3. v3
    Candidate ingested via manual entry.2026-07-31
  4. v2
    Candidate ingested via manual entry.2026-07-31
  5. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.