Azure AD Federation Settings Modified via Audit Logs

Alerts when federation settings on an Azure AD domain are modified, indicating potential identity trust tampering.

FreeUnreviewedSigmamediumv1
title: Azure AD Federation Settings Modified via Audit Logs
id: 65c2b2d2-7988-4fbc-be20-97a6e4d4244c
status: test
description: This rule flags events where federation settings for a domain are set or changed. Attackers can use federation changes to redirect authentication flows or establish persistence by altering how identity is trusted. The detection relies on Azure audit log telemetry capturing the activity name "Set federation settings on domain".
references:
  - https://learn.microsoft.com/en-us/azure/active-directory/hybrid/how-to-connect-monitor-federation-changes
  - https://github.com/SigmaHQ/sigma/blob/master/rules/cloud/azure/audit_logs/azure_federation_modified.yml
author: Austin Songer, Huntrule Team
date: 2021-09-06
modified: 2022-06-08
tags:
  - attack.privilege-escalation
  - attack.persistence
  - attack.initial-access
  - attack.stealth
  - attack.t1078
logsource:
  product: azure
  service: auditlogs
detection:
  selection:
    ActivityDisplayName: Set federation settings on domain
  condition: selection
falsepositives:
  - Federation Settings being modified or deleted may be performed by a system administrator.
  - Verify whether the user identity, user agent, and/or hostname should be making changes in your environment.
  - Federation Settings modified from unfamiliar users should be investigated. If known behavior is causing false positives, it can be exempted from the rule.
level: medium
license: DRL-1.1
related:
  - id: 352a54e1-74ba-4929-9d47-8193d67aba1e
    type: derived

What it detects

This rule flags events where federation settings for a domain are set or changed. Attackers can use federation changes to redirect authentication flows or establish persistence by altering how identity is trusted. The detection relies on Azure audit log telemetry capturing the activity name "Set federation settings on domain".

Known false positives

  • Federation Settings being modified or deleted may be performed by a system administrator.
  • Verify whether the user identity, user agent, and/or hostname should be making changes in your environment.
  • Federation Settings modified from unfamiliar users should be investigated. If known behavior is causing false positives, it can be exempted from the rule.

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.