Azure AD Privileged Identity Management (PIM) Elevation Approval or Denial Audit Events

Flags Azure PIM elevation requests that are approved or denied in audit logs for investigation.

FreeUnreviewedSigmahighv1
title: Azure AD Privileged Identity Management (PIM) Elevation Approval or Denial Audit Events
id: 8a6eb45a-c603-4b92-b347-31649232d9d3
status: test
description: This rule flags audit log events where a Privileged Identity Management (PIM) elevation request is explicitly marked as approved or denied. Attackers may use PIM to obtain or test elevated privileges, and approval/denial outcomes can indicate attempts to gain persistence or escalate access. The detection relies on Azure audit log telemetry that records the approval/denial message associated with PIM elevation requests.
references:
  - https://learn.microsoft.com/en-us/entra/architecture/security-operations-privileged-identity-management#azure-ad-roles-assignment
  - https://github.com/SigmaHQ/sigma/blob/master/rules/cloud/azure/audit_logs/azure_pim_activation_approve_deny.yml
author: Mark Morowczynski '@markmorow', Yochana Henderson, '@Yochana-H', Huntrule Team
date: 2022-08-09
tags:
  - attack.persistence
  - attack.initial-access
  - attack.privilege-escalation
  - attack.stealth
  - attack.t1078.004
logsource:
  product: azure
  service: auditlogs
detection:
  selection:
    properties.message: Request Approved/Denied
  condition: selection
falsepositives:
  - Actual admin using PIM.
level: high
license: DRL-1.1
related:
  - id: 039a7469-0296-4450-84c0-f6966b16dc6d
    type: derived

What it detects

This rule flags audit log events where a Privileged Identity Management (PIM) elevation request is explicitly marked as approved or denied. Attackers may use PIM to obtain or test elevated privileges, and approval/denial outcomes can indicate attempts to gain persistence or escalate access. The detection relies on Azure audit log telemetry that records the approval/denial message associated with PIM elevation requests.

Known false positives

  • Actual admin using PIM.

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.