Azure AD Privileged Identity Management (PIM) Elevation Approval or Denial Audit Events
Flags Azure PIM elevation requests that are approved or denied in audit logs for investigation.
FreeUnreviewedSigmahighv1
azure-ad-privileged-identity-management-pim-elevation-approval-or-denial-audit-e-039a7469
title: Azure AD Privileged Identity Management (PIM) Elevation Approval or Denial Audit Events
id: 8a6eb45a-c603-4b92-b347-31649232d9d3
status: test
description: This rule flags audit log events where a Privileged Identity Management (PIM) elevation request is explicitly marked as approved or denied. Attackers may use PIM to obtain or test elevated privileges, and approval/denial outcomes can indicate attempts to gain persistence or escalate access. The detection relies on Azure audit log telemetry that records the approval/denial message associated with PIM elevation requests.
references:
- https://learn.microsoft.com/en-us/entra/architecture/security-operations-privileged-identity-management#azure-ad-roles-assignment
- https://github.com/SigmaHQ/sigma/blob/master/rules/cloud/azure/audit_logs/azure_pim_activation_approve_deny.yml
author: Mark Morowczynski '@markmorow', Yochana Henderson, '@Yochana-H', Huntrule Team
date: 2022-08-09
tags:
- attack.persistence
- attack.initial-access
- attack.privilege-escalation
- attack.stealth
- attack.t1078.004
logsource:
product: azure
service: auditlogs
detection:
selection:
properties.message: Request Approved/Denied
condition: selection
falsepositives:
- Actual admin using PIM.
level: high
license: DRL-1.1
related:
- id: 039a7469-0296-4450-84c0-f6966b16dc6d
type: derived
What it detects
This rule flags audit log events where a Privileged Identity Management (PIM) elevation request is explicitly marked as approved or denied. Attackers may use PIM to obtain or test elevated privileges, and approval/denial outcomes can indicate attempts to gain persistence or escalate access. The detection relies on Azure audit log telemetry that records the approval/denial message associated with PIM elevation requests.
Known false positives
- Actual admin using PIM.
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.