Azure Audit Logs: PIM Role Setting Updates

Alerts on Azure PIM role setting update events recorded in audit logs.

FreeUnreviewedSigmahighv1
title: "Azure Audit Logs: PIM Role Setting Updates"
id: d8de8ad0-19d3-433f-b4b1-a00003f88749
status: test
description: This rule flags events where an Azure Privileged Identity Management (PIM) role setting is updated, specifically messages indicating an "Update role setting in PIM." Changes to PIM configuration can enable or strengthen privileged access and may be used for persistence or stealthy privilege escalation. The detection relies on Azure audit log message telemetry to identify these configuration update actions.
references:
  - https://learn.microsoft.com/en-us/entra/architecture/security-operations-privileged-identity-management#azure-ad-roles-assignment
  - https://github.com/SigmaHQ/sigma/blob/master/rules/cloud/azure/audit_logs/azure_pim_change_settings.yml
author: Mark Morowczynski '@markmorow', Yochana Henderson, '@Yochana-H', Huntrule Team
date: 2022-08-09
tags:
  - attack.initial-access
  - attack.privilege-escalation
  - attack.persistence
  - attack.stealth
  - attack.t1078.004
logsource:
  product: azure
  service: auditlogs
detection:
  selection:
    properties.message: Update role setting in PIM
  condition: selection
falsepositives:
  - Legit administrative PIM setting configuration changes
level: high
license: DRL-1.1
related:
  - id: db6c06c4-bf3b-421c-aa88-15672b88c743
    type: derived

What it detects

This rule flags events where an Azure Privileged Identity Management (PIM) role setting is updated, specifically messages indicating an "Update role setting in PIM." Changes to PIM configuration can enable or strengthen privileged access and may be used for persistence or stealthy privilege escalation. The detection relies on Azure audit log message telemetry to identify these configuration update actions.

Known false positives

  • Legit administrative PIM setting configuration changes

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.