Azure Audit Logs: PIM Role Setting Updates
Alerts on Azure PIM role setting update events recorded in audit logs.
FreeUnreviewedSigmahighv1
azure-audit-logs-pim-role-setting-updates-db6c06c4
title: "Azure Audit Logs: PIM Role Setting Updates"
id: d8de8ad0-19d3-433f-b4b1-a00003f88749
status: test
description: This rule flags events where an Azure Privileged Identity Management (PIM) role setting is updated, specifically messages indicating an "Update role setting in PIM." Changes to PIM configuration can enable or strengthen privileged access and may be used for persistence or stealthy privilege escalation. The detection relies on Azure audit log message telemetry to identify these configuration update actions.
references:
- https://learn.microsoft.com/en-us/entra/architecture/security-operations-privileged-identity-management#azure-ad-roles-assignment
- https://github.com/SigmaHQ/sigma/blob/master/rules/cloud/azure/audit_logs/azure_pim_change_settings.yml
author: Mark Morowczynski '@markmorow', Yochana Henderson, '@Yochana-H', Huntrule Team
date: 2022-08-09
tags:
- attack.initial-access
- attack.privilege-escalation
- attack.persistence
- attack.stealth
- attack.t1078.004
logsource:
product: azure
service: auditlogs
detection:
selection:
properties.message: Update role setting in PIM
condition: selection
falsepositives:
- Legit administrative PIM setting configuration changes
level: high
license: DRL-1.1
related:
- id: db6c06c4-bf3b-421c-aa88-15672b88c743
type: derived
What it detects
This rule flags events where an Azure Privileged Identity Management (PIM) role setting is updated, specifically messages indicating an "Update role setting in PIM." Changes to PIM configuration can enable or strengthen privileged access and may be used for persistence or stealthy privilege escalation. The detection relies on Azure audit log message telemetry to identify these configuration update actions.
Known false positives
- Legit administrative PIM setting configuration changes
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.