Azure App/Service Principal Assigned to Entra ID or Azure RBAC Roles (Audit Logs)

Finds Azure role assignments where an app/service principal is granted, eligible, or scoped membership via audit log messages.

FreeReviewedSigma · Medium · v5
Product
azure
Service
auditlogs
Author
Bailey Bercik '@baileybercik', Mark Morowczynski '@markmorow' (SigmaHQ), DRL 1.1
Published
2022-07-19
Updated
2026-07-31

ATT&CK techniques

Persistence → Priv Esc
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Defense Evasion

  6. Cred Access

  7. Discovery

  8. Lateral Movement

  9. Collection

  10. C2

  11. Exfiltration

  12. Impact

What it detects

This rule flags events where a service principal (application identity) is added as a member, eligible member, or scoped member to a role. Assigning privileged Entra ID or Azure RBAC permissions to an application can enable persistent access and privilege escalation without interactive user activity. It relies on Azure audit log messages indicating role assignment actions and targets service principals.

Related detections9 linkedT1098.003 — drag to rearrange
Suspicious MURKY PANDA Mail Permission Grant to Service Principal (via azure)
Malicious Assignment of a Privileged Azure AD Role (via auditlogs)
Suspicious Entra Cross-Tenant Access or External User Invitation via Azure Audit (via azure)
Suspicious Delegated Permission Grant to Entra Agent Access Scope via Azure Audit Logs
Suspicious IAM CreateLoginProfile For Root User via AWS AssumeRoot Abuse
Suspicious AWS IAM Privilege Escalation via AttachUserPolicy of Administrator Policy
Suspicious Member Added to Privileged Directory Role in Entra ID
Suspicious High-Privilege Microsoft Graph Application Role Grant via Azure Audit (via azure)
GCP Google Workspace: Application ContextAwareAccess Setting Changed
Azure App/Service Principal Assigned to Entra ID or Azure RBAC Roles (Audit Logs)
Pivot detection · T1098.003 · 9 related

Changelog

v5
  1. v5
    Candidate ingested via manual entry.2026-07-31
  2. v4
    Candidate ingested via manual entry.2026-07-31
  3. v3
    Candidate ingested via manual entry.2026-07-31
  4. v2
    Candidate ingested via manual entry.2026-07-31
  5. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.