Azure AD: Detect Removal From Group With Conditional Access Policy Modification Rights

Alerts when a user is removed from a group that can modify Conditional Access policies in Azure Entra.

FreeReviewedSigma · Medium · v5
Product
azure
Service
auditlogs
Author
Mark Morowczynski '@markmorow', Thomas Detzner '@tdetzner' (SigmaHQ), DRL 1.1
Published
2022-08-04
Updated
2026-07-31

ATT&CK techniques

Persistence → Cred Access
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Discovery

  6. Lateral Movement

  7. Collection

  8. C2

  9. Exfiltration

  10. Impact

What it detects

This rule flags audit events where a user is removed from a group, specifically targeting groups that have Conditional Access policy modification permissions. Attackers may remove users from privileged groups to disrupt security baselines, evade monitoring, or reduce access after misuse. It relies on Azure audit log messages indicating a “Remove member from group” action and applies no additional filtering beyond the matched message text.

Related detections9 linkedT1548 — drag to rearrange
Azure Entra: Added member to group granting Conditional Access policy modification
Azure Entra Conditional Access Policy Deleted by Non-Approved Actor
Azure Entra conditional access policy updated by non-approved actor
Suspicious User Home Directory Modification via dscl Process Creation
Possible GTFOBins Shell Breakout via apt Command
Suspicious XZ Utils Backdoor Kill-Switch Environment String via process_creation
Malicious Update Orchestrator Service Reconfiguration for Privilege Escalation
Suspicious AWS SAML Identity Provider Creation
Malicious macOS Credential Verification via dscl authonly
Azure AD: Detect Removal From Group With Conditional Access Policy Modification Rights
Pivot detection · T1548 · 9 related

Changelog

v5
  1. v5
    Candidate ingested via manual entry.2026-07-31
  2. v4
    Candidate ingested via manual entry.2026-07-31
  3. v3
    Candidate ingested via manual entry.2026-07-31
  4. v2
    Candidate ingested via manual entry.2026-07-31
  5. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.