Azure PIM Stale Sign-In Alerts for Privileged Roles
Alerts when Azure PIM reports a privileged account has gone stale due to no sign-in activity.
FreeUnreviewedSigmahighv1
azure-pim-stale-sign-in-alerts-for-privileged-roles-e402c26a
title: Azure PIM Stale Sign-In Alerts for Privileged Roles
id: 0e59cb71-81cb-4ac5-b672-e43fd624ed97
status: test
description: This rule flags privileged accounts that have not signed in for a configurable number of days, based on a PIM stale sign-in alert incident event. Attackers and misuse scenarios can leave dormant privileged accounts unmonitored, so identifying stale access can support investigation and privilege hygiene. It relies on Azure PIM telemetry where riskEventType equals staleSignInAlertIncident.
references:
- https://learn.microsoft.com/en-us/entra/id-governance/privileged-identity-management/pim-how-to-configure-security-alerts#potential-stale-accounts-in-a-privileged-role
- https://github.com/SigmaHQ/sigma/blob/master/rules/cloud/azure/privileged_identity_management/azure_pim_account_stale.yml
author: Mark Morowczynski '@markmorow', Gloria Lee, '@gleeiamglo', Huntrule Team
date: 2023-09-14
tags:
- attack.initial-access
- attack.stealth
- attack.t1078
- attack.persistence
- attack.privilege-escalation
logsource:
product: azure
service: pim
detection:
selection:
riskEventType: staleSignInAlertIncident
condition: selection
falsepositives:
- Investigate if potential generic account that cannot be removed.
level: high
license: DRL-1.1
related:
- id: e402c26a-267a-45bd-9615-bd9ceda6da85
type: derived
What it detects
This rule flags privileged accounts that have not signed in for a configurable number of days, based on a PIM stale sign-in alert incident event. Attackers and misuse scenarios can leave dormant privileged accounts unmonitored, so identifying stale access can support investigation and privilege hygiene. It relies on Azure PIM telemetry where riskEventType equals staleSignInAlertIncident.
Known false positives
- Investigate if potential generic account that cannot be removed.
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.