Azure PIM Stale Sign-In Alert for Privileged Role Accounts

Alerts when Azure PIM reports a privileged account has gone stale due to no sign-in activity.

FreeReviewedSigma · High · v5
Product
azure
Service
pim
Author
Mark Morowczynski '@markmorow', Gloria Lee, '@gleeiamglo' (SigmaHQ), DRL 1.1
Published
2023-09-14
Updated
2026-07-31
title: Azure PIM Stale Sign-In Alert for Privileged Role Accounts
id: 0e59cb71-81cb-4ac5-b672-e43fd624ed97
status: test
description: This rule flags stale sign-in conditions for accounts assigned to privileged roles when a stale sign-in alert incident is generated. Attackers may rely on dormant privileged accounts for stealthy persistence and reduced likelihood of detection. The detection relies on Azure Privileged Identity Management telemetry that records the stale sign-in risk event type.
references:
  - https://learn.microsoft.com/en-us/entra/id-governance/privileged-identity-management/pim-how-to-configure-security-alerts#potential-stale-accounts-in-a-privileged-role
  - https://github.com/SigmaHQ/sigma/blob/master/rules/cloud/azure/privileged_identity_management/azure_pim_account_stale.yml
author: Mark Morowczynski '@markmorow', Gloria Lee, '@gleeiamglo', Huntrule Team
date: 2023-09-14
tags:
  - attack.initial-access
  - attack.stealth
  - attack.t1078
  - attack.persistence
  - attack.privilege-escalation
logsource:
  product: azure
  service: pim
detection:
  selection:
    riskEventType: staleSignInAlertIncident
  condition: selection
falsepositives:
  - Investigate if potential generic account that cannot be removed.
level: high
license: DRL-1.1
related:
  - id: e402c26a-267a-45bd-9615-bd9ceda6da85
    type: derived