M365 Exchange Add-FederatedDomain Success: New Federated Domain Created

Alerts on successful Exchange addition of a new federated domain via Add-FederatedDomain.

FreeReviewedSigma · Medium · v4
Product
m365
Service
exchange
Author
Splunk Threat Research Team (original rule), '@ionsor (rule)' (SigmaHQ), DRL 1.1
Published
2022-02-08
Updated
2026-07-31

ATT&CK techniques

Persistence
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Priv Esc

  6. Defense Evasion

  7. Cred Access

  8. Discovery

  9. Lateral Movement

  10. Collection

  11. C2

  12. Exfiltration

  13. Impact

What it detects

This rule identifies successful creation of a new federated domain in Microsoft 365 via Exchange PowerShell, specifically the Add-FederatedDomain operation. Adding a federated domain can enable authentication redirection or federated identity abuse, which attackers may use to persist access using external identity providers. It relies on Exchange telemetry that records eventSource, eventName, and operation status.

Related detections4 linkedT1136.003 — drag to rearrange
Suspicious Entra Cross-Tenant Access or External User Invitation via Azure Audit (via azure)
Suspicious AWS IAM User Creation Using Support Impersonation Name
GitHub Audit Log: New Organization Member Added or Invited
AWS CloudTrail: ElastiCache Cache Security Group Created
M365 Exchange Add-FederatedDomain Success: New Federated Domain Created
Pivot detection · T1136.003 · 4 related

Changelog

v4
  1. v4
    Candidate ingested via manual entry.2026-07-31
  2. v3
    Candidate ingested via manual entry.2026-07-31
  3. v2
    Candidate ingested via manual entry.2026-07-31
  4. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.