Microsoft 365 Audit: New Federated Domain Added

Alerts on Microsoft 365 audit events indicating a new federated domain was added.

FreeReviewedSigma · Medium · v4
Product
m365
Service
audit
Author
Splunk Threat Research Team (original rule), Harjot Singh @cyb3rjy0t (sigma rule) (SigmaHQ), DRL 1.1
Published
2023-09-18
Updated
2026-07-31

ATT&CK techniques

Priv Esc → Defense Evasion
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Cred Access

  7. Discovery

  8. Lateral Movement

  9. Collection

  10. C2

  11. Exfiltration

  12. Impact

What it detects

This rule flags Microsoft 365 audit events where the operation indicates adding a new federated domain. Attackers may abuse federated identity to redirect authentication and enable credential misuse or backdoor access through an external identity provider. It relies on audit telemetry from Microsoft 365 that contains an Operation field including both 'domain' and 'add'/'new'.

Changelog

v4
  1. v4
    Candidate ingested via manual entry.2026-07-31
  2. v3
    Candidate ingested via manual entry.2026-07-31
  3. v2
    Candidate ingested via manual entry.2026-07-31
  4. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.