Suspicious Delegated Permission Grant to Entra Agent Access Scope via Azure Audit Logs

PremiumReviewedSigma · High · v1
Product
azure
Service
auditlogs
Author
HuntRule
Published
2026-06-26
Updated
2026-08-28

ATT&CK techniques

Persistence → Cred Access
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Defense Evasion

  6. Discovery

  7. Lateral Movement

  8. Collection

  9. C2

  10. Exfiltration

  11. Impact

What it detects

This rule detects a delegated permission grant that targets an Entra agent blueprint access_agent scope, the consent step that lets an attacker-controlled app drive an assistive AI agent. Adversaries obtain delegated access to agents that can send mail and act on the user behalf, so a grant referencing access_agent indicates agent hijacking through illicit consent.

Related detections9 linkedT1528 — drag to rearrange
Malicious Assignment of a Privileged Azure AD Role (via auditlogs)
Malicious OAuth Application Granted Full Mailbox and EWS Permissions (via m365)
Suspicious GAM OAuth Token Enumeration via Process Creation
Suspicious Entra ID Device Code Flow Authentication
Suspicious Entra Cross-Tenant Access or External User Invitation via Azure Audit (via azure)
Suspicious OAuth Application Registration with Localhost Reply URL via Azure AD
Malicious PRT Token Forging via AADInternals (via ps_script)
Possible VMware Workspace ONE SSRF via instanceHealth hostName At-Injection (via webserver)
Suspicious IAM CreateLoginProfile For Root User via AWS AssumeRoot Abuse
Suspicious Delegated Permission Grant to Entra Agent Access Scope via Azure Audit Logs
Pivot detection · T1528 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.