Suspicious Entra Cross-Tenant Access or External User Invitation via Azure Audit (via azure)

PremiumReviewedSigma · Medium · v1
Product
azure
Service
auditlogs
Author
HuntRule
Published
2026-07-19
Updated
2026-08-28

ATT&CK techniques

Persistence → Priv Esc
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Defense Evasion

  6. Cred Access

  7. Discovery

  8. Lateral Movement

  9. Collection

  10. C2

  11. Exfiltration

  12. Impact

What it detects

This rule detects Entra ID operations that add cross-tenant partners, invite external users, or create access packages, overlooked entry points into Microsoft Azure that adversaries abuse for persistence per Red Canary. These identity changes can silently grant outside principals durable access to a tenant, so unexpected occurrences should be validated against approved administrative activity.

Related detections9 linkedT1098.003 — drag to rearrange
Malicious Assignment of a Privileged Azure AD Role (via auditlogs)
Suspicious Delegated Permission Grant to Entra Agent Access Scope via Azure Audit Logs
Suspicious AWS IAM User Creation Using Support Impersonation Name
Suspicious IAM CreateLoginProfile For Root User via AWS AssumeRoot Abuse
Suspicious AWS IAM Privilege Escalation via AttachUserPolicy of Administrator Policy
Suspicious Member Added to Privileged Directory Role in Entra ID
Suspicious High-Privilege Microsoft Graph Application Role Grant via Azure Audit (via azure)
GCP Google Workspace: Application ContextAwareAccess Setting Changed
GitHub Audit Log: New Organization Member Added or Invited
Suspicious Entra Cross-Tenant Access or External User Invitation via Azure Audit (via azure)
Pivot detection · T1098.003 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.