Suspicious High-Privilege Microsoft Graph Application Role Grant via Azure Audit (via azure)

PremiumReviewedSigma · High · v1
Product
azure
Service
auditlogs
Author
HuntRule
Published
2026-05-03
Updated
2026-08-28

ATT&CK techniques

Persistence → Lateral Movement
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Cred Access

  6. Discovery

  7. Collection

  8. C2

  9. Exfiltration

  10. Impact

What it detects

This rule detects the assignment of high-privilege Microsoft Graph application roles such as AppRoleAssignment.ReadWrite.All, Directory.ReadWrite.All, or RoleManagement.ReadWrite.Directory to a service principal, an escalation path into Azure highlighted by Red Canary. Granting these permissions lets an app rewrite directory roles and grant itself further access, making it a powerful and stealthy persistence mechanism that should be tightly controlled.

Related detections9 linkedT1098.003 — drag to rearrange
Malicious Assignment of a Privileged Azure AD Role (via auditlogs)
Suspicious Entra Cross-Tenant Access or External User Invitation via Azure Audit (via azure)
Suspicious Delegated Permission Grant to Entra Agent Access Scope via Azure Audit Logs
Suspicious IAM CreateLoginProfile For Root User via AWS AssumeRoot Abuse
Suspicious AWS IAM Privilege Escalation via AttachUserPolicy of Administrator Policy
Suspicious Member Added to Privileged Directory Role in Entra ID
GCP Google Workspace: Application ContextAwareAccess Setting Changed
GitHub Audit: Outside Collaborator Membership and Permission Changes
Azure Audit Logs: Admin-initiated App Role Assignments and Privileged Delegated Permissions
Suspicious High-Privilege Microsoft Graph Application Role Grant via Azure Audit (via azure)
Pivot detection · T1098.003 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.