Suspicious UNC3944 Rogue Federated Identity Provider Added to Entra Tenant (via azure)

PremiumReviewedSigma · Medium · v1
Product
azure
Service
auditlogs
Author
HuntRule
Published
2026-06-13
Updated
2026-08-28

ATT&CK techniques

Persistence → Cred Access
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Priv Esc

  6. Discovery

  7. Lateral Movement

  8. Collection

  9. C2

  10. Exfiltration

  11. Impact

What it detects

This rule detects Azure AD/Entra directory operations that configure or modify domain federation settings, which adds or alters a trusted identity provider. UNC3944 abused hybrid identity by registering a rogue federated IdP to forge SAML tokens and impersonate any user in the tenant. Unexpected federation trust changes are a high-value indicator of a Golden SAML style backdoor.

Related detections3 linkedT1606.002 — drag to rearrange
Malicious Octo Tempest Credential Theft Tooling (via process_creation)
Malicious Storm-0558 Forged Token Sign-In from MSA Consumer Tenant (via azure signinlogs)
Malicious Octo Tempest Federation Persistence via AADInternals (via ps_script)
Suspicious UNC3944 Rogue Federated Identity Provider Added to Entra Tenant (via azure)
Pivot detection · T1606.002 · 3 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.