SIEM × Platform · Sentinel · Entra ID Audit

Sentinel detections for Entra ID Audit

Last reviewed:

Sigma rule outputs from CloudSigma rendered into Sentinel queries against the Entra ID Audit schema. Every rule is mapped to MITRE ATT&CK and validated against its dialect.

01 Coverage at a glance
5
Production rules
3
ATT&CK techniques
3
ATT&CK tactics
Sentinel
Output dialect
02 Rule index
Technique Rule Severity Log source
T1078.004 Valid Accounts: Cloud Accounts on Entra ID Audit medium Entra ID Audit
T1098 Account Manipulation on Entra ID Audit medium Entra ID Audit
T1098 Account Manipulation on Entra ID Audit medium Entra ID Audit
T1098 Account Manipulation on Entra ID Audit medium Entra ID Audit
T1528 Steal Application Access Token on Entra ID Audit medium Entra ID Audit
03 Example rule

Entra ID Privileged Role Assignment, generated by CloudSigma and validated against the Sentinel dialect.

L1 · production verified 2026-06-06 · sha256:6fe1a48006e752f4 Verify in CloudSigma →
Sigma rule · CloudSigma Sentinel · Entra ID Audit · 2026-02-09
title: Entra ID Privileged Role Assignment
id: 444fbbdb-07dd-49da-897b-2a97ad54b9e7
status: test
description: >
    Detects assignment of privileged directory roles in Entra ID such as
    Global Administrator or Privileged Role Administrator. Attackers may
    escalate privileges by assigning admin roles to compromised accounts.
author: CloudSigma
date: 2026-02-09
references:
    - https://attack.mitre.org/techniques/T1098/
    - https://learn.microsoft.com/en-us/entra/identity/monitoring-health/concept-audit-logs
tags:
    - attack.persistence
    - attack.privilege-escalation
    - attack.t1098
logsource:
    product: azure
    service: auditlogs
detection:
    selection:
        properties.operationType: Add
        properties.targetResources[].type: Role
    selection_privileged:
        properties.targetResources[].displayName|contains:
            - Global Administrator
            - Privileged Role Administrator
            - Application Administrator
            - Exchange Administrator
    condition: selection and selection_privileged
falsepositives:
    - Legitimate Privileged Identity Management (PIM) activations
    - IT team onboarding new global administrators
level: critical
Sources
  • Sigma project, https://github.com/SigmaHQ/sigma
  • Sentinel documentation, https://docs.sentinel.com/
Last verified: 2026-06-06