AuditLogs
| where Category =~ "AzureRBACRoleManagementElevateAccess"
| where ActivityDisplayName =~ "User has elevated their access to User Access Administrator for their Azure Resources"
| extend Actor = tostring(InitiatedBy.user.userPrincipalName)
| extend IPAddress = tostring(InitiatedBy.user.ipAddress)
| project
TimeGenerated,
Actor,
OperationName,
IPAddress,
Result,
LoggedByService
suppressionDuration: PT5H
enabled: true
alertRuleTemplateName:
name: Azure RBAC (Elevate Access)
tactics:
- PrivilegeEscalation
query: |
AuditLogs
| where Category =~ "AzureRBACRoleManagementElevateAccess"
| where ActivityDisplayName =~ "User has elevated their access to User Access Administrator for their Azure Resources"
| extend Actor = tostring(InitiatedBy.user.userPrincipalName)
| extend IPAddress = tostring(InitiatedBy.user.ipAddress)
| project
TimeGenerated,
Actor,
OperationName,
IPAddress,
Result,
LoggedByService
requiredDataConnectors:
- dataTypes:
- AuditLogs
connectorId: AzureActiveDirectory
description: |
'Detects when a Global Administrator elevates access to all subscriptions and management groups in a tenant. When a Global Administrator elevates access they are assigned the User Access Administrator role at root scope. This Microsoft Sentinel Analytic Rule monitors who has elevated access in your tenant so that admins can take appropriate action. [Learn more](https://learn.microsoft.com/en-us/azure/role-based-access-control/elevate-access-global-admin?tabs=azure-portal)'
id: 132fdff4-c044-4855-a390-c1b71e0f833b
kind: Scheduled
triggerThreshold: 0
incidentConfiguration:
groupingConfiguration:
lookbackDuration: PT5H
groupByEntities: []
matchingMethod: AllEntities
groupByAlertDetails: []
reopenClosedIncident: false
groupByCustomDetails: []
enabled: false
createIncident: true
queryFrequency: 2h
OriginalUri: https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Microsoft Entra ID/Analytic Rules/AzureRBAC.yaml
queryPeriod: 2h
triggerOperator: GreaterThan
eventGroupingSettings:
aggregationKind: SingleAlert
relevantTechniques:
- T1078
suppressionEnabled: false
entityMappings:
- fieldMappings:
- identifier: Name
columnName: Actor
entityType: Account
- fieldMappings:
- identifier: Address
columnName: IPAddress
entityType: IP
version: 1.0.0
severity: High