Azure new owner added for service principal

Set up the azure integration.

This page is not yet available in Spanish. We are working on its translation.
If you have any questions or feedback about our current translation project, feel free to reach out to us!

Goal

Detect when a new owner is added to a service principal, which applies to privilege escalation or persistence.

Strategy

Monitor Azure Active Directory logs where @evt.name is "Add owner to service principal" and @evt.outcome of Success.

Triage and response

  1. Inspect that the user is added to a service principal in @properties.targetResources.
  2. Verify with the user ({{@usr.name}}) to determine if the owner addition is legitimate.