---
title: BeyondTrust Identity Security Insights privileged access change detected
description: Datadog, the leading service for cloud-scale monitoring.
breadcrumbs: >-
  Docs > Datadog Security > OOTB Rules > BeyondTrust Identity Security Insights
  privileged access change detected
---

> For the complete documentation index, see [llms.txt](https://docs.datadoghq.com/llms.txt).

# BeyondTrust Identity Security Insights privileged access change detected

{% alert level="danger" %}
This rule is part of a beta feature. To learn more, [contact Support](https://docs.datadoghq.com/help/).
{% /alert %}
Classification:attack 
## Goal{% #goal %}

Detect changes to privileged access assignments that may increase risk by granting elevated permissions.

## Strategy{% #strategy %}

Monitor identity activity for modifications to privileged roles, policies, or permissions. This detection focuses on identifying unexpected or high-impact privilege changes that could enable unauthorized access, persistence, or misuse of administrative capabilities.

## Triage and Response{% #triage-and-response %}

1. Identify the account `{{@entityName}}` associated with the privileged access change.
1. Review the information associated with the alert to understand the nature and potential impact of the activity.
1. Validate whether the change aligns with approved access requests and organizational governance processes.
1. If the activity is suspicious, take appropriate remediation actions in accordance with established incident response procedures.
