Entra ID Elevated Access to User Access Administrator | Elastic Security [8.19] | Elastic

Entra ID Elevated Access to User Access Administrator

edit

IMPORTANT: This documentation is no longer updated. Refer to Elastic's version policy and the latest documentation.

Entra ID Elevated Access to User Access Administrator

Identifies when a user has elevated their access to User Access Administrator for their Azure Resources. The User Access Administrator role allows users to manage user access to Azure resources, including the ability to assign roles and permissions. Adversaries may target an Entra ID Global Administrator or other privileged role to elevate their access to User Access Administrator, which can lead to further privilege escalation and unauthorized access to sensitive resources. This is a New Terms rule that only signals if the user principal name has not been seen doing this activity in the last 14 days.

Rule type: new_terms

Rule indices:

Severity: high

Risk score: 73

Runs every: 5m

Searches indices from: now-9m ( Date Math format, see also [Additional look-back time](/content/guide/en/security/current/rules-ui-create.html#rule-schedule "Set the rule’s schedule"/index.html))

Maximum alerts per execution: 100

References:

Tags:

Version: 4

Rule authors:

Rule license: Elastic License v2

Investigation guide

Triage and Analysis

Investigating Entra ID Elevated Access to User Access Administrator

This rule identifies when a user elevates their permissions to the "User Access Administrator" role in Azure RBAC. This role allows full control over access management for Azure resources and can be abused by attackers for lateral movement, persistence, or privilege escalation. Since this is a New Terms rule, the alert will only trigger if the user has not performed this elevation in the past 14 days, helping reduce alert fatigue.

Possible investigation steps

False positive analysis

Response and remediation

Rule query

event.dataset: azure.auditlogs
    and (
      azure.auditlogs.operation_name: "User has elevated their access to User Access Administrator for their Azure Resources" or
      azure.auditlogs.properties.additional_details.value: "Microsoft.Authorization/elevateAccess/action"
    ) and event.outcome: "success"

Framework: MITRE ATT&CKTM

« Azure RBAC Built-In Administrator Roles AssignedEntra ID Domain Federation Configuration Change »

On this page

Most Popular

Video

Get Started with Elasticsearch

Video

Intro to Kibana

Video

ELK for Logs & Metrics

Was this helpful?Feedback

LikeDislike

Thank you for your feedback.

a18132920325.cdn.optimizely.com

a18132920325.cdn.optimizely.com is blocked

This page has been blocked by an extension

ERR_BLOCKED_BY_CLIENT

Reload

This page has been blocked by an extension