App Assigned To Azure RBAC/Microsoft Entra Role
Description
Detects when an app is assigned Azure AD roles, such as global administrator, or Azure RBAC roles, such as subscription owner.
Query · sigma
selection: targetResources.type: Service Principal properties.message: - Add member to role - Add eligible member to role - Add scoped member to role condition: selection
Known false positives
- When the permission is legitimately needed for the app