Azure Subscription Permission Elevation Via AuditLogs
Description
Detects when a user has been elevated to manage all Azure Subscriptions. This change should be investigated immediately if it isn't planned. This setting could allow an attacker access to Azure subscriptions in your environment.
Query · sigma
selection: Category: Administrative OperationName: Assigns the caller to user access admin condition: selection
Known false positives
- If this was approved by System Administrator.