Skip to content

[New Rule] Azure Modify Trusted Domains #888

@bm11100

Description

@bm11100

Description

Hardening Strategies for Microsoft 365 to Defend Against UNC2452 - thanks to @dstepanic17 for sharing the whitepaper.

The Azure AD Audit log and Unified Audit log records when a domain is configured for federated authentication and the modification of federated realm objects. In most organizations, domain federation settings will be updated infrequently. Organizations should create rules to alert on the log events generated by these activities and audit them to ensure they are legitimate.

Required Info

  • Eventing Sources:
  • Target Operating Systems:
  • Platforms
  • Target ECS Version: x.x.x
  • New fields required in ECS for this?
  • Related issues or PRs

Optional Info

Example Data

“Operation”: “Set domain authentication.”
“Operation”: “Set federation settings on domain.”

Metadata

Metadata

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions