LoFP LoFP / it administrators promote users to organization admin during onboarding, staffing changes, or incident response. verify that the target user should hold org admin privileges, and that a change request exists when policy requires one.

Techniques

Sample rules

Anthropic Admin Role Assigned to User

Description

The organization admin role controls organization settings, integrations, membership, and security configuration in Anthropic Claude for Enterprise. Membership role changes are reported as claude_user_role_updated with anthropic.audit.current_role. An attacker can promote a compromised or newly invited account to org admin to turn initial access into durable control-plane access. From admin, they can disable SSO, mint admin API keys for automation, start data exports, and weaken audit logging. Workspace-scoped role_assignment_granted grants (for example bare admin on a workspace) are out of scope for this rule.

Detection logic

from logs-anthropic.audit-* metadata _id, _version, _index
| where
    data_stream.dataset == "anthropic.audit" and
    mv_contains(event.category, "iam") and
    event.action == "claude_user_role_updated" and
    anthropic.audit.current_role == "admin"
| keep _id, _version, _index, @timestamp, event.*, organization.*, user.*, source.*, user_agent.*, anthropic.audit.*, data_stream.*