LoFP LoFP / when the permission is legitimately needed for the app

Techniques

Sample rules

Delegated Permissions Granted For All Users

Description

Detects when highly privileged delegated permissions are granted on behalf of all users

Detection logic

condition: selection
selection:
  properties.message: Add delegated permission grant

App Role Added

Description

Detects when an app is assigned Azure AD roles, such as global administrator, or Azure RBAC roles, such as subscription owner.

Detection logic

condition: selection
selection:
  properties.message:
  - Add member to role
  - Add eligible member to role
  - Add scoped member to role

App Granted Privileged Delegated Or App Permissions

Description

Detects when administrator grants either application permissions (app roles) or highly privileged delegated permissions

Detection logic

condition: selection
selection:
  properties.message: Add app role assignment to service principal

App Granted Microsoft Permissions

Description

Detects when an application is granted delegated or app role permissions for Microsoft Graph, Exchange, Sharepoint, or Azure AD

Detection logic

condition: selection
selection:
  properties.message:
  - Add delegated permission grant
  - Add app role assignment to service principal