Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Detection Strategies DET0270 — Detection of Domain or Tenant Policy Modifications via AD and Identity Provider
DET0270

Detection of Domain or Tenant Policy Modifications via AD and Identity Provider

2 analytic(s) · 1 technique(s) detected

Analytics

2
AN0755 Analytic 0755
Windows

Adversary modifies Group Policy Objects (GPOs), domain trust, or directory service objects via GUI, CLI, or programmatic APIs. Behavior includes creation/modification of GPOs, delegation permissions, trust objects, or rogue domain controller registration.

WinEventLog:Security EventCode=5136 WinEventLog:Security EventCode=4663, 4670, 4656 WinEventLog:Sysmon EventCode=1
[ObjectDN] Filter to specific AD containers (e.g., CN=Policies,CN=System,DC=domain,DC=com) for GPOs.
[AttributeModified] Focus on high-risk attributes such as gPCFileSysPath, ntSecurityDescriptor.
[TimeWindow] Correlate changes with suspicious process creation or privileged user logon.
[UserContext] Alert on unexpected user or service account modifying domain policy.
AN0756 Analytic 0756
Identity Provider

Adversary modifies tenant policy through changes to federation configuration, trust settings, or identity provider additions in Microsoft 365/AzureAD via Portal, PowerShell, or Graph API. Includes setting authentication to federated or updating federated domains.

m365:unified Set federation settings on domain|Set domain authentication|Add federated identity provider azure:signinlogs OperationName=SetDomainAuthentication OR Set-FederatedDomain
[OperationName] Identify rare modification operations that are not part of standard admin lifecycle.
[InitiatedBy] Filter by known administrators or service principals. Flag unknown initiators.
[UserAgent] Detect scripted modifications (e.g., PowerShell/Graph API vs Azure Portal).
[TimeWindow] Correlate tenant policy changes with new sign-ins or token forgery attempts.

Detected Techniques

1

Details

MITRE ID
DET0270
STIX ID
x-mitre-detection-strategy--3eb428c7-5192-4ae2-a5a3-022ca9695ec8
Analytics
2
Techniques Detected
1
By Tactic
Defense Impairment
1
Leaving Threaticon

This link opens an external site that isn't part of the platform.