User Added To Group With CA Policy Modification Access

Last updated on:

Applies to: Log360Log360 Cloud

About the rule

Rule Type

Standard

Rule Description

Monitor and alert on group membership additions of groups that have CA policy modification access

Severity

Trouble

Rule Requirement

Criteria

Action1: actionname = "Group Member Added" select Action1.CALLER,Action1.TARGET,Action1.RESULT,Action1.RESOURCE,Action1.OPERATION

Detection

Execution Mode

realtime

Log Sources

Microsoft 365

Author

Mark Morowczynski '@markmorow', Thomas Detzner '@tdetzner'