Temporary Access Pass Added To An Account

Last updated on:

About the rule

Rule Type

Standard

Rule Description

Detects when a temporary access pass (TAP) is added to an account. TAPs added to priv accounts should be investigated.

Severity

Critical

Rule Requirement

Criteria

Action1: actionname = "DETECTION_ACTION_M365_AUTH_METHOD_CHANGED_FOR_USER" AND (STATUS_OF_OPERATION contains "registered temporary access pass method") select Action1.CALLER,Action1.TARGET,Action1.RESULT,Action1.MODIFIED_PROPERTIES_GD,Action1.STATUS_OF_OPERATION,Action1.TARGET_ID,Action1.OPERATION

Detection

Execution Mode

realtime

Log Sources

Microsoft 365

Author

Mark Morowczynski '@markmorow', Yochana Henderson, '@Yochana-H'