Temporary Access Pass Added To An Account
Last updated on:
In this page
About the rule
Rule Type
Standard
Rule Description
Detects when a temporary access pass (TAP) is added to an account. TAPs added to priv accounts should be investigated.
Severity
Critical
Rule Requirement
Criteria
Action1: actionname = "DETECTION_ACTION_M365_AUTH_METHOD_CHANGED_FOR_USER" AND (STATUS_OF_OPERATION contains "registered temporary access pass method") select Action1.CALLER,Action1.TARGET,Action1.RESULT,Action1.MODIFIED_PROPERTIES_GD,Action1.STATUS_OF_OPERATION,Action1.TARGET_ID,Action1.OPERATION
Detection
Execution Mode
realtime
Log Sources
Microsoft 365
Author
Mark Morowczynski '@markmorow', Yochana Henderson, '@Yochana-H'


