Azure Management Group or Subscription Hierarchy Modification (T1666)

Detects high-impact configuration changes to Azure management groups or subscriptions (e.g., write/delete operations) that are performed by non-privileged accounts or outside of defined business change windows. This activity can indicate unauthorized privilege escalation, resource manipulation, or reconnaissance by an adversary.