Azure Management Group or Subscription Hierarchy Modification (T1666)
Detects high-impact configuration changes to Azure management groups or subscriptions (e.g., write/delete operations) that are performed by non-privileged accounts or outside of defined business change windows. This activity can indicate unauthorized privilege escalation, resource manipulation, or reconnaissance by an adversary.
Microsoft Sentinel (KQL)

