Azure AD Privileged Role Assignment Detection
Detects successful assignment of highly privileged roles (Global Administrator, Privileged Role Administrator, Security Administrator, Exchange Administrator) to a user in Microsoft Entra ID (formerly Azure AD). This is often a sign of privilege escalation or persistence establishment by an attacker.
Microsoft Sentinel (KQL)

