Azure Privileged Role Assignment Outside PIM (T1098.003)
Detects instances where a user or service principal is assigned to high-privilege roles (e.g., Global Administrator, Owner) without utilizing the Microsoft Entra Privileged Identity Management (PIM) service. This is indicated by the absence of 'PIM' in the LoggedByService field for a successful 'Add member to role' operation, which could signify an attempt to bypass established access controls and gain unauthorized elevated persistence.
Microsoft Sentinel (KQL)

