2026 Critical Enterprise Intrusion Chain Detection: Privileged Directory Role Assignment to Recently Compromised Identity
Detects the assignment of high-privilege Entra ID directory roles (e.g., Global Administrator) to identities that either have a recent risky sign-in history or were created within the last 48 hours. This pattern is indicative of privilege escalation following account compromise or the creation of backdoored accounts by an attacker. Assignments including change management tracking tags are excluded to reduce noise.
Microsoft Sentinel (KQL)

