Techniques › T1098.005 › AN0103
AN0103 Analytic 0103
Identity Provider · attack.mitre.org · ATT&CK Enterprise v19.2
<p>Adversary registers new devices to compromised user accounts to bypass MFA or conditional access policies via Azure Entra ID, Okta, or Duo self-enrollment portals.</p>
- Detects
- T1098.005 Device Registration
- Part of
- DET0036 Suspicious Device Registration via Entra ID or MFA Platform
Log sources and channels
Exactly as MITRE states them in x_mitre_log_source_references. Where a channel is vague, it is vague in the source; kevmap does not tidy it.
| Log source | Channel | Data component |
|---|---|---|
| azure:audit | Operation IN ("Add device", "Add registered users to device", "Add registered owner to device") | DC0010 User Account Modification |
| ApplicationLog:EntraIDPortal | DeviceRegistration events | DC0038 Application Log Content |
| azure:audit | New device object creation | DC0087 Active Directory Object Creation |
Mutable elements
Parameters MITRE marks as environment-specific. These are the knobs you are expected to tune; they are why an analytic is not a rule.
| Field | Description |
|---|---|
ActorUserPrincipalName | Define expected admin users to exclude known enrollment behavior |
IP Address | Scope internal vs. external device enrollment sources |
TimeWindow | Adjust for expected hours of legitimate self-enrollment |