Skip to content

Add Member To Role

Azure

Add Member To Role

service: Azure - Microsoft Entra ID
techniques:

Event

Records a directory role membership assignment. Eligible role-assignable groups can also receive directory roles. Directory roles govern Entra administration and are separate from Azure resource RBAC. Determine assignment scope and lifetime from the actual assignment/PIM records rather than the activity name alone.

Security Context

Unauthorized role grants can elevate or retain privileges (T1098.003). Legitimate administration produces the same event. A high-impact role warrants prompt verification, but the event alone does not establish compromise or a universal incident severity.

Log Source

Microsoft Entra directory audit logs with activityDisplayName: Add member to role and category: RoleManagement. Check result/resultReason and correlate stable object IDs. The sample uses Microsoft Graph directoryAudit-style JSON; Azure Monitor AuditLogs exports use different field names and casing.

Key Fields

FieldInvestigation value
targetResources, modifiedPropertiesAssigned principal, role instance ID, and role template ID; these identifiers are not interchangeable.
initiatedByAssigning identity; verify authority independently.

What to Investigate

  1. Confirm the recorded outcome and match the initiating identity, target, and timing to an approved change.
  2. Resolve the exact principal, role definition, and approved justification.
  3. Check scope, active versus eligible state, expiration, and associated PIM approvals/activation records.
  4. Correlate subsequent administrative activity. A Global Administrator directory role does not itself equal Azure subscription Owner.

Sample Event

Synthetic scenario. A successful event illustrates assigning Global Administrator to Draco. The role instance ID is distinct from its built-in template ID; the actor’s prior role and subsequent actions are not shown.

Exact field presence, target ordering, modified-property names, and payload serialization remain unverified against captured logs. Treat these examples as illustrations, not guaranteed schemas or complete change histories.

{
"id": "Directory_10000000-0000-4000-8000-000000000001_F1A2B_398214567",
"category": "RoleManagement",
"correlationId": "90000000-0000-4000-8000-000000000001",
"result": "success",
"resultReason": "",
"activityDisplayName": "Add member to role",
"activityDateTime": "2026-04-15T13:42:11Z",
"loggedByService": "Core Directory",
"operationType": "Assign",
"initiatedBy": {
"user": {
"id": "30000000-0000-4000-8000-000000000001",
"displayName": "Hermione Granger",
"userPrincipalName": "hermione@fantasticlogs.cloud",
"ipAddress": "198.51.100.42"
}
},
"targetResources": [
{
"id": "30000000-0000-4000-8000-001010011010",
"displayName": "Draco Malfoy",
"type": "User",
"userPrincipalName": "draco@fantasticlogs.cloud",
"modifiedProperties": [
{
"displayName": "Role.DisplayName",
"oldValue": null,
"newValue": "\"Global Administrator\""
},
{
"displayName": "Role.TemplateId",
"oldValue": null,
"newValue": "\"62e90394-69f5-4237-9190-012177145e10\""
},
{
"displayName": "Role.ObjectId",
"oldValue": null,
"newValue": "\"50000000-0000-4000-8000-000000000001\""
}
]
},
{
"id": "50000000-0000-4000-8000-000000000001",
"displayName": "Global Administrator",
"type": "Role",
"modifiedProperties": []
}
],
"additionalDetails": [
{
"key": "User-Agent",
"value": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/121.0.0.0 Safari/537.36"
}
]
}

Sources

MITRE ATT&CK Mapping

Tactics: Privilege Escalation Persistence

Techniques:
  • T1098.003 — Additional Cloud Roles — An adversary may add additional roles or permissions to an adversary-controlled cloud account to maintain persistent access to a tenant. For example, adversaries may update IAM policies in cloud-based environments or add a new global administrator in Office 365 environments. With sufficient permi...
Documentation reviewed: September 30, 2026. Samples are synthetic illustrations, not captured production logs or lab-validated fixtures.