Add Member To Role
Add Member To Role
Event
Records a directory role membership assignment. Eligible role-assignable groups can also receive directory roles. Directory roles govern Entra administration and are separate from Azure resource RBAC. Determine assignment scope and lifetime from the actual assignment/PIM records rather than the activity name alone.
Security Context
Unauthorized role grants can elevate or retain privileges (T1098.003). Legitimate administration produces the same event. A high-impact role warrants prompt verification, but the event alone does not establish compromise or a universal incident severity.
Log Source
Microsoft Entra directory audit logs with activityDisplayName: Add member to role and category: RoleManagement. Check result/resultReason and correlate stable object IDs. The sample uses Microsoft Graph directoryAudit-style JSON; Azure Monitor AuditLogs exports use different field names and casing.
Key Fields
| Field | Investigation value |
|---|---|
targetResources, modifiedProperties | Assigned principal, role instance ID, and role template ID; these identifiers are not interchangeable. |
initiatedBy | Assigning identity; verify authority independently. |
What to Investigate
- Confirm the recorded outcome and match the initiating identity, target, and timing to an approved change.
- Resolve the exact principal, role definition, and approved justification.
- Check scope, active versus eligible state, expiration, and associated PIM approvals/activation records.
- Correlate subsequent administrative activity. A Global Administrator directory role does not itself equal Azure subscription Owner.
Sample Event
Synthetic scenario. A successful event illustrates assigning Global Administrator to Draco. The role instance ID is distinct from its built-in template ID; the actor’s prior role and subsequent actions are not shown.
Exact field presence, target ordering, modified-property names, and payload serialization remain unverified against captured logs. Treat these examples as illustrations, not guaranteed schemas or complete change histories.
{ "id": "Directory_10000000-0000-4000-8000-000000000001_F1A2B_398214567", "category": "RoleManagement", "correlationId": "90000000-0000-4000-8000-000000000001", "result": "success", "resultReason": "", "activityDisplayName": "Add member to role", "activityDateTime": "2026-04-15T13:42:11Z", "loggedByService": "Core Directory", "operationType": "Assign", "initiatedBy": { "user": { "id": "30000000-0000-4000-8000-000000000001", "displayName": "Hermione Granger", "userPrincipalName": "hermione@fantasticlogs.cloud", "ipAddress": "198.51.100.42" } }, "targetResources": [ { "id": "30000000-0000-4000-8000-001010011010", "displayName": "Draco Malfoy", "type": "User", "userPrincipalName": "draco@fantasticlogs.cloud", "modifiedProperties": [ { "displayName": "Role.DisplayName", "oldValue": null, "newValue": "\"Global Administrator\"" }, { "displayName": "Role.TemplateId", "oldValue": null, "newValue": "\"62e90394-69f5-4237-9190-012177145e10\"" }, { "displayName": "Role.ObjectId", "oldValue": null, "newValue": "\"50000000-0000-4000-8000-000000000001\"" } ] }, { "id": "50000000-0000-4000-8000-000000000001", "displayName": "Global Administrator", "type": "Role", "modifiedProperties": [] } ], "additionalDetails": [ { "key": "User-Agent", "value": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/121.0.0.0 Safari/537.36" } ]}Sources
MITRE ATT&CK Mapping
Tactics: Privilege Escalation Persistence
- T1098.003 — Additional Cloud Roles — An adversary may add additional roles or permissions to an adversary-controlled cloud account to maintain persistent access to a tenant. For example, adversaries may update IAM policies in cloud-based environments or add a new global administrator in Office 365 environments. With sufficient permi...