Add Owner To Application
Add Owner To Application
Event
Changes ownership of the application object. Application registration ownership and enterprise-application (service-principal) ownership are distinct. Owners can manage supported settings and credentials on their owned application; adding an owner is not itself a tenant-wide administrator assignment or a new API consent grant.
Security Context
Unauthorized ownership changes can support account manipulation (T1098), including later credential changes. Adding the owner requires existing authorization; this event is not evidence that an Application Administrator boundary was bypassed. Any resulting workload access depends on effective grants and authentication.
Log Source
Microsoft Entra directory audit logs with activityDisplayName: Add owner to application and category: ApplicationManagement. Check result/resultReason and correlate stable object IDs. The sample uses Microsoft Graph directoryAudit-style JSON; Azure Monitor AuditLogs exports use different field names and casing.
Key Fields
| Field | Investigation value |
|---|---|
targetResources | Identify the application and added owner by IDs/types rather than assuming array order. |
modifiedProperties | Ownership change where represented; compare against actual owners and prior records. |
What to Investigate
- Confirm the recorded outcome and match the initiating identity, target, and timing to an approved change.
- Verify approval, the actor’s effective authorization, and the added owner’s identity.
- Compare application and service-principal ownership independently, then inspect credential/federation and permission changes.
- Correlate workload sign-ins and resource operations before claiming use of the application’s access.
Sample Event
Synthetic scenario. Draco is illustrated as the added owner of a Phoenix-Backup application registration. The event shows neither credential creation nor a new consent grant.
Exact field presence, target ordering, modified-property names, and payload serialization remain unverified against captured logs. Treat these examples as illustrations, not guaranteed schemas or complete change histories.
{ "id": "Directory_90000000-0000-4000-8000-000001100111_4E1F2_82919011", "category": "ApplicationManagement", "correlationId": "90000000-0000-4000-8000-000001100111", "result": "success", "resultReason": "", "activityDisplayName": "Add owner to application", "activityDateTime": "2026-04-15T18:42:11.7203814Z", "loggedByService": "Core Directory", "operationType": "Add", "initiatedBy": { "app": null, "user": { "id": "30000000-0000-4000-8000-001010011010", "displayName": "Draco Malfoy", "userPrincipalName": "draco@fantasticlogs.cloud", "ipAddress": "203.0.113.66" } }, "targetResources": [ { "id": "40000000-0000-4000-8000-000000000001", "displayName": "Phoenix-Backup", "type": "Application", "userPrincipalName": null, "groupType": null, "modifiedProperties": [ { "displayName": "Owner", "oldValue": "[]", "newValue": "[\"30000000-0000-4000-8000-001010011010\"]" }, { "displayName": "Included Updated Properties", "oldValue": null, "newValue": "\"Owner\"" } ] }, { "id": "30000000-0000-4000-8000-001010011010", "displayName": "Draco Malfoy", "type": "User", "userPrincipalName": "draco@fantasticlogs.cloud", "groupType": null, "modifiedProperties": [] } ], "additionalDetails": [ { "key": "User-Agent", "value": "python/3.11.6 (Linux-5.15.0-1052-aws-x86_64-with-glibc2.35) AZURECLI/2.56.0 (DEB)" } ]}Sources
MITRE ATT&CK Mapping
Tactics: Privilege Escalation Persistence
- T1098 — Account Manipulation — Adversaries may manipulate accounts to maintain and/or elevate access to victim systems. Account manipulation may consist of any action that preserves or modifies adversary access to a compromised account, such as modifying credentials or permission groups. These actions could also include accoun...