Skip to content

Add Owner To Application

Azure

Add Owner To Application

service: Azure - Microsoft Entra ID
techniques:

Event

Changes ownership of the application object. Application registration ownership and enterprise-application (service-principal) ownership are distinct. Owners can manage supported settings and credentials on their owned application; adding an owner is not itself a tenant-wide administrator assignment or a new API consent grant.

Security Context

Unauthorized ownership changes can support account manipulation (T1098), including later credential changes. Adding the owner requires existing authorization; this event is not evidence that an Application Administrator boundary was bypassed. Any resulting workload access depends on effective grants and authentication.

Log Source

Microsoft Entra directory audit logs with activityDisplayName: Add owner to application and category: ApplicationManagement. Check result/resultReason and correlate stable object IDs. The sample uses Microsoft Graph directoryAudit-style JSON; Azure Monitor AuditLogs exports use different field names and casing.

Key Fields

FieldInvestigation value
targetResourcesIdentify the application and added owner by IDs/types rather than assuming array order.
modifiedPropertiesOwnership change where represented; compare against actual owners and prior records.

What to Investigate

  1. Confirm the recorded outcome and match the initiating identity, target, and timing to an approved change.
  2. Verify approval, the actor’s effective authorization, and the added owner’s identity.
  3. Compare application and service-principal ownership independently, then inspect credential/federation and permission changes.
  4. Correlate workload sign-ins and resource operations before claiming use of the application’s access.

Sample Event

Synthetic scenario. Draco is illustrated as the added owner of a Phoenix-Backup application registration. The event shows neither credential creation nor a new consent grant.

Exact field presence, target ordering, modified-property names, and payload serialization remain unverified against captured logs. Treat these examples as illustrations, not guaranteed schemas or complete change histories.

{
"id": "Directory_90000000-0000-4000-8000-000001100111_4E1F2_82919011",
"category": "ApplicationManagement",
"correlationId": "90000000-0000-4000-8000-000001100111",
"result": "success",
"resultReason": "",
"activityDisplayName": "Add owner to application",
"activityDateTime": "2026-04-15T18:42:11.7203814Z",
"loggedByService": "Core Directory",
"operationType": "Add",
"initiatedBy": {
"app": null,
"user": {
"id": "30000000-0000-4000-8000-001010011010",
"displayName": "Draco Malfoy",
"userPrincipalName": "draco@fantasticlogs.cloud",
"ipAddress": "203.0.113.66"
}
},
"targetResources": [
{
"id": "40000000-0000-4000-8000-000000000001",
"displayName": "Phoenix-Backup",
"type": "Application",
"userPrincipalName": null,
"groupType": null,
"modifiedProperties": [
{
"displayName": "Owner",
"oldValue": "[]",
"newValue": "[\"30000000-0000-4000-8000-001010011010\"]"
},
{
"displayName": "Included Updated Properties",
"oldValue": null,
"newValue": "\"Owner\""
}
]
},
{
"id": "30000000-0000-4000-8000-001010011010",
"displayName": "Draco Malfoy",
"type": "User",
"userPrincipalName": "draco@fantasticlogs.cloud",
"groupType": null,
"modifiedProperties": []
}
],
"additionalDetails": [
{
"key": "User-Agent",
"value": "python/3.11.6 (Linux-5.15.0-1052-aws-x86_64-with-glibc2.35) AZURECLI/2.56.0 (DEB)"
}
]
}

Sources

MITRE ATT&CK Mapping

Tactics: Privilege Escalation Persistence

Techniques:
  • T1098 — Account Manipulation — Adversaries may manipulate accounts to maintain and/or elevate access to victim systems. Account manipulation may consist of any action that preserves or modifies adversary access to a compromised account, such as modifying credentials or permission groups. These actions could also include accoun...
Documentation reviewed: September 30, 2026. Samples are synthetic illustrations, not captured production logs or lab-validated fixtures.