Add Owner To Group
Add Owner To Group
Event
Adds ownership of a group, potentially delegating management of its properties and assigned membership. Ownership does not itself make the owner a member or directly confer the group’s resource roles. Dynamic membership is rule-driven; owners cannot manually add members to a dynamic group.
Security Context
Unauthorized ownership changes may enable account manipulation (T1098). Role-assignable groups use assigned membership and additional protections; active owners can be delegated membership management. Risk depends on the group’s actual roles, assignments, and membership controls, not an administrative-sounding name.
Log Source
Microsoft Entra directory audit logs with activityDisplayName: Add owner to group and category: GroupManagement. Check result/resultReason and correlate stable object IDs. The sample uses Microsoft Graph directoryAudit-style JSON; Azure Monitor AuditLogs exports use different field names and casing.
Key Fields
| Field | Investigation value |
|---|---|
targetResources | Resolve the group and added owner by object IDs. |
targetResources[].groupType, modifiedProperties | Audit hints only; retrieve groupTypes, membership rules, and isAssignableToRole to establish configuration. |
What to Investigate
- Confirm the recorded outcome and match the initiating identity, target, and timing to an approved change.
- Verify the actor’s authority and whether ownership is active or merely eligible under PIM.
- Determine group type, membership management, role-assignability, and actual downstream role/app assignments.
- Correlate later membership changes and access. Do not infer Privileged Role Administrator membership from the name GraphornAdmins.
Sample Event
Synthetic scenario. The event illustrates adding an owner to GraphornAdmins. Role-assignability and a Privileged Role Administrator assignment are not shown; an unverified groupType value is omitted.
Exact field presence, target ordering, modified-property names, and payload serialization remain unverified against captured logs. Treat these examples as illustrations, not guaranteed schemas or complete change histories.
{ "id": "Directory_90000000-0000-4000-8000-000001101000_5F2D8_93421177", "category": "GroupManagement", "correlationId": "90000000-0000-4000-8000-000001101000", "result": "success", "resultReason": "", "activityDisplayName": "Add owner to group", "activityDateTime": "2026-04-15T18:51:42.0119445Z", "loggedByService": "Core Directory", "operationType": "Add", "initiatedBy": { "app": null, "user": { "id": "30000000-0000-4000-8000-001010011010", "displayName": "Draco Malfoy", "userPrincipalName": "draco@fantasticlogs.cloud", "ipAddress": "203.0.113.66" } }, "targetResources": [ { "id": "60000000-0000-4000-8000-000000000001", "displayName": "GraphornAdmins", "type": "Group", "userPrincipalName": null, "modifiedProperties": [ { "displayName": "Group.DisplayName", "oldValue": "[]", "newValue": "[\"GraphornAdmins\"]" }, { "displayName": "Group.ObjectId", "oldValue": "[]", "newValue": "[\"60000000-0000-4000-8000-000000000001\"]" }, { "displayName": "Group.WellKnownObjectName", "oldValue": "[]", "newValue": "[]" }, { "displayName": "Included Updated Properties", "oldValue": null, "newValue": "\"Group.DisplayName, Group.ObjectId, Group.WellKnownObjectName\"" } ] }, { "id": "30000000-0000-4000-8000-001010011010", "displayName": "Draco Malfoy", "type": "User", "userPrincipalName": "draco@fantasticlogs.cloud", "groupType": null, "modifiedProperties": [] } ], "additionalDetails": [ { "key": "User-Agent", "value": "python/3.11.6 (Linux-5.15.0-1052-aws-x86_64-with-glibc2.35) AZURECLI/2.56.0 (DEB)" } ]}Sources
MITRE ATT&CK Mapping
Tactics: Privilege Escalation Persistence
- T1098 — Account Manipulation — Adversaries may manipulate accounts to maintain and/or elevate access to victim systems. Account manipulation may consist of any action that preserves or modifies adversary access to a compromised account, such as modifying credentials or permission groups. These actions could also include accoun...