Skip to content

Add Owner To Group

Azure

Add Owner To Group

service: Azure - Microsoft Entra ID
techniques:

Event

Adds ownership of a group, potentially delegating management of its properties and assigned membership. Ownership does not itself make the owner a member or directly confer the group’s resource roles. Dynamic membership is rule-driven; owners cannot manually add members to a dynamic group.

Security Context

Unauthorized ownership changes may enable account manipulation (T1098). Role-assignable groups use assigned membership and additional protections; active owners can be delegated membership management. Risk depends on the group’s actual roles, assignments, and membership controls, not an administrative-sounding name.

Log Source

Microsoft Entra directory audit logs with activityDisplayName: Add owner to group and category: GroupManagement. Check result/resultReason and correlate stable object IDs. The sample uses Microsoft Graph directoryAudit-style JSON; Azure Monitor AuditLogs exports use different field names and casing.

Key Fields

FieldInvestigation value
targetResourcesResolve the group and added owner by object IDs.
targetResources[].groupType, modifiedPropertiesAudit hints only; retrieve groupTypes, membership rules, and isAssignableToRole to establish configuration.

What to Investigate

  1. Confirm the recorded outcome and match the initiating identity, target, and timing to an approved change.
  2. Verify the actor’s authority and whether ownership is active or merely eligible under PIM.
  3. Determine group type, membership management, role-assignability, and actual downstream role/app assignments.
  4. Correlate later membership changes and access. Do not infer Privileged Role Administrator membership from the name GraphornAdmins.

Sample Event

Synthetic scenario. The event illustrates adding an owner to GraphornAdmins. Role-assignability and a Privileged Role Administrator assignment are not shown; an unverified groupType value is omitted.

Exact field presence, target ordering, modified-property names, and payload serialization remain unverified against captured logs. Treat these examples as illustrations, not guaranteed schemas or complete change histories.

{
"id": "Directory_90000000-0000-4000-8000-000001101000_5F2D8_93421177",
"category": "GroupManagement",
"correlationId": "90000000-0000-4000-8000-000001101000",
"result": "success",
"resultReason": "",
"activityDisplayName": "Add owner to group",
"activityDateTime": "2026-04-15T18:51:42.0119445Z",
"loggedByService": "Core Directory",
"operationType": "Add",
"initiatedBy": {
"app": null,
"user": {
"id": "30000000-0000-4000-8000-001010011010",
"displayName": "Draco Malfoy",
"userPrincipalName": "draco@fantasticlogs.cloud",
"ipAddress": "203.0.113.66"
}
},
"targetResources": [
{
"id": "60000000-0000-4000-8000-000000000001",
"displayName": "GraphornAdmins",
"type": "Group",
"userPrincipalName": null,
"modifiedProperties": [
{
"displayName": "Group.DisplayName",
"oldValue": "[]",
"newValue": "[\"GraphornAdmins\"]"
},
{
"displayName": "Group.ObjectId",
"oldValue": "[]",
"newValue": "[\"60000000-0000-4000-8000-000000000001\"]"
},
{
"displayName": "Group.WellKnownObjectName",
"oldValue": "[]",
"newValue": "[]"
},
{
"displayName": "Included Updated Properties",
"oldValue": null,
"newValue": "\"Group.DisplayName, Group.ObjectId, Group.WellKnownObjectName\""
}
]
},
{
"id": "30000000-0000-4000-8000-001010011010",
"displayName": "Draco Malfoy",
"type": "User",
"userPrincipalName": "draco@fantasticlogs.cloud",
"groupType": null,
"modifiedProperties": []
}
],
"additionalDetails": [
{
"key": "User-Agent",
"value": "python/3.11.6 (Linux-5.15.0-1052-aws-x86_64-with-glibc2.35) AZURECLI/2.56.0 (DEB)"
}
]
}

Sources

MITRE ATT&CK Mapping

Tactics: Privilege Escalation Persistence

Techniques:
  • T1098 — Account Manipulation — Adversaries may manipulate accounts to maintain and/or elevate access to victim systems. Account manipulation may consist of any action that preserves or modifies adversary access to a compromised account, such as modifying credentials or permission groups. These actions could also include accoun...
Documentation reviewed: September 30, 2026. Samples are synthetic illustrations, not captured production logs or lab-validated fixtures.