Skip to content

Add User

Azure

Add User

service: Azure - Microsoft Entra ID
tactics:
techniques:

Event

Records user creation. Resolve whether the identity is cloud-managed, synchronized, or externally provisioned and inspect its enabled state and user type. Creating a user does not itself assign an administrator role, license, or application entitlement.

Security Context

An unauthorized new cloud user can provide persistence (T1136.003). Onboarding and provisioning are common legitimate causes. The event does not expose usable credentials or prove sign-in succeeded; enabled status alone does not bypass authentication policies.

Log Source

Microsoft Entra directory audit logs with activityDisplayName: Add user and category: UserManagement. Check result/resultReason and correlate stable object IDs. The sample uses Microsoft Graph directoryAudit-style JSON; Azure Monitor AuditLogs exports use different field names and casing.

Key Fields

FieldInvestigation value
targetResources[].id, userPrincipalNameNew user’s stable object ID and sign-in name.
targetResources[].modifiedPropertiesRecorded attributes, such as AccountEnabled and UserType; not a guaranteed complete profile.

What to Investigate

  1. Confirm the recorded outcome and match the initiating identity, target, and timing to an approved change.
  2. Match the user to an approved identity/provisioning request and verify the initiating identity’s authority.
  3. Inspect actual group membership, directory roles, licenses, and app assignments separately.
  4. Correlate authentication-method registration, sign-ins, and downstream activity; avoid inferring the administrator’s role from their name.

Sample Event

Synthetic scenario. The sample records creation of an enabled Member user. Contractor status, administrator role, and the exact client interface are not established by the record.

Exact field presence, target ordering, modified-property names, and payload serialization remain unverified against captured logs. Treat these examples as illustrations, not guaranteed schemas or complete change histories.

{
"id": "Directory_90000000-0000-4000-8000-000000000010_3F8AA_30277124",
"category": "UserManagement",
"correlationId": "90000000-0000-4000-8000-000000000010",
"result": "success",
"resultReason": "",
"activityDisplayName": "Add user",
"activityDateTime": "2026-04-15T14:08:42.1827341Z",
"loggedByService": "Core Directory",
"operationType": "Add",
"initiatedBy": {
"app": null,
"user": {
"id": "30000000-0000-4000-8000-000000000001",
"displayName": "Hermione Granger",
"userPrincipalName": "hermione@fantasticlogs.cloud",
"ipAddress": "198.51.100.42"
}
},
"targetResources": [
{
"id": "30000000-0000-4000-8000-000000000111",
"displayName": "Luna Lovegood",
"type": "User",
"userPrincipalName": "luna@fantasticlogs.cloud",
"groupType": null,
"modifiedProperties": [
{
"displayName": "AccountEnabled",
"oldValue": "[]",
"newValue": "[true]"
},
{
"displayName": "DisplayName",
"oldValue": "[]",
"newValue": "[\"Luna Lovegood\"]"
},
{
"displayName": "UserPrincipalName",
"oldValue": "[]",
"newValue": "[\"luna@fantasticlogs.cloud\"]"
},
{
"displayName": "UserType",
"oldValue": "[]",
"newValue": "[\"Member\"]"
},
{
"displayName": "Included Updated Properties",
"oldValue": null,
"newValue": "\"AccountEnabled, DisplayName, UserPrincipalName, UserType\""
}
]
}
],
"additionalDetails": [
{
"key": "User-Agent",
"value": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/121.0.0.0 Safari/537.36"
}
]
}

Sources

MITRE ATT&CK Mapping

Tactics: Persistence

Techniques:
  • T1136.003 — Cloud Account — Adversaries may create a cloud account to maintain access to victim systems. With a sufficient level of access, such accounts may be used to establish secondary credentialed access that does not require persistent remote access tools to be deployed on the system.
Documentation reviewed: September 30, 2026. Samples are synthetic illustrations, not captured production logs or lab-validated fixtures.