Skip to content

Add Verified Domain

Azure

Add Verified Domain

service: Azure - Microsoft Entra ID
tactics:
techniques:

Event

Records verified-domain state, rather than merely initiating domain addition. Verification establishes domain ownership through the supported verification process. Managed versus Federated authentication is separate configuration; the sample shows Managed.

Security Context

Unexpected domain verification merits investigation, but verification alone is not a federation-trust change or proof of forged SAML tokens. No ATT&CK technique is assigned to this event alone. Approved custom-domain onboarding is routine.

Log Source

Microsoft Entra directory audit logs. The sample uses activityDisplayName: Add verified domain. Match target IDs and result, not a display name alone; Microsoft Graph-style JSON and Azure Monitor exports use different wrappers/casing.

Key Fields

FieldInvestigation value
targetResources[].id, modifiedPropertiesDomain name, IsVerified, and authentication type where present.

What to Investigate

  1. Confirm the recorded outcome and compare actor, target, and timing with the approved workflow.
  2. Verify domain ownership and the approved tenant onboarding request.
  3. Inspect actual domain authentication settings and any separate federation configuration changes.
  4. Correlate new user identifiers and sign-ins. Do not infer a DNS record type, an earlier event, or tenant-wide impersonation from this record.

Sample Event

Synthetic scenario. The sample shows a domain becoming verified with Managed authentication. It does not prove a specific DNS verification path or any federation change.

Exact field presence, modified-property names, payload nesting, and timestamp formatting remain unverified against captured logs. Names and illustrative identifiers do not prove intent or downstream activity.

{
"id": "Directory_90000000-0000-4000-8000-000001101101_3A8C1_72584931",
"category": "DirectoryManagement",
"correlationId": "90000000-0000-4000-8000-000001101101",
"result": "success",
"resultReason": "",
"activityDisplayName": "Add verified domain",
"activityDateTime": "2026-04-15T11:32:18.5072194Z",
"loggedByService": "Core Directory",
"operationType": "Update",
"initiatedBy": {
"app": null,
"user": {
"id": "30000000-0000-4000-8000-000000000001",
"displayName": "Hermione Granger",
"userPrincipalName": "hermione@fantasticlogs.cloud",
"ipAddress": "198.51.100.42"
}
},
"targetResources": [
{
"id": "partners.fantasticlogs.cloud",
"displayName": "partners.fantasticlogs.cloud",
"userPrincipalName": null,
"groupType": null,
"modifiedProperties": [
{
"displayName": "DomainName",
"oldValue": "[]",
"newValue": "[\"partners.fantasticlogs.cloud\"]"
},
{
"displayName": "IsVerified",
"oldValue": "[false]",
"newValue": "[true]"
},
{
"displayName": "AuthenticationType",
"oldValue": "[]",
"newValue": "[\"Managed\"]"
},
{
"displayName": "IsDefault",
"oldValue": "[]",
"newValue": "[false]"
},
{
"displayName": "Included Updated Properties",
"oldValue": null,
"newValue": "\"DomainName, IsVerified, AuthenticationType, IsDefault\""
}
]
}
],
"additionalDetails": [
{
"key": "User-Agent",
"value": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/121.0.0.0 Safari/537.36"
}
]
}

Sources

Documentation reviewed: October 4, 2026. Samples are synthetic illustrations, not captured production logs or lab-validated fixtures.