Add Verified Domain
Add Verified Domain
Event
Records verified-domain state, rather than merely initiating domain addition. Verification establishes domain ownership through the supported verification process. Managed versus Federated authentication is separate configuration; the sample shows Managed.
Security Context
Unexpected domain verification merits investigation, but verification alone is not a federation-trust change or proof of forged SAML tokens. No ATT&CK technique is assigned to this event alone. Approved custom-domain onboarding is routine.
Log Source
Microsoft Entra directory audit logs. The sample uses activityDisplayName: Add verified domain. Match target IDs and result, not a display name alone; Microsoft Graph-style JSON and Azure Monitor exports use different wrappers/casing.
Key Fields
| Field | Investigation value |
|---|---|
targetResources[].id, modifiedProperties | Domain name, IsVerified, and authentication type where present. |
What to Investigate
- Confirm the recorded outcome and compare actor, target, and timing with the approved workflow.
- Verify domain ownership and the approved tenant onboarding request.
- Inspect actual domain authentication settings and any separate federation configuration changes.
- Correlate new user identifiers and sign-ins. Do not infer a DNS record type, an earlier event, or tenant-wide impersonation from this record.
Sample Event
Synthetic scenario. The sample shows a domain becoming verified with Managed authentication. It does not prove a specific DNS verification path or any federation change.
Exact field presence, modified-property names, payload nesting, and timestamp formatting remain unverified against captured logs. Names and illustrative identifiers do not prove intent or downstream activity.
{ "id": "Directory_90000000-0000-4000-8000-000001101101_3A8C1_72584931", "category": "DirectoryManagement", "correlationId": "90000000-0000-4000-8000-000001101101", "result": "success", "resultReason": "", "activityDisplayName": "Add verified domain", "activityDateTime": "2026-04-15T11:32:18.5072194Z", "loggedByService": "Core Directory", "operationType": "Update", "initiatedBy": { "app": null, "user": { "id": "30000000-0000-4000-8000-000000000001", "displayName": "Hermione Granger", "userPrincipalName": "hermione@fantasticlogs.cloud", "ipAddress": "198.51.100.42" } }, "targetResources": [ { "id": "partners.fantasticlogs.cloud", "displayName": "partners.fantasticlogs.cloud", "userPrincipalName": null, "groupType": null, "modifiedProperties": [ { "displayName": "DomainName", "oldValue": "[]", "newValue": "[\"partners.fantasticlogs.cloud\"]" }, { "displayName": "IsVerified", "oldValue": "[false]", "newValue": "[true]" }, { "displayName": "AuthenticationType", "oldValue": "[]", "newValue": "[\"Managed\"]" }, { "displayName": "IsDefault", "oldValue": "[]", "newValue": "[false]" }, { "displayName": "Included Updated Properties", "oldValue": null, "newValue": "\"DomainName, IsVerified, AuthenticationType, IsDefault\"" } ] } ], "additionalDetails": [ { "key": "User-Agent", "value": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/121.0.0.0 Safari/537.36" } ]}