Skip to content

Admin Registered Security Info

Azure

Admin Registered Security Info

service: Azure - Microsoft Entra ID
tactics:
techniques:

Event

Records administrative registration of security information for a user. Determine the actual authentication method and whether it is enabled for MFA, passwordless sign-in, or self-service password reset under the applicable policies. Registration alone does not prove the method was used.

Security Context

Unauthorized method registration can manipulate authentication (contextual T1556.006/T1098). Legitimate account recovery uses this workflow. A phone method does not automatically allow password reset: SSPR eligibility, accepted methods, required method count, and administrative-account restrictions matter.

Log Source

Microsoft Entra directory audit logs. The sample uses activityDisplayName: Admin registered security info. Match target IDs and result, not a display name alone; Microsoft Graph-style JSON and Azure Monitor exports use different wrappers/casing.

Key Fields

FieldInvestigation value
initiatedBy, targetResourcesAdministrator and affected user; names do not establish roles.
additionalDetailsMethod information when present; Phone alone reveals neither the number nor its owner.

What to Investigate

  1. Confirm the recorded outcome and compare actor, target, and timing with the approved workflow.
  2. Verify operator authority and the approved recovery/registration request.
  3. Inspect the actual method and applicable authentication/SSPR policies without exposing secret material.
  4. Correlate later authentication and password-reset events; do not assume the operator controls the phone.

Sample Event

Synthetic scenario. The sample identifies Phone as the method for Neville. It does not contain the number, prove attacker ownership, or show a password reset.

Exact field presence, modified-property names, payload nesting, and timestamp formatting remain unverified against captured logs. Names and illustrative identifiers do not prove intent or downstream activity.

{
"id": "Directory_90000000-0000-4000-8000-000001101110_8B2A4_55397128",
"category": "UserManagement",
"correlationId": "90000000-0000-4000-8000-000001101110",
"result": "success",
"resultReason": "",
"activityDisplayName": "Admin registered security info",
"activityDateTime": "2026-04-15T19:14:02.7184310Z",
"loggedByService": "Authentication Methods",
"operationType": "Update",
"initiatedBy": {
"app": null,
"user": {
"id": "30000000-0000-4000-8000-001010011010",
"displayName": "Draco Malfoy",
"userPrincipalName": "draco@fantasticlogs.cloud",
"ipAddress": "203.0.113.66"
}
},
"targetResources": [
{
"id": "30000000-0000-4000-8000-000000000100",
"displayName": "Neville Longbottom",
"type": "User",
"userPrincipalName": "neville@fantasticlogs.cloud",
"groupType": null,
"modifiedProperties": []
}
],
"additionalDetails": [
{
"key": "AuthenticationMethod",
"value": "Phone"
},
{
"key": "UserAgent",
"value": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/121.0.0.0 Safari/537.36"
}
]
}

Sources

MITRE ATT&CK Mapping

Tactics: Persistence

Techniques:
  • T1556.006 — Multi-Factor Authentication — Adversaries may disable or modify multi-factor authentication (MFA) mechanisms to enable persistent access to compromised accounts.
  • T1098 — Account Manipulation — Adversaries may manipulate accounts to maintain and/or elevate access to victim systems. Account manipulation may consist of any action that preserves or modifies adversary access to a compromised account, such as modifying credentials or permission groups. These actions could also include accoun...
Documentation reviewed: October 4, 2026. Samples are synthetic illustrations, not captured production logs or lab-validated fixtures.