Admin Registered Security Info
Admin Registered Security Info
Event
Records administrative registration of security information for a user. Determine the actual authentication method and whether it is enabled for MFA, passwordless sign-in, or self-service password reset under the applicable policies. Registration alone does not prove the method was used.
Security Context
Unauthorized method registration can manipulate authentication (contextual T1556.006/T1098). Legitimate account recovery uses this workflow. A phone method does not automatically allow password reset: SSPR eligibility, accepted methods, required method count, and administrative-account restrictions matter.
Log Source
Microsoft Entra directory audit logs. The sample uses activityDisplayName: Admin registered security info. Match target IDs and result, not a display name alone; Microsoft Graph-style JSON and Azure Monitor exports use different wrappers/casing.
Key Fields
| Field | Investigation value |
|---|---|
initiatedBy, targetResources | Administrator and affected user; names do not establish roles. |
additionalDetails | Method information when present; Phone alone reveals neither the number nor its owner. |
What to Investigate
- Confirm the recorded outcome and compare actor, target, and timing with the approved workflow.
- Verify operator authority and the approved recovery/registration request.
- Inspect the actual method and applicable authentication/SSPR policies without exposing secret material.
- Correlate later authentication and password-reset events; do not assume the operator controls the phone.
Sample Event
Synthetic scenario. The sample identifies Phone as the method for Neville. It does not contain the number, prove attacker ownership, or show a password reset.
Exact field presence, modified-property names, payload nesting, and timestamp formatting remain unverified against captured logs. Names and illustrative identifiers do not prove intent or downstream activity.
{ "id": "Directory_90000000-0000-4000-8000-000001101110_8B2A4_55397128", "category": "UserManagement", "correlationId": "90000000-0000-4000-8000-000001101110", "result": "success", "resultReason": "", "activityDisplayName": "Admin registered security info", "activityDateTime": "2026-04-15T19:14:02.7184310Z", "loggedByService": "Authentication Methods", "operationType": "Update", "initiatedBy": { "app": null, "user": { "id": "30000000-0000-4000-8000-001010011010", "displayName": "Draco Malfoy", "userPrincipalName": "draco@fantasticlogs.cloud", "ipAddress": "203.0.113.66" } }, "targetResources": [ { "id": "30000000-0000-4000-8000-000000000100", "displayName": "Neville Longbottom", "type": "User", "userPrincipalName": "neville@fantasticlogs.cloud", "groupType": null, "modifiedProperties": [] } ], "additionalDetails": [ { "key": "AuthenticationMethod", "value": "Phone" }, { "key": "UserAgent", "value": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/121.0.0.0 Safari/537.36" } ]}Sources
MITRE ATT&CK Mapping
Tactics: Persistence
- T1556.006 — Multi-Factor Authentication — Adversaries may disable or modify multi-factor authentication (MFA) mechanisms to enable persistent access to compromised accounts.
- T1098 — Account Manipulation — Adversaries may manipulate accounts to maintain and/or elevate access to victim systems. Account manipulation may consist of any action that preserves or modifies adversary access to a compromised account, such as modifying credentials or permission groups. These actions could also include accoun...