Skip to content

Microsoft.Directory/groups/members/update

Azure

Microsoft.Directory/groups/members/update

service: Azure - Microsoft Entra ID
techniques:

Event

The title is an Entra directory permission name, not an audit activity name. microsoft.directory/groups/members/update excludes role-assignable groups; those require separate groupsAssignableToRoles authority. The sample illustrates Add member to group. Dynamic membership is governed by rules rather than manual additions.

Security Context

Unauthorized membership changes can confer additional cloud roles (contextual T1098.003), depending on the group’s actual assignments. A group name does not prove privileged access, and ownership is not equivalent to membership.

Log Source

Microsoft Entra directory audit logs, illustrated with activityDisplayName: Add member to group. The catalog title is a permission label. Match target IDs and result; Graph-style JSON and Azure Monitor exports use different wrappers and casing.

Key Fields

FieldInvestigation value
activityDisplayName, resultRecorded activity and outcome.
initiatedBy, correlationIdInitiating identity and related changes.
targetResourcesTarget object type and ID; distinguish applications from service principals.
targetResources[].modifiedPropertiesIllustrative prior/new values; exact serialization needs captured-log validation.

What to Investigate

  1. Confirm the recorded outcome and compare actor, target, and timing with the approved workflow.
  2. Confirm group type, membership mode, and the exact added or removed object IDs.
  3. Review actual resource-role assignments and active versus eligible access; do not infer an Entra administrator role from the group name.
  4. Verify initiating authority and correlate subsequent access rather than inventing a prior ownership change.

Sample Event

Synthetic scenario. The sample adds Draco to GraphornAdmins. It does not establish that the group is role-assignable or grants Privileged Role Administrator.

Exact field presence, modified-property names, payload nesting, and timestamp formatting remain unverified against captured logs. Names and illustrative identifiers do not prove intent or downstream activity.

{
"id": "Directory_90000000-0000-4000-8000-000011001000_4F2E7_82119354",
"category": "GroupManagement",
"correlationId": "90000000-0000-4000-8000-000011001000",
"result": "success",
"resultReason": "",
"activityDisplayName": "Add member to group",
"activityDateTime": "2026-04-15T19:08:42.0381729Z",
"loggedByService": "Core Directory",
"operationType": "Add",
"initiatedBy": {
"app": null,
"user": {
"id": "30000000-0000-4000-8000-001010011010",
"displayName": "Draco Malfoy",
"userPrincipalName": "draco@fantasticlogs.cloud",
"ipAddress": "203.0.113.66"
}
},
"targetResources": [
{
"id": "30000000-0000-4000-8000-001010011010",
"displayName": "Draco Malfoy",
"type": "User",
"userPrincipalName": "draco@fantasticlogs.cloud",
"modifiedProperties": [
{
"displayName": "Group.DisplayName",
"oldValue": "[]",
"newValue": "[\"GraphornAdmins\"]"
},
{
"displayName": "Group.ObjectId",
"oldValue": "[]",
"newValue": "[\"60000000-0000-4000-8000-000000000001\"]"
},
{
"displayName": "Included Updated Properties",
"oldValue": null,
"newValue": "\"Group.DisplayName, Group.ObjectId\""
}
]
},
{
"id": "60000000-0000-4000-8000-000000000001",
"displayName": "GraphornAdmins",
"type": "Group",
"userPrincipalName": null,
"modifiedProperties": []
}
],
"additionalDetails": [
{
"key": "User-Agent",
"value": "python/3.11.6 (Linux-5.15.0-1052-aws-x86_64-with-glibc2.35) AZURECLI/2.56.0 (DEB)"
}
]
}

Sources

MITRE ATT&CK Mapping

Tactics: Privilege Escalation Persistence

Techniques:
  • T1098.003 — Additional Cloud Roles — An adversary may add additional roles or permissions to an adversary-controlled cloud account to maintain persistent access to a tenant. For example, adversaries may update IAM policies in cloud-based environments or add a new global administrator in Office 365 environments. With sufficient permi...
Documentation reviewed: October 5, 2026. Samples are synthetic illustrations, not captured production logs or lab-validated fixtures.