Update User Authentication Methods
Update User Authentication Methods
Event
The illustrated activity is Admin registered security info for a phone method. Administrative method management requires appropriate authentication-administrator authority for the target; User Administrator should not be assumed sufficient for a privileged account. Registered methods, allowed methods, default selection, and authentication-strength requirements are separate.
Security Context
Unauthorized registration can support MFA modification and account manipulation (T1556.006/T1098). It does not guarantee future prompts go to that number, replace stronger methods, or satisfy phishing-resistant authentication requirements. Approved recovery is a common alternative.
Log Source
Microsoft Entra directory audit logs, illustrated with activityDisplayName: Admin registered security info. Match result, actor, and target IDs. Graph-style exports and Azure Monitor wrappers differ; exact modified-property and additionalDetails serialization still needs captured-log validation.
Key Fields
| Field | Investigation value |
|---|---|
activityDisplayName, result | Recorded activity and outcome. |
initiatedBy, correlationId | Actor and related changes; verify actual administrative authority. |
targetResources | Target ID/type and illustrative old/new properties. |
additionalDetails | Optional method/client context; do not assume all exports expose full values. |
What to Investigate
- Confirm the recorded outcome and compare actor, target, and timing with the approved workflow.
- Verify actor permissions, target privilege/scope, and the approved recovery or enrollment workflow.
- Review prior/new method inventory, allowed-method policy, defaults, and authentication-strength requirements.
- Correlate actual authentication method use and sign-ins; inspect deletion or replacement of existing methods separately.
Sample Event
Synthetic scenario. The example registers an illustrative phone method for Hermione. The additionalDetails names and disclosure of a full phone number are unverified audit serialization; no actual prompt or successful authentication is shown.
Exact field presence, payload nesting, identity/session details, and timestamp formatting remain unverified against captured logs. Names and illustrative identifiers do not prove intent or downstream activity.
{ "id": "Directory_90000000-0000-4000-8000-000100100010_C2B41_38912407", "category": "UserManagement", "correlationId": "90000000-0000-4000-8000-000100100010", "result": "success", "resultReason": "", "activityDisplayName": "Admin registered security info", "activityDateTime": "2026-04-15T18:25:42.1148088Z", "loggedByService": "Authentication Methods", "operationType": "Update", "initiatedBy": { "app": null, "user": { "id": "30000000-0000-4000-8000-001010011010", "displayName": "Draco Malfoy", "userPrincipalName": "draco@fantasticlogs.cloud", "ipAddress": "203.0.113.66" } }, "targetResources": [ { "id": "30000000-0000-4000-8000-000000000001", "displayName": "Hermione Granger", "type": "User", "userPrincipalName": "hermione@fantasticlogs.cloud", "groupType": null, "modifiedProperties": [] } ], "additionalDetails": [ { "key": "User-Agent", "value": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/121.0.0.0 Safari/537.36" }, { "key": "AuthenticationMethod", "value": "Phone" }, { "key": "PhoneNumber", "value": "+12025550137" }, { "key": "PhoneType", "value": "Mobile" } ]}Sources
MITRE ATT&CK Mapping
Tactics: Persistence Defense Impairment
- T1556.006 — Multi-Factor Authentication — Adversaries may disable or modify multi-factor authentication (MFA) mechanisms to enable persistent access to compromised accounts.
- T1098 — Account Manipulation — Adversaries may manipulate accounts to maintain and/or elevate access to victim systems. Account manipulation may consist of any action that preserves or modifies adversary access to a compromised account, such as modifying credentials or permission groups. These actions could also include accoun...