Skip to content

Update User Authentication Methods

Azure

Update User Authentication Methods

service: Azure - Microsoft Entra ID
techniques:

Event

The illustrated activity is Admin registered security info for a phone method. Administrative method management requires appropriate authentication-administrator authority for the target; User Administrator should not be assumed sufficient for a privileged account. Registered methods, allowed methods, default selection, and authentication-strength requirements are separate.

Security Context

Unauthorized registration can support MFA modification and account manipulation (T1556.006/T1098). It does not guarantee future prompts go to that number, replace stronger methods, or satisfy phishing-resistant authentication requirements. Approved recovery is a common alternative.

Log Source

Microsoft Entra directory audit logs, illustrated with activityDisplayName: Admin registered security info. Match result, actor, and target IDs. Graph-style exports and Azure Monitor wrappers differ; exact modified-property and additionalDetails serialization still needs captured-log validation.

Key Fields

FieldInvestigation value
activityDisplayName, resultRecorded activity and outcome.
initiatedBy, correlationIdActor and related changes; verify actual administrative authority.
targetResourcesTarget ID/type and illustrative old/new properties.
additionalDetailsOptional method/client context; do not assume all exports expose full values.

What to Investigate

  1. Confirm the recorded outcome and compare actor, target, and timing with the approved workflow.
  2. Verify actor permissions, target privilege/scope, and the approved recovery or enrollment workflow.
  3. Review prior/new method inventory, allowed-method policy, defaults, and authentication-strength requirements.
  4. Correlate actual authentication method use and sign-ins; inspect deletion or replacement of existing methods separately.

Sample Event

Synthetic scenario. The example registers an illustrative phone method for Hermione. The additionalDetails names and disclosure of a full phone number are unverified audit serialization; no actual prompt or successful authentication is shown.

Exact field presence, payload nesting, identity/session details, and timestamp formatting remain unverified against captured logs. Names and illustrative identifiers do not prove intent or downstream activity.

{
"id": "Directory_90000000-0000-4000-8000-000100100010_C2B41_38912407",
"category": "UserManagement",
"correlationId": "90000000-0000-4000-8000-000100100010",
"result": "success",
"resultReason": "",
"activityDisplayName": "Admin registered security info",
"activityDateTime": "2026-04-15T18:25:42.1148088Z",
"loggedByService": "Authentication Methods",
"operationType": "Update",
"initiatedBy": {
"app": null,
"user": {
"id": "30000000-0000-4000-8000-001010011010",
"displayName": "Draco Malfoy",
"userPrincipalName": "draco@fantasticlogs.cloud",
"ipAddress": "203.0.113.66"
}
},
"targetResources": [
{
"id": "30000000-0000-4000-8000-000000000001",
"displayName": "Hermione Granger",
"type": "User",
"userPrincipalName": "hermione@fantasticlogs.cloud",
"groupType": null,
"modifiedProperties": []
}
],
"additionalDetails": [
{
"key": "User-Agent",
"value": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/121.0.0.0 Safari/537.36"
},
{
"key": "AuthenticationMethod",
"value": "Phone"
},
{
"key": "PhoneNumber",
"value": "+12025550137"
},
{
"key": "PhoneType",
"value": "Mobile"
}
]
}

Sources

MITRE ATT&CK Mapping

Tactics: Persistence Defense Impairment

Techniques:
  • T1556.006 — Multi-Factor Authentication — Adversaries may disable or modify multi-factor authentication (MFA) mechanisms to enable persistent access to compromised accounts.
  • T1098 — Account Manipulation — Adversaries may manipulate accounts to maintain and/or elevate access to victim systems. Account manipulation may consist of any action that preserves or modifies adversary access to a compromised account, such as modifying credentials or permission groups. These actions could also include accoun...
Documentation reviewed: October 5, 2026. Samples are synthetic illustrations, not captured production logs or lab-validated fixtures.