Skip to content

Commit d034440

Browse files
author
Markus Vilcinskas
committed
workbook01
1 parent c3d6fe4 commit d034440

File tree

1 file changed

+5
-2
lines changed

1 file changed

+5
-2
lines changed

articles/active-directory/reports-monitoring/workbook-sensitive-operations-report.md

Lines changed: 5 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -90,7 +90,10 @@ This section includes an overview of all changes made to service principal membe
9090

9191
### Modified federation settings
9292

93-
Another common approach to gain a long-term foothold in the environment is to modify the tenant’s federated domain trusts, and to add an additional, attacker controlled, SAML IDP as a trusted authentication source.
93+
Another common approach to gain a long-term foothold in the environment is to:
94+
95+
- Modify the tenant’s federated domain trusts.
96+
- Add an additional SAML IDP that is controlled by the attacker as a trusted authentication source.
9497

9598
This section includes the following data:
9699

@@ -142,7 +145,7 @@ This paragraph lists the supported filters for each section.
142145

143146
**Use:**
144147

145-
- **Modified application and service principal credentials** to look out for credentials being added to service principals which are not frequently used in your organization. Use the filters present in this section to further investigate any of the suspicious actors or service principals that were modified.
148+
- **Modified application and service principal credentials** to look out for credentials being added to service principals that are not frequently used in your organization. Use the filters present in this section to further investigate any of the suspicious actors or service principals that were modified.
146149

147150

148151
- **New permissions granted to service principals** to look out for broad or excessive permissions being added to service principals by actors that may be compromised.

0 commit comments

Comments
 (0)