Windows Entra User Management Via Azure CLI — Detection Rule
This analytic detects the usage of the Azure CLI to interact with user accounts such as creating or deleting a user. Adversaries create new users so that their malicious activity does not interrupt the normal functions of the compromised users and can remain undetected. While legitimate administrative use is expected, anomalous execution patterns, unexpected users, or unusual parent processes should be treated as potential indicators of compromise and investigated promptly.