Skip to content
Skip to main content
Cloud Services Technical Explainer

Could an attacker create new users or administrators?

Yes - if the authority they control permits identity or role changes. A newly created user or role assignment can provide a separate access route, so resetting the original account's password may not affect it.

An admin session creates a second identity

A session associated with Dave's Microsoft Entra administrator account creates svc-review@northstar.example at 14:06. At 14:09, the same session adds that user to a privileged role. At 14:18, the new identity signs in for the first time.

Follow creator, capability and first use
EstablishedOne recorded account context created, privileged and enabled use of a new identity.
Still openWhether Dave controlled that session and whether provisioning was authorised.

Creation, privilege and use are separate events

Preserve the initiating account and session, target object ID, user type, invitation or creation event, role name and scope, authentication-method changes, first sign-in and later resource actions. A plausible display name is weak; stable identifiers and event joins are stronger.

Compare the sequence with directory automation, HR or contractor records, approvals, change tickets and the supposed owner's activity. Legitimate provisioning can look identical at feature level. The evidential question is whether the specific identity, authority and use matched an authorised purpose.

Current Microsoft Entra example - checked 2 September 2026

Microsoft's current audit activity reference includes Add user and Add member to role. Its security-operations guidance recommends correlating those events when monitoring privileged account creation and also monitoring authentication-method changes that could provide continued access.

Exact event fields and role models are provider-specific. Preserve the target object ID, modified properties, initiator, role definition and relevant scope from the contemporary export.

The point to remember

A new identity can become an independent access route. Join its creation, authority and first use to the initiating session, then test that sequence against authorised provisioning records.

Reference: CLD-047Cloud Services