Suspicious activity

Role assignment administration activities committed from a malicious IP

Risk Level

Imminent Compromised (2)



Orca detected that an API calls to manage a role assignment were made by the principal - {AzurePrincipal} from a malicious IP, the operation was successful. This action may indicate of a presence of an unauthorized actor in the cloud environment, since the API calls were made a malicious IP.
  • Recommended Mitigation

    It is recommended to review the role assignment which was affected.