Detection of Remote Device Management Services

ID: DET0702
Domains: Mobile
Analytics: AN1820, AN1821
Version: 1.0
Created: 21 October 2025
Last Modified: 21 October 2025

Analytics

AN1820

Defender observes anomalous access to remote device management or enterprise mobility management control planes followed by device-state queries, location requests, or management actions inconsistent with user role, historical behavior, or device ownership context.

Log Sources
Data Component Name Channel
User Account Authentication (DC0002) saas:MDM Authentication events to device management or enterprise mobility management consoles
Cloud Service Enumeration (DC0083) saas:MDM Device lookup, location query, or remote management operation
Mutable Elements
Field Description
RoleDeviationThreshold Defines acceptable variance between user privileges and management actions
GeoAccessAnomalyThreshold Baseline deviation tolerance for management console access locations
DeviceOwnershipBaseline Expected mapping of users to managed devices

AN1821

Defender observes anomalous authentication or session activity targeting remote device management services followed by device-tracking queries, device-state requests, or remote actions inconsistent with established user-device relationships or operational patterns.

Log Sources
Data Component Name Channel
User Account Authentication (DC0002) saas:MDM Authentication events to Apple iCloud or enterprise device management services
Cloud Service Enumeration (DC0083) saas:MDM Device lookup, location query, or remote management operation
Mutable Elements
Field Description
UserDeviceRelationshipDeviation Defines acceptable deviation from known user-device mappings
SessionAnomalyThreshold Baseline deviation tolerance for management sessions
QueryFrequencyThreshold Threshold for excessive device tracking or lookup activity