{
  "technique_id": "T1484",
  "name": "Domain or Tenant Policy Modification",
  "tactics": [
    "Defense Impairment",
    "Privilege Escalation"
  ],
  "platforms": [
    "Windows",
    "Identity Provider"
  ],
  "summary": "Adversaries may modify the configuration settings of a domain or identity tenant to evade defenses and/or escalate privileges in centrally managed environments. Such services provide a centralized means of managing identity resources such as devices and accounts, and often include configuration settings that may apply between domains or tenants such as trust relationships, identity syncing, or identity federation...",
  "generated_by": "SOC Response Atlas by Basyrix"
}