How do you handle identity detections when the customer considers every admin action legitimate?

Wait 5 sec.

I'm interested in how other SOC / Detection Engineering teams deal with this situation. We have identity-based detections for administrative actions, for example AD group membership changes (grant/revoke). The customer does not use PIM/JIT and their administrators have standing privileges. Naturally, legitimate administrative work therefore generates detections. The customer doesn't want the SOC contacting them every time this happens. Their position is essentially: if an authorized administrator performed the action, we can assume it was legitimate. From an operational perspective I understand the problem. Constantly asking whether routine administrative activity was authorized creates alert fatigue for both the SOC and the customer. The dilemma is that an administrator account can also be compromised. In that case, the activity is still technically being performed through an authorized admin account, so simply treating "performed by an admin" as proof of legitimacy potentially removes visibility into exactly the scenario we're concerned about. At the same time, alerting on every administrative action clearly isn't sustainable. For those working in SOC / Detection Engineering: how do you approach this problem, particularly in environments with standing administrative privileges? Where do you draw the line between reducing noise from legitimate administration and maintaining useful detection coverage for potentially compromised privileged accounts?   submitted by   /u/m1L35dY50N [link]   [comments]