Elastic medium stable kql
Entra ID User Sign-in with Unusual Authentication Type
Identifies rare instances of authentication methods for Microsoft Entra ID principal users. An adversary with stolen credentials may attempt to authenticate with an unusual method, which may indicate an attempt to bypass conditional access policies (CAP) and multi-factor authentication (MFA) requirements. The authentication method may not be commonly used by the user based on their historical sign-in activity.
Detection Logic
data_stream.dataset: "azure.signinlogs" and event.category: "authentication"
and azure.signinlogs.properties.user_type: "Member"
and not azure.signinlogs.properties.device_detail.browser: *
and not source.as.organization.name: "MICROSOFT-CORP-MSN-AS-BLOCK"
and not azure.signinlogs.properties.authentication_requirement: "multiFactorAuthentication"
and azure.signinlogs.properties.authentication_details.authentication_method:*
and event.outcome:success Field Validations
Loading…
Comments (0)
Loading comments...