LoFP LoFP / t1606

t1606

TitleTags
initial sso configuration issues or first-time federation setup errors for legitimate users may trigger this detection. temporary federation service outages affecting multiple users simultaneously.
legacy federation broker applications that call getfederationtoken and immediately redirect users to a console session from the same host may trigger this rule. validate the source ip against known application server infrastructure and confirm the federation architecture is documented.
we recommend investigating the sessions flagged by this detection in the context of other sign-ins from the user.