Techniques
Sample rules
Disabled MFA to Bypass Authentication Mechanisms
- source: sigma
- technicques:
- t1556
Description
Detection for when multi factor authentication has been disabled, which might indicate a malicious activity to bypass authentication mechanisms.
Detection logic
condition: selection
selection:
eventName: Disable Strong Authentication.
eventSource: AzureActiveDirectory
status: success