LoFP LoFP / authorized modification by administrators

Techniques

Sample rules

Disabled MFA to Bypass Authentication Mechanisms

Description

Detection for when multi factor authentication has been disabled, which might indicate a malicious activity to bypass authentication mechanisms.

Detection logic

condition: selection
selection:
  eventName: Disable Strong Authentication.
  eventSource: AzureActiveDirectory
  status: success