LoFP LoFP / federation settings modified from unfamiliar users should be investigated. if known behavior is causing false positives, it can be exempted from the rule.

Techniques

Sample rules

Azure Domain Federation Settings Modified

Description

Identifies when an user or application modified the federation settings on the domain.

Detection logic

condition: selection
selection:
  ActivityDisplayName: Set federation settings on domain