LoFP LoFP / investigate where if active time period for a role is set too short.

Techniques

Sample rules

Roles Activated Too Frequently

Description

Identifies when the same privilege role has multiple activations by the same user.

Detection logic

condition: selection
selection:
  riskEventType: sequentialActivationRenewalsAlertIncident