Public reference
This page documents all current ITDR built-in detections from the live rule engine so your incident response team can review trigger logic, thresholds, grouping, and evidence expectations.
View mode
Technical mode exposes full trigger logic, conditions, evidence fields, and grouping keys.
Detection coverage model
Rule behavior is validated against live Microsoft telemetry, then alerts are grouped into incidents through the same investigation workflow used in the platform.
Office 365 Management telemetry supports both native mailbox-rule detections and mapped SecurityCompliance/threat signals.
Office 365 Management coverage model
This catalog includes built-in Exchange mailbox-rule detections. In addition, the platform ingests Office 365 Management content types (`Audit.AzureActiveDirectory`, `Audit.Exchange`, `Audit.SharePoint`, `Audit.General`, `DLP.All`) and maps SecurityCompliance/threat-related records into alerts with source `o365_management`.
Subscription-level failures are warning-classified. If one content type is unavailable (for example `DLP.All`), other enabled content types can still ingest.
Licensing realism
This matrix reflects current platform behavior and production observations as of April 22, 2026. Microsoft licensing and tenant entitlements can change; this page is an operational guide, not a legal licensing contract.
Microsoft references: Business Premium security overview | Entra risk detection licensing | Entra log retention by tier
Operational expectations
Prevent initial login
Identity platform controls
Conditional Access, phishing-resistant auth, device compliance, and browser/DNS controls stop many attacks before account session establishment.
Detect compromise patterns
ITDR detections (this catalog)
The rules on this page detect suspicious identity and workload behavior from Graph telemetry and correlated context; provider-originated Office 365 alerts are mapped separately.
Contain and respond
Platform response workflow
Capability-aware actions, verification, and immutable action history reduce dwell time after a suspicious event is observed.
Licensing matrix
| Detection | Business Premium (includes P1) | Entra ID P1 / M365 E3 baseline | Entra ID P2 / M365 E5 baseline | Practical notes |
|---|---|---|---|---|
High-risk app permission or governance change high_risk_app_change | Supported | Supported | Supported | Uses directory audit + workload identity correlation. Main blockers are permissions and connector health, not P2. |
Possible rogue high-privilege new workload identity rogue_application_high_privilege_new_sp | Supported | Supported | Supported | Uses directory audit + workload identity correlation. Main blockers are permissions and connector health, not P2. |
Ownerless privileged workload identity change rogue_application_ownerless_privileged | Supported | Supported | Supported | Uses directory audit + workload identity correlation. Main blockers are permissions and connector health, not P2. |
Possible rogue application consent burst rogue_application_consent_burst | Supported | Supported | Supported | Uses directory audit + workload identity correlation. Main blockers are permissions and connector health, not P2. |
Repeated failed sign-ins for identity repeated_failed_signins | Supported | Supported | Supported | Requires sign-in log ingestion from Graph. Not tied to P2-specific risk APIs. |
Workload app retrying with expired client secret expired_credential_secret | Supported | Supported | Supported | Requires sign-in log ingestion from Graph. Not tied to P2-specific risk APIs. |
Adversary-in-the-middle token replay from distinct device aitm_token_replay_distinct_device | Supported | Supported | Supported | Requires sign-in log ingestion from Graph. Not tied to P2-specific risk APIs. |
Risky successful sign-in risky_signin_success | Partial | Partial | Supported | Depends on Microsoft sign-in risk fields. On non-P2 tenants this rule can be sparse or generic. |
Successful sign-in after repeated failures success_after_failed_signins | Supported | Supported | Supported | Requires sign-in log ingestion from Graph. Not tied to P2-specific risk APIs. |
Rapid location change across successful sign-ins rapid_location_change | Supported | Supported | Supported | Requires sign-in log ingestion from Graph. Not tied to P2-specific risk APIs. |
Possible non-interactive token replay non_interactive_token_replay | Supported | Supported | Supported | Requires sign-in log ingestion from Graph. Not tied to P2-specific risk APIs. |
Suspicious non-interactive sign-in non_interactive_signin_anomaly | Supported | Supported | Supported | Requires sign-in log ingestion from Graph. Not tied to P2-specific risk APIs. |
Credential theft pattern across identities credential_theft_detection | Supported | Supported | Supported | Requires sign-in log ingestion from Graph. Not tied to P2-specific risk APIs. |
Malicious datacenter utilization pattern malicious_datacenter_utilization | Supported | Supported | Supported | Requires sign-in log ingestion from Graph. Not tied to P2-specific risk APIs. |
Malicious Inbox Rule Detection malicious_inbox_rule_detection | Supported | Supported | Supported | Requires Office 365 Management Activity ingestion and Exchange operation visibility. |
Suspicious Email Filter Hiding Generic Account and Security Notifications suspicious_email_filter_hiding_generic_security_notifications | Supported | Supported | Supported | Requires Office 365 Management Activity ingestion and Exchange operation visibility. |
Suspicious Email Filter Hiding Finance and BEC Keywords suspicious_email_filter_hiding_finance_bec_keywords | Supported | Supported | Supported | Requires Office 365 Management Activity ingestion and Exchange operation visibility. |
Suspicious Email Filter Hiding External Account Security Notifications suspicious_email_filter_hiding_external_security_notifications | Supported | Supported | Supported | Requires Office 365 Management Activity ingestion and Exchange operation visibility. |
Attack chain: risky login to MFA change to inbox rule itdr_chain_risky_login_mfa_change_inbox_rule | Supported | Supported | Supported | Requires base detections and correlation windows; this is sequence analytics over existing signals. |
Attack chain: password spray to success to lateral movement itdr_chain_spray_success_lateral | Supported | Supported | Supported | Requires base detections and correlation windows; this is sequence analytics over existing signals. |
Attack chain: token replay across multiple identities itdr_chain_token_replay_multi_identity | Supported | Supported | Supported | Requires base detections and correlation windows; this is sequence analytics over existing signals. |
MFA denied challenge followed by successful sign-in mfa_denied_then_success | Supported | Supported | Supported | Requires sign-in log ingestion from Graph. Not tied to P2-specific risk APIs. |
Authentication method change after risky sign-in auth_method_change_after_risky_signin | Supported | Supported | Supported | Requires base detections and correlation windows; this is sequence analytics over existing signals. |
Password reset after risky sign-in password_reset_after_risky_signin | Supported | Supported | Supported | Requires base detections and correlation windows; this is sequence analytics over existing signals. |
OAuth consent activity after risky sign-in oauth_consent_from_risky_session | Supported | Supported | Supported | Requires base detections and correlation windows; this is sequence analytics over existing signals. |
MFA method weakened after risky sign-in mfa_method_weakened | Supported | Supported | Supported | Requires base detections and correlation windows; this is sequence analytics over existing signals. |
Privileged role assignment by risky actor privileged_role_assignment_risky_actor | Supported | Supported | Supported | Requires base detections and correlation windows; this is sequence analytics over existing signals. |
Likely dormant workload identity suddenly active unused_workload_identity_suddenly_active | Supported | Supported | Supported | Uses directory audit + workload identity correlation. Main blockers are permissions and connector health, not P2. |
Feed-level expectations
| Microsoft feed | Used for | Business Premium (includes P1) | Entra ID P1 / M365 E3 baseline | Entra ID P2 / M365 E5 baseline | Notes |
|---|---|---|---|---|---|
auditLogs/signIns (v1.0) | Core signal feed for sign-in detections and chain correlation. | Supported | Supported | Supported | Requires Graph permissions and role assignment. Without this feed, sign-in detections cannot trigger regardless of license. |
Office 365 Management Activity API | Exchange mailbox-rule detections (rules 13-16) plus provider-originated SecurityCompliance/threat alert mapping. | Supported | Supported | Supported | Requires Office 365 Management API app permissions (`ActivityFeed.Read`; `ActivityFeed.ReadDlp` for DLP). Missing one subscription does not block all others. |
identityProtection/riskDetections | Optional enrichment and connector warning context. | Partial | Partial | Supported | Non-P2 tenants can return generic/limited risk context. This feed is enrichment; core detections still run without it. |
identityProtection/riskyUsers | Optional user risk enrichment and investigation context. | Partial | Partial | Supported | Coverage varies by tenant entitlement and permissions. P2 generally gives full risk detail; lower tiers can be partial. |
identityProtection/riskyServicePrincipals | Optional workload identity risk enrichment. | Not expected | Not expected | Partial | Commonly blocked without premium workload-identity risk entitlements. Treat as optional enrichment, not a core dependency. |
| # | Rule | Rule Type | Category | Family | Severity |
|---|---|---|---|---|---|
| 1 | High-risk app permission or governance change | high_risk_app_change | consent_or_config_change | directory_audit | high |
| 2 | Possible rogue high-privilege new workload identity | rogue_application_high_privilege_new_sp | rogue_application_high_privilege_new_sp | directory_audit | critical |
| 3 | Ownerless privileged workload identity change | rogue_application_ownerless_privileged | rogue_application_ownerless_privileged | directory_audit | critical |
| 4 | Possible rogue application consent burst | rogue_application_consent_burst | rogue_application_consent_burst | directory_audit | high |
| 5 | Repeated failed sign-ins for identity | repeated_failed_signins | failed_signin_pattern | sign_in | medium |
| 27 | Workload app retrying with expired client secret | expired_credential_secret | expired_credential_secret | sign_in | medium |
| 28 | Adversary-in-the-middle token replay from distinct device | aitm_token_replay_distinct_device | aitm_token_replay_distinct_device | sign_in | high |
| 6 | Risky successful sign-in | risky_signin_success | risky_signin_success | sign_in | high |
| 7 | Successful sign-in after repeated failures | success_after_failed_signins | successful_signin_after_failures | sign_in | high |
| 8 | Rapid location change across successful sign-ins | rapid_location_change | sign_in_anomaly | sign_in | high |
| 9 | Possible non-interactive token replay | non_interactive_token_replay | non_interactive_token_replay | sign_in | high |
| 10 | Suspicious non-interactive sign-in | non_interactive_signin_anomaly | non_interactive_signin_anomaly | sign_in | high |
| 11 | Credential theft pattern across identities | credential_theft_detection | credential_theft_detection | sign_in | high |
| 12 | Malicious datacenter utilization pattern | malicious_datacenter_utilization | malicious_datacenter_utilization | sign_in | high |
| 13 | Malicious Inbox Rule Detection | malicious_inbox_rule_detection | malicious_inbox_rule_detection | o365_management | high |
| 14 | Suspicious Email Filter Hiding Generic Account and Security Notifications | suspicious_email_filter_hiding_generic_security_notifications | suspicious_email_filter_hiding_generic_security_notifications | o365_management | high |
| 15 | Suspicious Email Filter Hiding Finance and BEC Keywords | suspicious_email_filter_hiding_finance_bec_keywords | suspicious_email_filter_hiding_finance_bec_keywords | o365_management | critical |
| 16 | Suspicious Email Filter Hiding External Account Security Notifications | suspicious_email_filter_hiding_external_security_notifications | suspicious_email_filter_hiding_external_security_notifications | o365_management | high |
| 17 | Attack chain: risky login to MFA change to inbox rule | itdr_chain_risky_login_mfa_change_inbox_rule | itdr_chain_risky_login_mfa_change_inbox_rule | attack_chain | critical |
| 18 | Attack chain: password spray to success to lateral movement | itdr_chain_spray_success_lateral | itdr_chain_spray_success_lateral | attack_chain | critical |
| 19 | Attack chain: token replay across multiple identities | itdr_chain_token_replay_multi_identity | itdr_chain_token_replay_multi_identity | attack_chain | high |
| 20 | MFA denied challenge followed by successful sign-in | mfa_denied_then_success | mfa_denied_then_success | sign_in | high |
| 21 | Authentication method change after risky sign-in | auth_method_change_after_risky_signin | auth_method_change_after_risky_signin | attack_chain | high |
| 22 | Password reset after risky sign-in | password_reset_after_risky_signin | password_reset_after_risky_signin | attack_chain | high |
| 23 | OAuth consent activity after risky sign-in | oauth_consent_from_risky_session | oauth_consent_from_risky_session | attack_chain | high |
| 24 | MFA method weakened after risky sign-in | mfa_method_weakened | mfa_method_weakened | attack_chain | critical |
| 25 | Privileged role assignment by risky actor | privileged_role_assignment_risky_actor | privileged_role_assignment_risky_actor | attack_chain | critical |
| 26 | Likely dormant workload identity suddenly active | unused_workload_identity_suddenly_active | unused_workload_identity_suddenly_active | directory_audit | high |
28 rules
high_risk_app_change | consent_or_config_change
Trigger logic
Scoring and severity
Rule conditions
{
"event_source": "directory_audit",
"keywords": [
"consent",
"permission grant",
"credential",
"certificate",
"secret",
"owner",
"service principal",
"application"
],
"threshold": 1,
"suppress_microsoft_self_update": true,
"suppress_platform_connector_principal": true
}Evidence emitted
Alert and incident keys
Source ID: directory_audit_change:{event_id}
Grouping key: {tenant_id}:consent_or_config_change:{entity_type}:{entity_id}
Recommended next actions
rogue_application_high_privilege_new_sp | rogue_application_high_privilege_new_sp
Trigger logic
Scoring and severity
Rule conditions
{
"event_source": "directory_audit",
"keywords": [
"add service principal",
"add application",
"add app role assignment",
"add delegated permission grant"
],
"entity_age_days": 14,
"requires_high_risk_permissions": true,
"threshold": 1
}Evidence emitted
Alert and incident keys
Source ID: rogue_new_high_privilege:{event_id}
Grouping key: {tenant_id}:rogue_application_high_privilege_new_sp:{entity_type}:{entity_id}
Recommended next actions
rogue_application_ownerless_privileged | rogue_application_ownerless_privileged
Trigger logic
Scoring and severity
Rule conditions
{
"event_source": "directory_audit",
"keywords": [
"add password credential",
"add key credential",
"certificates and secrets",
"update application",
"credential",
"secret",
"certificate"
],
"requires_high_risk_permissions": true,
"requires_ownerless": true,
"threshold": 1
}Evidence emitted
Alert and incident keys
Source ID: rogue_ownerless_privileged:{event_id}
Grouping key: {tenant_id}:rogue_application_ownerless_privileged:{entity_type}:{entity_id}
Recommended next actions
rogue_application_consent_burst | rogue_application_consent_burst
Trigger logic
Scoring and severity
Rule conditions
{
"event_source": "directory_audit",
"keywords": [
"consent",
"oauth2permissiongrant",
"permission grant",
"grant admin consent"
],
"threshold": 3,
"window_minutes": 30
}Evidence emitted
Alert and incident keys
Source ID: rogue_consent_burst:{entity_type}:{entity_id}:{first_event_id}:{latest_event_id}
Grouping key: {tenant_id}:rogue_application_consent_burst:{entity_type}:{entity_id}
Recommended next actions
repeated_failed_signins | failed_signin_pattern
Trigger logic
Scoring and severity
Rule conditions
{
"event_source": "signin",
"status": "failure",
"threshold": 5,
"window_minutes": 30,
"renotify_delta": 5,
"stable_source_id_per_identity_app": true
}Evidence emitted
Alert and incident keys
Source ID: failed_signins:{identity_id}:{app_key}
Grouping key: {tenant_id}:failed_signin_pattern:identity:{identity_id}:{app_key}
Recommended next actions
Automatic reconciliation trims non-failure evidence and can auto-close stale failed-signin alerts/incidents if fewer than 5 valid failures remain.
expired_credential_secret | expired_credential_secret
Trigger logic
Scoring and severity
Rule conditions
{
"event_source": "signin",
"status_error_code": "7000222",
"threshold": 50,
"window_hours": 24,
"renotify_delta": 50
}Evidence emitted
Alert and incident keys
Source ID: expired_credential_secret:{app_id}:{day_bucket}
Grouping key: {tenant_id}:expired_credential_secret:application:{app_id}
Recommended next actions
This is an operational, not security, signal — the broken-customer-integration pattern. Inspired by 24X7Soc where one app accumulated 855 retries in 24h on an expired secret.
aitm_token_replay_distinct_device | aitm_token_replay_distinct_device
Trigger logic
Scoring and severity
Rule conditions
{
"event_source": "signin",
"interactive_status": "success",
"non_interactive_status": "success",
"window_minutes": 30,
"require_distinct_device_fingerprint": true
}Evidence emitted
Alert and incident keys
Source ID: aitm_token_replay_distinct_device:{identity_id}:{interactive_event_id}
Grouping key: {tenant_id}:aitm_token_replay_distinct_device:identity:{identity_id}
Recommended next actions
MITRE T1557 (Adversary-in-the-Middle) + T1550.001 (Application Access Token) + T1539 (Steal Web Session Cookie). Designed to catch Evilginx-style AiTM phishing kits where the proxy captures the post-MFA session cookie and the attacker replays the token from their own device.
Suppressed when both events share a deviceId or when neither side has fingerprint data — keeps noise down on legacy/legacy-OS sign-ins.
risky_signin_success | risky_signin_success
Trigger logic
Scoring and severity
Rule conditions
{
"event_source": "signin",
"status": "success",
"risk_level": [
"medium",
"high"
],
"risk_state": [
"atRisk",
"confirmedCompromised"
],
"threshold": 1,
"window_minutes": 60
}Evidence emitted
Alert and incident keys
Source ID: risky_signin_success:{event_id}
Grouping key: {tenant_id}:risky_signin_success:identity:{identity_id}
Recommended next actions
success_after_failed_signins | successful_signin_after_failures
Trigger logic
Scoring and severity
Rule conditions
{
"event_source": "signin",
"status": "success_after_failure",
"threshold": 5,
"window_minutes": 30,
"success_after_minutes": 10
}Evidence emitted
Alert and incident keys
Source ID: success_after_failures:{success_event_id}
Grouping key: {tenant_id}:successful_signin_after_failures:identity:{identity_id}:{app_key}
Recommended next actions
rapid_location_change | sign_in_anomaly
Trigger logic
Scoring and severity
Rule conditions
{
"event_source": "signin",
"status": "success",
"requires_interactive": true,
"window_minutes": 60,
"distinct_location": true,
"distinct_ip": true,
"threshold": 1
}Evidence emitted
Alert and incident keys
Source ID: rapid_location_change:{prior_event_id}:{current_event_id}
Grouping key: {tenant_id}:sign_in_anomaly:identity:{identity_id}
Recommended next actions
non_interactive_token_replay | non_interactive_token_replay
Trigger logic
Scoring and severity
Rule conditions
{
"event_source": "signin",
"status": "success",
"is_interactive": false,
"threshold": 3,
"window_minutes": 20,
"distinct_ip_min": 2,
"distinct_location_min": 2
}Evidence emitted
Alert and incident keys
Source ID: non_interactive_token_replay:{identity_id}:{app_key}:{first_event_id}:{latest_event_id}
Grouping key: {tenant_id}:non_interactive_token_replay:identity:{identity_id}:{app_key}
Recommended next actions
non_interactive_signin_anomaly | non_interactive_signin_anomaly
Trigger logic
Scoring and severity
Rule conditions
{
"event_source": "signin",
"status": "success",
"is_interactive": false,
"window_minutes": 60,
"baseline_minutes": 1440,
"threshold": 1
}Evidence emitted
Alert and incident keys
Source ID: non_interactive_signin_anomaly:{prior_interactive_id}:{current_non_interactive_id}
Grouping key: {tenant_id}:non_interactive_signin_anomaly:identity:{identity_id}
Recommended next actions
credential_theft_detection | credential_theft_detection
Trigger logic
Scoring and severity
Rule conditions
{
"event_source": "signin",
"status": "failure",
"threshold": 6,
"window_minutes": 20,
"distinct_identity_min": 4,
"group_by": "ip_address"
}Evidence emitted
Alert and incident keys
Source ID: credential_theft_detection:{public_ip}:{first_event_id}:{latest_event_id}
Grouping key: {tenant_id}:credential_theft_detection:ip:{public_ip}
Recommended next actions
malicious_datacenter_utilization | malicious_datacenter_utilization
Trigger logic
Scoring and severity
Rule conditions
{
"event_source": "signin",
"status": "success",
"threshold": 5,
"window_minutes": 30,
"distinct_identity_min": 4,
"requires_datacenter_signal_or_non_interactive_burst": true,
"group_by": "ip_address"
}Evidence emitted
Alert and incident keys
Source ID: malicious_datacenter_utilization:{public_ip}:{first_event_id}:{latest_event_id}
Grouping key: {tenant_id}:malicious_datacenter_utilization:ip:{public_ip}
Recommended next actions
This is a behavior-based heuristic for currently ingested logs, not a third-party datacenter-intel feed match.
malicious_inbox_rule_detection | malicious_inbox_rule_detection
Trigger logic
Scoring and severity
Rule conditions
{
"event_source": "o365_management",
"workload": "exchange",
"requires_inbox_rule_operation": true,
"requires_suspicious_rule_actions": true
}Evidence emitted
Alert and incident keys
Source ID: malicious_inbox_rule_detection:{source_log_id}
Grouping key: {tenant_id}:malicious_inbox_rule_detection:mailbox:{actor_or_source}
Recommended next actions
suspicious_email_filter_hiding_generic_security_notifications | suspicious_email_filter_hiding_generic_security_notifications
Trigger logic
Scoring and severity
Rule conditions
{
"event_source": "o365_management",
"workload": "exchange",
"requires_filter_terms": [
"account",
"security",
"alert",
"notification"
],
"minimum_filter_term_matches": 3
}Evidence emitted
Alert and incident keys
Source ID: suspicious_email_filter_hiding_generic_security_notifications:{source_log_id}
Grouping key: {tenant_id}:suspicious_email_filter_hiding_generic_security_notifications:mailbox:{actor_or_source}
Recommended next actions
suspicious_email_filter_hiding_finance_bec_keywords | suspicious_email_filter_hiding_finance_bec_keywords
Trigger logic
Scoring and severity
Rule conditions
{
"event_source": "o365_management",
"workload": "exchange",
"requires_filter_terms": [
"finance",
"invoice",
"wire",
"payment",
"vendor"
],
"minimum_filter_term_matches": 2
}Evidence emitted
Alert and incident keys
Source ID: suspicious_email_filter_hiding_finance_bec_keywords:{source_log_id}
Grouping key: {tenant_id}:suspicious_email_filter_hiding_finance_bec_keywords:mailbox:{actor_or_source}
Recommended next actions
suspicious_email_filter_hiding_external_security_notifications | suspicious_email_filter_hiding_external_security_notifications
Trigger logic
Scoring and severity
Rule conditions
{
"event_source": "o365_management",
"workload": "exchange",
"requires_filter_terms": [
"google",
"gmail",
"security alert",
"verification code"
],
"minimum_filter_term_matches": 2
}Evidence emitted
Alert and incident keys
Source ID: suspicious_email_filter_hiding_external_security_notifications:{source_log_id}
Grouping key: {tenant_id}:suspicious_email_filter_hiding_external_security_notifications:mailbox:{actor_or_source}
Recommended next actions
itdr_chain_risky_login_mfa_change_inbox_rule | itdr_chain_risky_login_mfa_change_inbox_rule
Trigger logic
Scoring and severity
Rule conditions
{
"sequence": [
"risky_signin_success",
"authentication_method_change",
"mailbox_rule_manipulation"
],
"window_hours": 24,
"scope": "same_identity"
}Evidence emitted
Alert and incident keys
Source ID: itdr_chain_risky_login_mfa_change_inbox_rule:{risky_alert_id}:{mfa_event_id}:{inbox_alert_id}
Grouping key: {tenant_id}:itdr_chain_risky_login_mfa_change_inbox_rule:identity:{identity}
Recommended next actions
itdr_chain_spray_success_lateral | itdr_chain_spray_success_lateral
Trigger logic
Scoring and severity
Rule conditions
{
"sequence": [
"credential_theft_detection",
"successful_signin_after_failures_or_risky_success",
"multi_identity_same_ip_access"
],
"window_minutes": 120,
"scope": "source_ip"
}Evidence emitted
Alert and incident keys
Source ID: itdr_chain_spray_success_lateral:{spray_alert_id}:{first_success_alert_id}:{latest_signin_id}
Grouping key: {tenant_id}:itdr_chain_spray_success_lateral:ip:{public_source_ip}
Recommended next actions
itdr_chain_token_replay_multi_identity | itdr_chain_token_replay_multi_identity
Trigger logic
Scoring and severity
Rule conditions
{
"sequence": [
"non_interactive_token_replay",
"shared_source_ip",
"multiple_identities"
],
"window_hours": 24,
"group_by": "source_ip"
}Evidence emitted
Alert and incident keys
Source ID: itdr_chain_token_replay_multi_identity:{source_ip}:{first_alert_id}:{latest_alert_id}
Grouping key: {tenant_id}:itdr_chain_token_replay_multi_identity:ip:{shared_source_ip}
Recommended next actions
mfa_denied_then_success | mfa_denied_then_success
Trigger logic
Scoring and severity
Rule conditions
{
"event_source": "signin",
"status": "mfa_denied_then_success",
"threshold": 2,
"window_minutes": 30,
"success_after_minutes": 15
}Evidence emitted
Alert and incident keys
Source ID: mfa_denied_then_success:{success_event_id}
Grouping key: {tenant_id}:mfa_denied_then_success:identity:{identity_id}:{app_key}
Recommended next actions
auth_method_change_after_risky_signin | auth_method_change_after_risky_signin
Trigger logic
Scoring and severity
Rule conditions
{
"sequence": [
"risky_signin_success",
"authentication_method_change"
],
"window_hours": 24,
"scope": "same_identity"
}Evidence emitted
Alert and incident keys
Source ID: auth_method_change_after_risky_signin:{risky_alert_id}:{mfa_event_id}
Grouping key: {tenant_id}:auth_method_change_after_risky_signin:identity:{identity}
Recommended next actions
password_reset_after_risky_signin | password_reset_after_risky_signin
Trigger logic
Scoring and severity
Rule conditions
{
"sequence": [
"risky_signin_success",
"password_reset"
],
"window_hours": 24,
"scope": "same_identity"
}Evidence emitted
Alert and incident keys
Source ID: password_reset_after_risky_signin:{risky_alert_id}:{password_event_id}
Grouping key: {tenant_id}:password_reset_after_risky_signin:identity:{identity}
Recommended next actions
oauth_consent_from_risky_session | oauth_consent_from_risky_session
Trigger logic
Scoring and severity
Rule conditions
{
"sequence": [
"risky_signin_success",
"oauth_consent_or_permission_grant"
],
"window_hours": 24,
"scope": "same_identity"
}Evidence emitted
Alert and incident keys
Source ID: oauth_consent_from_risky_session:{risky_alert_id}:{consent_event_id}
Grouping key: {tenant_id}:oauth_consent_from_risky_session:identity:{identity}
Recommended next actions
mfa_method_weakened | mfa_method_weakened
Trigger logic
Scoring and severity
Rule conditions
{
"sequence": [
"risky_signin_success",
"mfa_method_weakened"
],
"window_hours": 24,
"scope": "same_identity"
}Evidence emitted
Alert and incident keys
Source ID: mfa_method_weakened:{risky_alert_id}:{mfa_weakened_event_id}
Grouping key: {tenant_id}:mfa_method_weakened:identity:{identity}
Recommended next actions
privileged_role_assignment_risky_actor | privileged_role_assignment_risky_actor
Trigger logic
Scoring and severity
Rule conditions
{
"sequence": [
"risky_signin_success",
"privileged_role_assignment"
],
"window_hours": 24,
"scope": "same_identity"
}Evidence emitted
Alert and incident keys
Source ID: privileged_role_assignment_risky_actor:{risky_alert_id}:{role_event_id}
Grouping key: {tenant_id}:privileged_role_assignment_risky_actor:identity:{identity}
Recommended next actions
unused_workload_identity_suddenly_active | unused_workload_identity_suddenly_active
Trigger logic
Scoring and severity
Rule conditions
{
"event_source": "workload_identity_activity",
"min_age_days": 90,
"recent_signin_window_hours": 24,
"requires_sensitive_change_context": true,
"activation_bucket_hours": 6
}Evidence emitted
Alert and incident keys
Source ID: unused_workload_identity_suddenly_active:{service_principal_id}:{6h_activation_bucket_epoch}
Grouping key: {tenant_id}:unused_workload_identity_suddenly_active:service_principal:{service_principal_id}
Recommended next actions