Alerts related to data source "AzureAD".
A disabled user attempted to authenticate via SSO
A possible risky login to Azure
A successful SSO sign-in from TOR
A user accessed multiple unusual resources via SSO
A user connected from a new country
A user logged in at an unusual time via SSO
Authentication attempt by a honey user
First connection from a country in organization
First SSO access from ASN for user
First SSO access from ASN in organization
First SSO Resource Access in the Organization
Impossible traveler - SSO
Intense SSO failures
Invalid SAML Detected
IP Rotation Pattern in SSO Spray
Possible ConsentFix - OAuth Token Theft Detected
Possible Impossible Travel Pattern - SSO
SSO authentication attempt by a honey user
SSO authentication by a machine account
SSO authentication by a service account
SSO Brute Force
SSO Password Spray
SSO with abnormal operating system
SSO with abnormal user agent
SSO with new operating system
Suspicious authentication with Azure Password Hash Sync user
Suspicious Azure AD interactive sign-in using PowerShell
Suspicious SSO access from ASN
User attempted to connect from a suspicious country
User signed in to an application via Power Automate for the first time
Was this helpful?