MFA was disabled for an Azure identity
Synopsis
Field
Value
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
1 Hour
Required Data
AzureAD Audit Log
Detection Modules
Identity Threat Module, SaaS Threat Detection
ATT&CK Tactic
Credential Access (TA0006), Persistence (TA0003), Defense Impairment (TA0112)
ATT&CK Technique
Modify Authentication Process: Multi-Factor Authentication (T1556.006)
Severity
Low
Description
MFA was disabled for the user.
Attacker's Goals
This allows the attacker to connect using this account without the need for the additional layer of authentication.
Investigative actions
Follow further actions by the initiator.
Check the login activity from this account.
Follow further actions done by this account.
Variations
PreviousMFA was disabled for a Google Workspace user
NextMicrosoft 365 DLP policy disabled or removed
Was this helpful?
