Suspicious MFA request reported by user in Entra ID
Synopsis
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
1 Day
Required Data
AzureAD Audit Log
Detection Modules
Identity Threat Module, SaaS Threat Detection
ATT&CK Tactic
Persistence (TA0003), Initial Access (TA0001)
ATT&CK Technique
Valid Accounts (T1078)
Severity
Informational
Description
A user has flagged an MFA request as suspicious in Microsoft Entra ID. This could indicate a potential compromised user account or unauthorized access attempt.
Attacker's Goals
An attacker may attempt to gain unauthorized access to the account.
Investigative actions
Check if the authentication attempt was legitimate.
Investigate any recent unusual login behavior or IP addresses associated with the account.
Verify whether the user has recently changed their authentication methods or account settings.
Follow the account for possible suspicious or unusual logins.
Variations
Was this helpful?
