Analytics BIOC
Low
✕
MFA was disabled for an Azure identity
MFA was disabled for the user.
- Module:
- Identity Threat Detection (ITDR), SaaS Threat Detection
- Licensed by:
- Identity Threat Detection (ITDR)
- Data source:
- AzureAD Audit Log
ATT&CK tactics: Credential Access (TA0006) Defense Evasion (TA0005) Persistence (TA0003)
ATT&CK techniques: Modify Authentication Process (T1556)
Attacker's goals:
This allows the attacker to connect using this account without the need for the additional layer of authentication.
Investigative actions:
Follow further actions by the initiator. Check the login activity from this account. Follow further actions done by this account.
- Test period:
- N/A (single event)
- Deduplication:
- 1 Hour
2 variations:
- Suspicious MFA was disabled for an Azure identity Medium (parent: Low)
- MFA was disabled for an Azure identity regularly by the user Informational (parent: Low)