Analytics BIOC Low

MFA was disabled for an Azure identity

MFA was disabled for the user.

Module:
Identity Threat Detection (ITDR), SaaS Threat Detection
Licensed by:
Identity Threat Detection (ITDR)
Data source:
AzureAD Audit Log
ATT&CK tactics: Credential Access (TA0006) Defense Evasion (TA0005) Persistence (TA0003)
ATT&CK techniques: Modify Authentication Process (T1556)
Attacker's goals:

This allows the attacker to connect using this account without the need for the additional layer of authentication.

Investigative actions:

Follow further actions by the initiator. Check the login activity from this account. Follow further actions done by this account.

Test period:
N/A (single event)
Deduplication:
1 Hour
2 variations:
  • Suspicious MFA was disabled for an Azure identity Medium (parent: Low)
  • MFA was disabled for an Azure identity regularly by the user Informational (parent: Low)