Analytics BIOC Informational

Suspicious MFA request reported by user in Entra ID

A user has flagged an MFA request as suspicious in Microsoft Entra ID. This could indicate a potential compromised user account or unauthorized access attempt.

Module:
Identity Threat Detection (ITDR), SaaS Threat Detection
Licensed by:
Identity Threat Detection (ITDR)
Data source:
AzureAD Audit Log
ATT&CK tactics: Persistence (TA0003) Initial Access (TA0001)
ATT&CK techniques: Valid Accounts (T1078)
Attacker's goals:

An attacker may attempt to gain unauthorized access to the account.

Investigative actions:

Check if the authentication attempt was legitimate. Investigate any recent unusual login behavior or IP addresses associated with the account. Verify whether the user has recently changed their authentication methods or account settings. Follow the account for possible suspicious or unusual logins.

Test period:
N/A (single event)
Deduplication:
1 Day
1 variation:
  • Suspicious MFA request reported by a sensitive user in Entra ID Low (parent: Informational)