Product
Monitoring High-Risk Sign-ins in Microsoft Entra ID
1 rule 1 TTPThis brief details the detection of compromised cloud accounts by leveraging Microsoft Identity Protection telemetry to identify high-risk authentication events indicative of credential abuse.
Microsoft Security Updates — July 2026
11 CVEs 354 IOCsRoundup of Microsoft security advisories published in July 2026.
Microsoft Entra ID Guest Account Promoted to Member
1 rule 1 TTPA sophisticated threat actor, having compromised an existing guest account in Microsoft Entra ID, can establish persistent access and elevate privileges by performing a Guest-to-Member account conversion, which grants full directory read access and bypasses Conditional Access restrictions, enabling stealthy long-term access and reconnaissance.
Microsoft Entra ID Temporary Access Pass (TAP) Abuse for MFA Bypass and Persistence
3 rules 2 TTPsAn attacker with elevated privileges abuses the Microsoft Entra ID Temporary Access Pass (TAP) feature to bypass multi-factor authentication (MFA), gain unauthorized access to target user accounts, and establish persistence by registering new authentication methods.
Microsoft 365 OAuth Device Code Phishing Exploits Non-Compliant Devices
2 rules 3 TTPsAttackers are actively exploiting the OAuth device code flow in Microsoft 365 to bypass multi-factor authentication (MFA) and gain initial access, leveraging phishing kits like Kali365 and tradecraft similar to Storm-2372 to harvest MFA-satisfied tokens from non-compliant or attacker-controlled devices, and subsequently establishing persistence through device registration.
Entra ID Microsoft Authentication Broker DRS Sign-In from Suspicious ASN
2 rules 3 TTPsDetects Microsoft Entra ID sign-in activity where the Microsoft Authentication Broker requests the Device Registration Service from a suspicious ASN, indicating potential OAuth phishing or adversary-in-the-middle device registration.
Storm-2949 Abuses SSPR for Cloud-Wide Data Exfiltration
2 rules 6 TTPsStorm-2949 compromised cloud identities through social engineering and abused the Self-Service Password Reset (SSPR) process to bypass MFA and gain persistent access, enabling lateral movement and data exfiltration from Microsoft 365 and Azure environments.
Tycoon2FA AiTM Phishing via Microsoft Entra ID Sign-Ins
2 rules 2 TTPsDetects Microsoft Entra ID sign-ins consistent with Tycoon2FA phishing-as-a-service (PhaaS) adversary-in-the-middle (AiTM) activity targeting Microsoft 365 and Gmail, where the Microsoft Authentication Broker requests tokens for Microsoft Graph or Exchange Online, or the Office web client application authenticates to itself, combined with Node.js-style user agents (node, axios, undici).
Entra ID Sign-in Brute Force Attempt Against Microsoft 365
2 rules 1 TTPA high volume of failed Microsoft Entra ID sign-in attempts against Microsoft 365 services within a short time period indicates a potential brute-force attack, which could lead to unauthorized access to Microsoft 365 services.
M365 Identity Login from Atypical Travel Location
2 rules 1 TTPThis rule detects successful Microsoft 365 portal logins from rare locations, potentially indicating an adversary attempting to access an account from an unusual location or behind a VPN.
Entra ID OAuth Phishing via Auth Broker to DRS
2 rules 1 TTP 2 IOCsDetection of OAuth phishing in Microsoft Entra ID through Microsoft Authentication Broker (MAB) and Device Registration Service (DRS) indicated by the same user principal and session ID originating from multiple IP addresses within a short timeframe, indicative of unauthorized token acquisition.
Entra ID Service Principal Creation for Persistence
2 rules 1 TTPAn adversary may create a new service principal in Microsoft Entra ID to establish persistence and potentially impersonate legitimate services or applications, blending in with normal activity.
Entra ID Privilege Escalation to User Access Administrator
2 rules 2 TTPsA user has elevated their access to User Access Administrator for their Azure Resources, potentially leading to privilege escalation and unauthorized access; this activity is flagged only if the user hasn't performed it in the last 14 days.
Multiple Entra ID Protection Alerts Indicate Potential Account Compromise
2 rules 3 TTPsMultiple Microsoft Entra ID Protection alerts associated with a single user in a short timeframe may indicate an ongoing attack or compromised account, stemming from suspicious sign-in activity such as anomalous IP addresses or risky sign-ins.
Entra ID OAuth Device Code Flow Phishing
2 rules 3 TTPsAttackers are leveraging device code phishing to steal application access tokens from users of Entra ID OAuth applications, by tricking users into entering codes into attacker-controlled polling clients, leading to unauthorized access to cloud resources.
Entra ID Protection Alert Followed by Device Registration
2 rules 2 TTPsDetection of a Microsoft Entra ID protection alert followed by a new device registration attempt by the same user, potentially indicating account compromise and unauthorized device registration for persistence.
Entra ID Unusual ROPC Login Attempt
2 rules 2 TTPsDetects unusual resource owner password credential (ROPC) login attempts by a user principal in Microsoft Entra ID, potentially indicating account compromise or password spraying.
BloodHound Suite User-Agent Detected in Entra ID Sign-ins
3 rules 6 TTPsDetection of BloodHound tools like AzureHound and SharpHound being used to enumerate Microsoft Entra ID and Microsoft 365 environments, potentially indicating reconnaissance activity by red teams or malicious actors.
Entra ID Illicit Consent Grant via Registered Application
2 rules 3 TTPsAttackers register malicious applications within Entra ID and deceive users into granting extensive permissions through OAuth consent, enabling unauthorized access to sensitive data like emails and files.
Entra ID Service Principal Sign-in from Unusual Source ASN
2 rules 2 TTPsDetects Entra ID service principal sign-ins from a source ASN that is unusual based on a history window, potentially indicating compromised credentials or a rogue application.
Entra ID OAuth User Impersonation to Microsoft Graph
2 rules 2 TTPsDetects potential session hijacking or token replay in Microsoft Entra ID, where a user signs in and subsequently accesses Microsoft Graph from a different IP address using the same session ID, indicating a successful OAuth phishing attack, session hijacking, or token replay attack.
TeamFiltration Tool User-Agent Detected in Entra ID Sign-ins
2 rules 7 TTPs 1 IOCThe TeamFiltration tool, used for Entra ID and Microsoft 365 enumeration and password spraying, is detected via specific user-agent strings in sign-in logs.
M365 Identity OAuth Illicit Consent Grant by Rare Client and User
2 rules 3 TTPsAdversaries may register a malicious application in Microsoft Entra ID and trick users into granting excessive permissions via OAuth consent, allowing the malicious application to access resources in Microsoft 365 on behalf of the user, potentially leading to data exfiltration.
Entra ID Protection Admin Confirmed Compromise
3 rules 3 TTPsAn administrator's confirmation of a compromised user or sign-in in Microsoft Entra ID Protection signals a high-confidence account compromise requiring immediate investigation and remediation.
Entra ID Protection - Sign-in Risk Detection
3 rules 4 TTPsThis brief covers detection of sign-in risk events identified by Microsoft Entra ID Protection, including anonymized IP addresses, unlikely travel, and password spray attacks, which can indicate compromised accounts or malicious activity.
Entra ID OAuth Authorization Code Grant for Unusual User, App, and Resource
2 rules 3 TTPsDetects the first-time use of an OAuth 2.0 authorization code grant flow for a specific combination of user, application, and resource in Microsoft Entra ID, potentially indicating OAuth phishing attacks like ConsentFix, where attackers steal authorization codes.
Entra ID Custom Domain Added or Verified
2 rules 1 TTPDetection of custom domain additions or verifications in Entra ID, a precursor to potentially malicious domain federation for Golden SAML attacks.
Azure AD Admin Consent Bypassed by Service Principal
2 rules 1 TTPA service principal in Azure Active Directory is assigning app roles without standard admin consent, potentially leading to unauthorized privilege escalation by exploiting automation to assign sensitive permissions without proper oversight.
Unusual Microsoft Graph Email Access via OAuth Application
2 rules 2 TTPsAn adversary might use a phished OAuth refresh token or Primary Refresh Token (PRT) with a first-party application to access email resources via Microsoft Graph API, particularly focusing on unusual application and user combinations.
Entra ID High Risk Sign-in Detected
2 rules 1 TTPThis rule detects high-risk sign-ins in Microsoft Entra ID, as identified by Identity Protection, where the sign-in is flagged with a risk level of `high` during the authentication process, indicating a strong likelihood of account compromise.
Entra ID User Sign-in with Unusual Non-Managed Device
2 rules 2 TTPsDetects Microsoft Entra ID user sign-ins from devices not typically used or managed, indicating potential account compromise or unauthorized access via device registration for persistence.
Entra ID Conditional Access Policy (CAP) Modified
2 rules 2 TTPsAn adversary may modify existing Conditional Access Policies (CAPs) in Microsoft Entra ID to weaken access controls and maintain persistence in the environment with a compromised identity.