Tag
high
advisory
Azure AD Threat Intelligence Detection
2 rules 1 TTPThis brief focuses on detecting unusual user activity and sign-in patterns flagged by Azure AD Threat Intelligence, which may indicate stealthy attacks, persistence attempts, privilege escalation, or initial access.
Azure Active Directory
azuread
threat-intelligence
risk-detection
2r
1t
high
advisory
Entra ID Protection Detects User Risk
3 rules 4 TTPsEntra ID Protection detects user risk activity such as anonymized IP addresses, unlikely travel, password spray, and other suspicious behaviors indicating potential initial access attempts and compromised accounts within cloud environments.
Entra ID
azure
entra-id
risk-detection
initial-access
3r
4t