This website uses cookies to ensure you get the best experience.
Got it!
Register
|
Login
Menu
Home
Sigma Rules
Splunk Rules
Explore Rules
Analytic Stories
MITRE ATT&CK
Overview
Matrix
Techniques
Groups
Software
Campaigns
Search
About
Disabled MFA to Bypass Authentication Mechanisms
Original Source:
[Sigma source]
Title:
Disabled MFA to Bypass Authentication Mechanisms
Status:
test
Description:
Detection for when multi factor authentication has been disabled, which might indicate a malicious activity to bypass authentication mechanisms.
References:
-https://learn.microsoft.com/en-us/azure/active-directory/authentication/howto-mfa-userstates
-https://learn.microsoft.com/en-us/entra/identity/monitoring-health/reference-audit-activities#core-directory
-https://research.splunk.com/cloud/482dd42a-acfa-486b-a0bb-d6fcda27318e/
-https://analyticsrules.exchange/analyticrules/65c78944-930b-4cae-bd79-c3664ae30ba7/
-https://www.elastic.co/docs/reference/security/prebuilt-rules/rules/integrations/azure/persistence_entra_id_mfa_disabled_for_user
Author:
@ionsor
Date:
2022-02-08
modified:
2026-04-30
Tags:
-'attack.credential-access'
-'attack.persistence'
-'attack.defense-impairment'
-'attack.t1556'
Logsource:
product: azure
service: auditlogs
Detection:
selection:
operationName
:
'Disable Strong Authentication'
properties.result
:
'success'
condition
:
selection
Falsepositives:
-Authorized modification by administrators
Level:
medium