Microsoft Defender for Identity
Identity protection

Microsoft Defender for Identity XDR security alerts

In brief

The page adds entries for AADInternals private-key extraction, malicious or suspicious MFA-method registration, and updates several existing alert descriptions. It removes entries for Honeytoken Activity, stolen session-cookie replay, suspicious Entra device join or registration, and adds guidance on Classic versus Defender-format alerts and alert tuning.

What Defender admins need to know

Administrators should use the refreshed alert list and linked tuning guidance when reviewing alert coverage or mappings. No required configuration change is stated.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Defender for Identity generates alerts in both the Defender format and the classic format. The Defender format provides an alert structure that's consistent with other Microsoft Defender products. Both formats are based on the same underlying detections from Defender for Identity sensors, but they differ in structure, naming, and categorization. To identify the format of each alert, check the Detection source field on the security alerts page.

Alert name mapping

Alert names in the XDR structure differ from the alert names in the classic structure, but alert IDs stay consistent between the two structures.

Security alert name Severity MITRE Technique Detector ID
AADInternals private key extraction attempt
Description:

AADInternals was used to decrypt a certificate's private key as an administrator. A successfully decrypted private key might be used to impersonate hybrid components such as Pass-through Authentication (PTA) and Microsoft Entra Cloud Sync, which might lead to lateral movement to the cloud.
HighT1552.004xdr_AADInternalsPrivateKeyExtractAttempt
A compromised user account signed in
Description:

Credential stuffing led to a successful sign in, confirming an account has been compromised and accessed by an unauthorized party.
High T1078 xdr_CredentialStuffingToolObserved
Anomalous OAuth device code authentication activity
Description:

An OAuth Device Code authentication was detected in an unusual context based on user behavior and sign-in patterns. Due to the design of Device Code flows, this activity requires immediate investigation as it may indicate unauthorized token issuance or post-authentication abuse.
High T1528, T1078.004 xdr_AnomalousDeviceCodeAuth
AS-REP roasting
Description:

Multiple attempts to sign in without preauthentication were detected. This behavior might indicate an Authentication Server Response (AS-REP) roasting attack, which targets the Kerberos authentication protocol, specifically accounts that have turned off preauthentication.
High T1558.004 xdr_AsrepRoastingAttack
DCSync attack (replication of directory services)
Description:

A DCSync replication request was detected from {IPAddress}. This indicates an attacker may be using Directory Replication Service (DRS) to extract password hashes from Active Directory, potentially compromising all domain credentials.
High T1003.006 xdr_DcSyncAttackDetected
Honeytoken ActivityMalicious registration of an attacker controlled MFA device
Description:

Honeytoken user attemptedA new malicious Microsoft Authenticator device was registered to sign inthe account, enabling persistent attacker access through an attacker controlled MFA method.
HighMedium T1098T1556.006, T1098.005 xdr_HoneytokenSignInAttemptxdr_MFAMethodAddition
Malicious sign in from a randomized user agent
Description:

A user's credentials were intercepted from an unusual user agent. This user agent has recently been observed in a sign-in pattern related to adversary-in-the-middle and password spraying attacks. We recommend that you promptly investigate this alert, as an attacker might already be using the stolen credentials to move laterally in the network.
High T1539, T1110.003, T1110.001 xdr_AnomalousRandomUASignIn
Multiple failed Okta authentication attempts detected
Description:

Multiple failed Okta authentication attempts were detected for user {AccountUpn}. A total of {TotalFailedRequestCounts} failed attempts originated from IP address {IPAddress} within a 2 minute window. The attempts involved authentication actions {ActionType}. This activity indicates a brute force attack or credential stuffing attempt. The user agent string {UserAgent} was used across all attempts.
High T1110 xdr_OktaMultipleFailedLogons
Multiple failed Okta sign in attempts followed by successful sign in with anomalous user behavior
Description:

Multiple failed sign-in attempts followed by a successful sign-in were observed for user {AccountUpn} within a short time span. The activity included high-risk properties {RiskyBehaviors}, classified by Okta as {RiskLevel}. All sign-in attempts originated from a single IP address {IPAddress}.
High T1110, T1078 xdr_OktaMultipleFailedLogonsFollowedBySignIn
Possible OAuth code theft detected through consent abuse
Description:

A possible OAuth authorization code theft has been detected. Threat actors tricked a user into granting consent or sharing an authorization code through social engineering or adversary-in-the-middle (AiTM) techniques. A stolen code is exchanged for access tokens. Threat actors then impersonate the user without a password or multifactor authentication (MFA). This allows unauthorized access to Microsoft 365 services and sensitive data.
High T1557 xdr_PossibleOauthCodeTheft
Possible overpass-the-hash attack
Description:

A possible overpass-the-hash attack was detected. In this type of attack, an attacker uses the NT hash of a user account or other Kerberos keys to obtain Kerberos tickets, which allows unauthorized access to network resources.
High T1550.002 xdr_PossibleOverPassTheHash
Possible service principal account secret leak
Description:

A failed attempt to sign in to a service principal account by a credential stuffing tool was detected. The error code indicates that the secret was valid but misused. The service principal account's credentials might have been leaked or are in the possession of an unauthorized party.
Medium T1078 xdr_CredentialStuffingToolObserved
Possible use of a stolen session cookie
Description:

An active user session was observed across different environments with inconsistent user-agent, network, or location attributes. This anomaly may indicate unauthorized session reuse and should be investigated for potential account compromise.
High T1557T1550.001, T1539, T1598T1078.004 xdr_BrowserSessionCookieTheftxdr_StolenSessionArtifactReplay
Possibly compromised service principal account signed in
Description:

A possibly compromised service principal account signed in. A credential stuffing attempt was successfully authenticated, indicating that the service principal account's credentials might have been leaked or are in the possession of an unauthorized party.
High T1078 xdr_CredentialStuffingToolObserved
Possibly compromised service principal account signed in
Description:

A possibly compromised service principal account signed in. An automated tool used for discovery successfully logged into a service principal account, indicating that the service principal account's credentials might have been leaked or are in the possession of an unauthorized party.
High T1078 xdr_DiscoveryToolObserved
Possibly compromised user account signed in
Description:

A possibly compromised user account signed in. An automated tool used for discovery successfully logged into a user account, indicating that the user account's credentials might have been leaked or are in the possession of an unauthorized party.
High T1078 xdr_DiscoveryToolObserved
Stolen session cookie replay detected
Description:

An active user session was observed across different environments with inconsistent user-agent, network, or location attributes. This anomaly may indicate unauthorized session reuse and should be investigated for potential account compromise.
HighT1557, T1539, T1598xdr_BrowserSessionCookieTheft
SailPoint ISC suspected brute-force attack
Description:

Multiple failed authentication attempts were detected in SailPoint Identity Security Cloud from the IP address {IPAddress}. This activity might indicate a potential brute-force attack.
High T1110.001 xdr_SailPointBruteforceAttack
Suspected brute-force attack (Kerberos, NTLM)
Description:

Suspicious brute force has been detected. A threat actor might have carried out brute force on your Active Directory and possibly found passwords of users, could lead to serious security threats and data breach.
Medium T1110.001 xdr_OnPremBruteforce
Suspected brute-force attack on Lightweight Directory Access Protocol (LDAP) authentication
Description:

A series of suspicious login attempts from a single device was detected against a single user account.
Medium T1110.001 xdr_LdapBindBruteforce
Suspected Conditional Access bypass via non-compliant device
Description:

A sign-in was observed from non‑compliant devices where Conditional Access policies requiring device compliance were not enforced for the accessed resources. The previously compliant devices are no longer compliant, which might indicate post‑compromise changes. This pattern might be indicative of adversarial activity where an attacker degrades device compliance while continuing to sign in to targeted resources through Conditional Access bypass paths, enabling token issuance or further access. Go through the Recommendation section to immediately investigate and mitigate associated risks.
Medium T1078.004 xdr_SuspectedCABwithNonCompliantDevice
Suspected password spray attack (Kerberos, NTLM)
Description:

Suspicious password spray has been detected. A threat actor might have carried out password spray on your Active Directory and possibly found passwords of users, could lead to serious security threats and data breach.
Medium T1110.003 xdr_OnPremPasswordSpray
Suspected password spray attack on Lightweight Directory Access Protocol (LDAP) authentication
Description:

A single device was observed attempting logins across multiple user accounts, indicating a malicious authentication pattern.
Medium T1110.003 xdr_LdapBindBruteforce
Suspicious creation of ESXi group
Description:

A suspicious VMwareVMWare ESXi group was created in the domain. This might indicate that an attacker is trying to get more permissions for later steps in an attack.
High T1098 xdr_SuspiciousUserAdditionToEsxGroup
Suspicious DMSA related activity detected
Description:

A suspicious Delegated Managed Service Account (DMSA) related activity was detected. This may indicate a compromised managed account or an attempt to exploit a DMSA account.
High T1555 xdr_SuspiciousDmsaAction
Suspicious email app consent grant
Description:

A suspicious email application consent grant has been detected from a possibly compromised user account. An attacker might have leveraged the illicit consent grant to use the legitimate email application for unauthorized access to and collection of user data, persistence, or to maliciously send email on behalf of the user.
Medium T1110.004, T1110.003 xdr_MfaTamperingAndEmailSoftwareAbuse
Suspicious Entra account enablement after disruption
Description:

An account that was previously disabled as part of a disruption or containment action was subsequently re‑enabled. This behavior is highly suspicious and may indicate an attempt by a threat actor to restore access to a compromised identity or bypass containment measures.
High T1098 xdr_SuspiciousAccountEnabled
Suspicious NTLM authentication
Description:

One or more suspicious NTLM authentication attempts originating from the IP address {SourceIpAddress} have been detected. This anomalous NTLM authentication activity is suspected to have been specially crafted by an attacker, possibly as part of an attack involving a malicious tool. The attacker might also be using stolen credentials to carry out this attack. Anomalous NTLM behavior is commonly observed in various attack techniques, including pass-the-hash, reconnaissance, brute-force, remote code execution (RCE), and others.
Medium T1550.002, T1087.002 xdr_SuspiciousNtlmAuthentication
Suspicious on-premises account enablement after disruption
Description:

An account that was previously disabled as part of a disruption or containment action was subsequently re‑enabled. This behavior is highly suspicious and may indicate an attempt by a threat actor to restore access to a compromised identity or bypass containment measures.
High T1098 xdr_SuspiciousAccountEnabled
Suspicious OS switch sign-in
Description:

An unexpected change in operating system is observed during a user sign‑in while the client profile remains consistent. Such shifts are uncommon for stable environments. This might indicate token replay, session hijacking, or authentication artifact reuse from a different platform. A potential identity compromise might be in progress through anomalous changes in the user’s device context. Go through the Recommended Action section to immediately investigate and mitigate associated risks.
Medium T1078 xdr_SuspiciousOsSwitchSignIn
Suspicious registration of a new Authenticator MFA method
Description:

A new Microsoft Authenticator device was registered for a user account that Microsoft Defender classified as very high risk. This activity might indicate that an attacker who compromised the account registered their own device to maintain persistent MFA access, allowing continued authentication even after a password reset.
MediumT1556.006, T1098.005xdr_MFAMethodAddition
Suspicious registration of a new Email MFA method
Description:

An email MFA method was added or changed for a user account that Microsoft Defender classified as very high risk. This activity might indicate that an attacker who compromised the account added their own email address as an MFA method to maintain persistent access and enable self-service password reset abuse.
MediumT1556.006, T1098.005xdr_MFAMethodAddition
Suspicious registration of a new Phone MFA method
Description:

A phone MFA method was added or changed for a user account that Microsoft Defender classified as very high risk. This might indicate that an attacker who compromised the account registered their own phone number as an MFA method to maintain persistent access and bypass future MFA challenges. Unauthorized MFA changes on a high-risk account can enable long-term account takeover.
MediumT1556.006, T1098.005xdr_MFAMethodAddition
Suspicious SAM Account Name Change
Description:

Detected a suspicious change of the SAM account name, which may indicate an attempt to exploit Kerberos authentication via NTP time manipulation (Timeroasting). This technique can allow attackers to brute-force or replay Kerberos tickets, leading to credential compromise and lateral movement.
Medium T1110.001, T1558.003 xdr_SuspiciousChangeOfSamName
Suspicious sign in with CSRF speedbump trigger
Description:

Microsoft Entra ID detected a successful risky sign-in following CSRF (cross-site request forgery) speedbump trigger alert. This typically occurs when the sign-in flow deviates from expected browser behavior, such as session or cookie inconsistencies, missing or invalid forged tokens, or rapid automated request patterns.
Medium T1557, T1185 xdr_CsrfSpeedbumpToRiskyLogin
User exhibiting spike in distinct application‑resource access combinations
Description:

A user account was observed interacting with an unusually high number of distinct cloud application‑resource combinations within a short time period and running uncommon cloud application actions. The observed activity corresponds to sign‑ins flagged as risky where multifactor authentication (MFA) was satisfied using a stored credential, and where the account password hasn't been updated recently. An increase in the diversity of accessed application‑resource combinations under these authentication conditions might reflect abnormal cloud service interaction patterns and should be reviewed.
Medium T1087 xdr_SpikeAppResourceInSignIns
Security alert name Severity MITRE Technique Detector ID
--- --- --- ---
Attempt to disable Defender for Identity service principal observed
Description:

An actor attempted to disable or impair the security application responsible for generating identity and authentication alerts. This behavior is consistent with adversaries seeking to evade detection after initial access, maintain persistence, or disrupt monitoring by modifying, stopping, or uninstalling security services. Such activity often occurs following credential compromise, privilege escalation, or lateral movement.
High T1562.001 xdr_SuspectedMDITampering
Skipped MFA on remembered device from uncommon ISP sign-in
Description:

A suspicious Microsoft Entra sign-in from an internet service provider (ISP) the account hasn't used in the past 30 days skipped multifactormulti-factor authentication (MFA) on a remembered device. This indicates that an attacker might have used a stolen persistent cookie replayed from the attacker's infrastructure instead of the user's normal network. It's important to investigate and mitigate this urgently because skipped MFA could lead to potential security risks such as unauthorized access, session hijacking, and data breach.
Medium T1550.004, T1078.004 xdr_SuspiciousMfaSkip
Suspicious access denial to view primary group ID of an object
Description:

An access control list (ACL) denied access to view the primary group ID of an object. An attacker might have compromised a user account and is looking to hide the group of a backdoor user.
Medium T1564.002 xdr_SuspiciousDenyAccessToPrimaryGroupId
Suspicious account link
Description:

An account was linked through a cross tenant administrative action. The action was performed in a suspicious way that may indicate the account may be used in an attempt to bypass MFA.
Medium T1556 xdr_SuspiciousAccountLink
Suspicious property lock deactivated on Microsoft Entra application
Description:

The servicePrincipalLockConfiguration.isEnabled property of a Microsoft Entra application or one of its associated service principals was modified. Disabling this lock removes essential built-in protections that guard against unauthorized credential rotation, redirect URI tampering, and illicit permission grants. Changes to this setting are rare during standard administrative operations and often signal suspicious activity. Threat actors can deliberately disable the lock to weaken the application's security posture, creating an opening for lateral movement or privilege escalation within the environment.
Medium T1562.001, T1671 xdr_SuspiciousPropertyLockEntra
Possible SPN enumeration via LDAP
Description:

One or more potential Service Principal Name (SPN) scanning activities via Lightweight Directory Access Protocol (LDAP), originating from the IP address {SourceIpAddress}, have been detected. This enumeration might indicate an attacker's reconnaissance within the organization and could be used in attacks such as Kerberoasting.
Medium T1087.002 xdr_PossibleSpnEnumerationLdap
Suspected account enumeration (Kerberos, NTLM, AD FS)
Description:

Suspected account enumeration has been detected. A threat actor may have enumerated accounts in Active Directory to identify and map out weaknesses or vulnerabilities. If not mitigated, this activity can lead to serious security threats and data breach.
Medium T1087.002 xdr_SuspectedAccountEnumeration
Suspicious addition of device on-premises
Description:

A suspicious addition of device on-premises has been observed. This could pose several risks such as compliance issues, unauthorized access to sensitive or confidential work-related data or intellectual property, malware or phishing attack, or data breach. Investigate immediately to mitigate associated security risks.
High T1098.005 xdr_SuspiciousAdditionOfOnPremDevice
Suspicious Entra device join or registration
Description:

A user was suspiciously registered or joined into a new device to Entra, originating from an IP address identified by Microsoft Threat Intelligence. An attacker might have compromised the user account to perform persistence and lateral movement. Investigate immediately to mitigate associated security risks.
HighT1098.005xdr_SuspiciousDeviceRegistration
Suspicious LDAP query
Description:

A suspicious Lightweight Directory Access Protocol (LDAP) query associated with a known attack tool was detected. An attacker might be performing reconnaissance for later steps.
High T1087.002 xdr_SuspiciousLdapQuery
Suspicious LDAP query targeting sensitive attributes
Description:

A suspicious LDAP query containing sensitive attributes that are uncommon for the source device has been detected in Active Directory. Attackers might be attempting to determine and plan their lateral movement in the domain. Active Directory LDAP attribute queries are used by attackers to gain critical information about the domain environment.
Medium T1087.002, T1069.002 xdr_SuspiciousSensitiveAttributeLdapQuery
Suspicious Server Message Block (SMB) enumeration from untrusted host
Description:

Suspicious SMB session enumeration targeting the MDI sensor. This indicates adversary reconnaissance aimed at identifying active user sessions on the host.
Medium T1049 xdr_SmbSessionEnumeration
Security alert name Severity MITRE Technique Detector ID
Suspicious bulk user deletion via scripted activity
Description:

A high volume of user deletion operations was detected from a single account within a short time window using a Python-based user agent. This behavior is consistent with an attacker using automated scripting to mass-delete user accounts after gaining administrative access, potentially causing widespread disruption to organizational identity infrastructure. Attackers may leverage stolen credentials or compromised service principals to delete users in bulk, disrupting business operations and removing evidence of previously compromised accounts.
Medium T1531 Nonexdr_SuspiciousBulkUserDeletion
Newly created user performed organization branding change
Description:

A newly created user account performed an organization branding change shortly after account creation. This behavior may indicate malicious use of attacker-controlled accounts with elevated privileges to perform tenant defacement or unauthorized configuration changes.
HighT1491.001, T1136.003, T1098.003xdr_SuspiciousBrandingChangesByNewUser

Initial Access alerts

|

Suspicious sign-in from an unusual user agent and IP address using device code flow
Description:

A successful sign-in was detected using an uncommon or atypical user agent combined with a potentially risky IP address. This pattern is frequently associated with password spray, credential stuffing, or other unauthorized authentication attempts originating from attacker-controlled infrastructure. In some cases, it may also indicate the use of compromised credentials for unauthorized access.
| Medium | T1078.001 | xdr_SuspiciousEntraSignIn | |
Suspicious sign-in from an unusual user agent and IP address using PowerShell
Description:

A successful sign-in was detected using an uncommon or atypical user agent combined with a potentially risky IP address. This pattern is frequently associated with password spray, credential stuffing, or other unauthorized authentication attempts originating from attacker-controlled infrastructure. In some cases, it may also indicate the use of compromised credentials for unauthorized access.
| Medium | T1078.001 | xdr_SuspiciousEntraSignIn | |
Suspicious sign-in made to an admin account
Description:

An admin account sign-in was performed in a suspicious manner. This behavior might indicate that a user account was compromised and is being used for malicious activities.
| Low | T1078.001 | xdr_SuspiciousAdminAccountSignIn | |
Suspicious sign-in made using a malicious certificate
Description:

A user signed in to the organization using a malicious certificate. This behavior might indicate that a user account was compromised and is being used for malicious activities, and that a malicious domain with Azure ADAAD Internals certificate is registered in the organization.
| High | T1078.001 | xdr_SignInUsingMaliciousCertificate | |
Suspicious sign-in observed from Entra ID sync application
Description:

A suspicious sign-in from the Entra ID synchronization service application has been detected. This behavior might indicate that the application was compromised and is being used for malicious activities. Go through the recommended actions to investigate immediately and mitigate associated risks.
| Medium | T1078.001 | xdr_SuspiciousConnectSyncProvisioningSignIn | |
Suspicious sign-in observed from Entra ID sync application to an uncommon resource app
Description:

A suspicious sign-in from the Entra ID synchronization service application to an uncommon resource application has been detected. This behavior might indicate that the application was compromised and is being used for malicious activities. Go through the recommended actions to investigate immediately and mitigate associated risks.
| Medium | T1078.001 | xdr_SuspiciousConnectSyncProvisioningSignIn | |
Suspicious sign-in observed to Entra ID sync application using an uncommon user agent
Description:

A suspicious sign-in from the Entra ID synchronization service application using an uncommon user agent has been detected. This behavior might indicate that the application was compromised and is being used for malicious activities. Go through the recommended actions to investigate immediately and mitigate associated risks.
| Medium | T1078.001 | xdr_SuspiciousConnectSyncProvisioningSignIn |

Security alert name Severity MITRE Technique Detector ID
Guest user account promoted to member
Description:

A guest (external) user account was promoted to a member (internal) account. Guest accounts typically have restricted access, while member accounts are treated as internal users and may inherit broader permissions, access to resources, and eligibility for privileged roles. This can also be abused by adversaries to escalate privileges, bypass external access restrictions, or establish persistence within the tenant.
Medium T1098 xdr_GuestToMemberPromotion
Malicious registration of a device with strong MFA
Description:

A new Microsoft Authenticator device was registered to the account shortly after compromise, enabling persistent attacker access through an attacker controlled MFA method.
MediumT1556.006, T1098.005xdr_MFAMethodAddition
OAuth app created a user
Description:

A new user account was created by an OAuth application. An attacker might have compromised this application for persistence in the organization.
Medium T1136.003 xdr_OAuthAppCreatedAUser
Okta privileged API token created
Description:

{ActorAliasName} created an API token. If stolen, it can grant the attacker access with the user's permission.
High T1078.004 xdr_OktaPrivilegedApiTokenCreated
Okta privileged API token updated
Description:

{ActorAliasName} updated a Privileged API token Configuration to be more promiscuous. If stolen, it can grant the attacker access with the user's permission.
High T1078.004 xdr_OktaPrivilegedApiTokenUpdated
Reciprocal Temporary Access Pass creation between users
Description:

Two users created Temporary Access Passes (TAPs) for each other within a short time window. This behavior may indicate a compromised account establishing circular persistence by using TAP credentials and then removing traces of the temporary credential.
High T1098 Nonexdr_ReciprocalTAPCreationViaGraphAPI
Shadow credentials added to account
Description:

A shadow credential injection has been detected on the account. This could be an indication of persistence or lateral movement. Attackers inject shadow credentials to Active Directory (AD) accounts to gain or maintain access to the account they're hacking.
High T1098 xdr_ShadowCredentialsAttack
Shadow Credentials Added to Account and Used for Authentication
Description:

An account had shadow credentials injected into it, and they have been used for authentication. When this happens, attackers could bypass traditional credential theft methods to gain persistent access to a user account. Aside from persistence, this could also be an indication of lateral movement.
High T1098 xdr_ShadowCredentialsAttack
Suspicious addition of ACL on-premises
Description:

Suspicious addition of ACL on-premises has been observed. This can lead to unauthorized access, gaining elevated permissions, account and resource compromise, lateral movement, among others. Investigate immediately to mitigate associated security risks.
High T1098 xdr_SuspiciousAdditionOfAcl
Suspicious addition of alternative phone number
Description:

A new alternative phone number was added for a user or users in a suspicious way. An attacker might have done this to manipulate multifactormulti-factor authentication and leverage mobile phone authentication to fraudulently gain persistence in the organization.
Medium T1556.006 xdr_SuspiciousMFAAddition
Suspicious addition of default third‑party MFA method to user account
Description:

A new third‑party multifactor authentication method was set as the default for a user account. Changing the default MFA provider could allow sign‑ins to be approved outside of the organization’s standard authentication flow and might indicate account manipulation intended to persist access or weaken enforcement. Go through the Recommendation section to immediately investigate and mitigate associated risks.
Medium T1556.006 xdr_Suspicious3rdPartyMfaAddition
Suspicious addition of email
Description:

New email was added for multiple users in a suspicious way. An attacker might have done this to gain persistence in the organization.
Medium T1556.006 xdr_SuspiciousMFAAddition
Suspicious change to primary group ID
Description:

A user's primary group ID was modified. An attacker might have compromised a user account and assigned a backdoor user with strong permissions in the domain for later use.
High T1098 xdr_SuspiciousChangeInUserPrimaryGroupId
Suspicious MFA tampering activity by admin account
Description:

An administrator account performed multifactor authentication (MFA) tampering activity after a risky authentication. An attacker might have compromised an admin account to manipulate MFA settings for possible lateral movement activity.
Low T1556.006 xdr_AdminAccountTakeover
Suspicious removal of privileged app role assignment through Graph API
Description:

A privileged app role assignment was deleted through Microsoft Graph API. This activity might indicate unauthorized removal or modification of application privileges.
High T1114 xdr_SuspiciousAppRoleAssignmentDeletion
Suspicious resource-based constrained delegation (RBCD) attribute change
Description:

One or more suspicious Resource-Based Constrained Delegation (RBCD)-related Active Directory (AD) attribute changes were detected. Such activity is often an initial step in RBCD attacks and might allow an attacker to impersonate users when accessing the targeted account affected by the RBCD attribute change. This behavior might indicate an attacker's attempt to achieve privilege escalation and establish persistence within the organization.
Medium T1098 xdr_SuspiciousRbcdAttributeChange
Suspicious service principal sign-in following credential addition
Description:

Anomalous service principal sign-Service Principal sign in to access {ResourceDisplayName} detected, shortly after new credentials are added. Such activity may indicate application persistence, unauthorized credential implantation, privilege escalation, or Service Principal compromise.
Medium T1098.001 xdr_AnomalousSPNSignInAfterCredAddition
Suspicious sign‑in by a user exhibiting a spike in account update activity
Description:

A user account that exhibited an unusual increase in account update operations, including changes to authentication methods such as the removal of multifactor authentication (MFA), was also observed performing a suspicious sign‑in activity. This pattern might indicate attempts to modify authentication settings or access the account in a manner consistent with unauthorized use.
Medium T1098 xdr_SuspiciousSpikeUserUpdate
User was created and assigned to Global Administrator role
Description:

A new user was created and assigned to Global Administrator role. An attacker might have compromised the user account to perform persistence and lateral movement.
High T1136.003, T1098.003 xdr_SuspiciousUserCreationAndSensitiveRoleAssignment
User was created and assigned to sensitive role
Description:

A new user was created and assigned to a sensitive role. An attacker might have compromised the user account to perform persistence and lateral movement.
Medium T1136.003, T1098.003 xdr_SuspiciousUserCreationAndSensitiveRoleAssignment
Anomalous activity following Global Administrator elevation
Description:

Anomalous behavior was observed on a user account around Global Administrator role elevation. The activity includes unusual Graph API patterns such as persistence, credential manipulation, policy changes, and reconnaissance, along with burst call behavior, failed access attempts, and risky sign-in events from unfamiliar locations or devices. This activity might indicate credential abuse, privilege escalation, backdoor creation, or compromise of the elevated Global Administrator account.
Medium T1078.004, T1098 xdr_AnomalousGlobalAdminActivity
Okta privilege escalation following anomalous sign in by {ActorAliasName}
Description:

An anomalous Okta sign in attempt (event {AnomalousLoginEventId}) at {AnomalousLoginTime} from IP address {IPAddress} was followed by privileged action {PrivilegedActionType} within the same session {SessionId} at {Timestamp}. Time delta between events: {DeltaSeconds}s.
High T1110, T1548 xdr_OktaPrivilegeEscalationFollowingSignIn
Okta session impersonation leading to privileged action for {AccountUpn}
Description:

An Okta impersonation session (event {ImpersonationStartEventId}) was initiated at {ImpersonateSessionTime} from IP address {IPAddress}. A privileged action {PrivilegedActionType} occurred within the same session {SessionId} at {Timestamp}. The time between events was {DeltaSeconds}s
High T1548, T1134 xdr_OktaUserSessionImpersonationPrivilegedAction
Potential Certighost (CVE-2026-54121) AD CS abuse
Description:

Activity associated with potential Certighost (CVE-2026-54121) abuse was detected in Active Directory Certificate Services (AD CS). This activity may indicate an attempt to abuse certificate enrollment or certificate-based authentication to impersonate a privileged identity, including a domain controller, and elevate privileges in the domain.
HighT1649, T1550.003xdr_CertighostAdcsChaseAbuse
Risky sign in followed by privilege role grant
Description:

A user account flagged with a high risk Microsoft Entra sign in assessment was assigned to a high privilege directory role such as Global Administrator or Privileged Role Administrator shortly after logging in, using the Add member to role operation. This sequence strongly suggests a compromised credential followed by rapid privilege escalation.
Medium T1078.004, T1098.003 xdr_RiskySignInFollowedByPrivilegedRoleGrant
Suspected certificate enrollment abuse (ESC15)
Description:

A certificate was enrolled suspiciously. An attacker might be using the ESC15 technique to exploit CVE-2024-49019 (https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-49019) and escalate privileges in the forest.
High T1068 xdr_SuspectedCertificateEnrollmentESC15
Suspicious addition and removal of elevated privileges
Description:

A high-privilege Entra ID role (for example, Global Administrator or Privileged Role Administrator) was granted to user or service principal and was quickly revoked after. This rapid role assignment and removal pattern is uncommon in regular administrative workflows and might indicate an attempt to evade detection during privilege escalation. Investigate this alert immediately to prevent or mitigate any unauthorized access, privilege escalation, and security breach.
Medium T1078.004 xdr_SuspiciousAdditionAndRemovalOfPrivilegedRole