Entra ID Detection Pack
61 detection rules for Microsoft Entra ID — covering MFA abuse, Identity Protection risk events, Conditional Access bypass, OAuth consent phishing, and privileged role manipulation. The identity layer is the primary breach vector.
Pack summary
- Detection rules
- 61
- Critical severity
- 17
- Log sources
- 5
- ATT&CK techniques
- 20
What's included
61 rules across 5 threat categories for Entra ID identity threats.
MFA fraud alerts, impossible travel, brute force, sign-in risk events, token replay.
Global admin assignment, PIM role activation anomalies, directory sync account abuse.
Consent phishing, service principal credential addition, app registration abuse.
CA policy deletion, named location exclusions, SSPR disabling, federation trust addition.
High user risk, high sign-in risk, leaked credentials, anonymised IP address detections.
Detection rules (20 of 61 shown)
Showing 20 representative rules. All 61 rules activate with one click.
| Rule name | Severity |
|---|---|
| Entra ID MFA Fraud Alert Submitted | Critical |
| Entra ID Global Administrator Role Assigned | Critical |
| Entra ID Conditional Access Policy Disabled | Critical |
| Entra ID Sign-In Risk Detected — High | Critical |
| Entra ID User Risk Detected — High | Critical |
| Entra ID Privileged Identity Management Role Activation Outside Business Hours | High |
| Entra ID Application Registration — New Secret or Certificate | High |
| Entra ID OAuth Application Granted High-Privilege Consent | High |
| Entra ID Guest User Added to Privileged Group | High |
| Entra ID Impossible Travel Sign-In — Successful | High |
| Entra ID Sign-In from Tor Exit Node | High |
| Entra ID Token Replay Detected by Identity Protection | Critical |
| Entra ID Directory Synchronisation Account Used Interactively | Critical |
| Entra ID Password Reset by Admin Without Ticket | Medium |
| Entra ID Named Location Added to CA Policy Exclusion | High |
| Entra ID Service Principal Created with KeyCredential | High |
| Entra ID Self-Service Password Reset Disabled | High |
| Entra ID Brute Force — Multiple Authentication Failures | High |
| Entra ID External Federation Trust Added | Critical |
| Entra ID Audit Log Deletion or Purge | Critical |
Prerequisites
- Entra ID diagnostic settings configured to export Sign-In and Audit logs to Log Analytics workspace or Event Hub
- Microsoft Identity Protection P2 license for risk event data (P1 provides limited risk signals)
- Privileged Identity Management enabled and audit logs exported for PIM-related detections
- Entra ID Conditional Access configured — CA evaluation logs are required for bypass detections
Entra ID Detection Pack: frequently asked questions
What Entra ID log types does this detection pack use?
The Entra ID detection pack uses Sign-In Logs (interactive and non-interactive), Audit Logs (directory change events), Identity Protection risk events, Privileged Identity Management audit logs, and Conditional Access evaluation logs. All log types must be exported to a Log Analytics workspace or Event Hub for ingestion.
How does ManySignal use Microsoft Identity Protection risk signals?
ManySignal ingests Identity Protection risk events and incorporates them into its own risk scoring. When Identity Protection raises a high user or sign-in risk, ManySignal correlates this with other events (unusual resource access, mailbox delegation changes) to produce enriched, high-confidence alerts with investigation context.
Can ManySignal detect OAuth consent phishing attacks?
Yes. OAuth consent phishing (T1528) is a detection specifically targeting high-privilege OAuth application consent grants — especially for permissions like Mail.Read, Calendars.Read, Files.ReadWrite.All, or admin consent for all users in the tenant. ManySignal alerts on these grants immediately and surfaces the application's publisher verification status.
Does this pack cover Entra ID Privileged Identity Management?
Yes. PIM role activations outside business hours, activations from atypical locations, and role assignments that bypass PIM eligibility (direct permanent assignment) are all covered. PIM audit logs must be configured to flow to your Log Analytics workspace.
How does ManySignal handle Microsoft 365 Defender and Entra ID signal overlap?
ManySignal deduplicates Entra ID signals that are also surfaced in Microsoft 365 Defender incidents. When the same event appears in both sources, ManySignal merges the signals into a single alert with full context from both platforms, preventing double-alerting while preserving all available evidence.
Detect Entra ID identity threats before attackers establish M365 persistence
61 detection rules for Microsoft Entra ID with Identity Protection integration, PIM monitoring, and OAuth consent phishing coverage.