title: Privilege Role Sign-In Outside Expected Controls id: cf1e5687-84e1-41af-97a9-158094efef53 status: test description: Detects failed sign-in due to user not meeting expected controls for adminitrators references: - https://docs.microsoft.com/en-us/azure/active-directory/fundamentals/security-operations-privileged-accounts#things-to-monitor author: Mark Morowczynski '@markmorow', Yochana Henderson, '@Yochana-H' date: 2022-08-11 modified: 2023-12-15 tags: - attack.initial-access - attack.persistence - attack.privilege-escalation - attack.stealth - attack.t1078 logsource: product: azure service: signinlogs detection: # You have to tune the rule for your environment before use it selection: # Countries you do NOT operate out of e,g GB, use list for mulitple location|expand: '%UnLegitCountries%' callerIpAddress|expand: '%UnApprovedIp%' # unapproved browser, operating system properties.deviceDetail.deviceId|expand: '%UnApprovedDevice%' filter_main_success: resultType: 0 condition: selection and not 1 of filter_main_* falsepositives: - Unknown level: high