title: Azure AD Threat Intelligence id: a2cb56ff-4f46-437a-a0fa-ffa4d1303cba status: test description: Indicates user activity that is unusual for the user or consistent with known attack patterns. references: - https://learn.microsoft.com/en-us/entra/id-protection/concept-identity-protection-risks#azure-ad-threat-intelligence-sign-in - https://learn.microsoft.com/en-us/entra/id-protection/concept-identity-protection-risks#azure-ad-threat-intelligence-user - https://learn.microsoft.com/en-us/entra/architecture/security-operations-user-accounts#unusual-sign-ins author: Mark Morowczynski '@markmorow', Gloria Lee, '@gleeiamglo' date: 2023-09-07 tags: - attack.stealth - attack.t1078 - attack.persistence - attack.privilege-escalation - attack.initial-access logsource: product: azure service: riskdetection detection: selection: riskEventType: 'investigationsThreatIntelligence' condition: selection falsepositives: - We recommend investigating the sessions flagged by this detection in the context of other sign-ins from the user. level: high