Initial Access (TA0001)(opens in a new tab or window)
event.dataset: "azure.identity_protection" and
event.action: "User Risk Detection" and
azure.identityprotection.properties.activity: "signin"
Install detection rules in Elastic Security
Detect Entra ID Protection - Risk Detection - Sign-in Risk in the Elastic Security detection engine by installing this rule into your Elastic Stack.
To setup this rule, check out the installation guide for Prebuilt Security Detection Rules(opens in a new tab or window).