Initial Access (TA0001)(external, opens in a new tab or window)
text code block:data_stream.dataset:azure.signinlogs and ( azure.signinlogs.properties.risk_level_during_signin:high or azure.signinlogs.properties.risk_level_aggregated:high ) and not (event.outcome:failure and azure.signinlogs.properties.risk_level_aggregated:none and azure.signinlogs.properties.risk_state:none) and not azure.signinlogs.properties.risk_state:(remediated or dismissed or confirmedSafe)
Install detection rules in Elastic Security
Detect Entra ID High Risk Sign-in in the Elastic Security detection engine by installing this rule into your Elastic Stack.
To setup this rule, check out the installation guide for Prebuilt Security Detection Rules(external, opens in a new tab or window).