M ManySignal
Detection Pack Microsoft Entra ID

Entra ID Detection Pack

61 detection rules for Microsoft Entra ID — covering MFA abuse, Identity Protection risk events, Conditional Access bypass, OAuth consent phishing, and privileged role manipulation. The identity layer is the primary breach vector.

Pack summary

Detection rules
61
Critical severity
17
Log sources
5
ATT&CK techniques
20

What's included

61 rules across 5 threat categories for Entra ID identity threats.

Authentication & MFA Threats 20 rules

MFA fraud alerts, impossible travel, brute force, sign-in risk events, token replay.

Privileged Access Abuse 15 rules

Global admin assignment, PIM role activation anomalies, directory sync account abuse.

OAuth & Application Threats 12 rules

Consent phishing, service principal credential addition, app registration abuse.

Conditional Access & Policy Tampering 8 rules

CA policy deletion, named location exclusions, SSPR disabling, federation trust addition.

Identity Protection Signals 6 rules

High user risk, high sign-in risk, leaked credentials, anonymised IP address detections.

Detection rules (20 of 61 shown)

Showing 20 representative rules. All 61 rules activate with one click.

Rule name Severity
Entra ID MFA Fraud Alert Submitted Critical
Entra ID Global Administrator Role Assigned Critical
Entra ID Conditional Access Policy Disabled Critical
Entra ID Sign-In Risk Detected — High Critical
Entra ID User Risk Detected — High Critical
Entra ID Privileged Identity Management Role Activation Outside Business Hours High
Entra ID Application Registration — New Secret or Certificate High
Entra ID OAuth Application Granted High-Privilege Consent High
Entra ID Guest User Added to Privileged Group High
Entra ID Impossible Travel Sign-In — Successful High
Entra ID Sign-In from Tor Exit Node High
Entra ID Token Replay Detected by Identity Protection Critical
Entra ID Directory Synchronisation Account Used Interactively Critical
Entra ID Password Reset by Admin Without Ticket Medium
Entra ID Named Location Added to CA Policy Exclusion High
Entra ID Service Principal Created with KeyCredential High
Entra ID Self-Service Password Reset Disabled High
Entra ID Brute Force — Multiple Authentication Failures High
Entra ID External Federation Trust Added Critical
Entra ID Audit Log Deletion or Purge Critical

Prerequisites

  • Entra ID diagnostic settings configured to export Sign-In and Audit logs to Log Analytics workspace or Event Hub
  • Microsoft Identity Protection P2 license for risk event data (P1 provides limited risk signals)
  • Privileged Identity Management enabled and audit logs exported for PIM-related detections
  • Entra ID Conditional Access configured — CA evaluation logs are required for bypass detections

Entra ID Detection Pack: frequently asked questions

What Entra ID log types does this detection pack use?

The Entra ID detection pack uses Sign-In Logs (interactive and non-interactive), Audit Logs (directory change events), Identity Protection risk events, Privileged Identity Management audit logs, and Conditional Access evaluation logs. All log types must be exported to a Log Analytics workspace or Event Hub for ingestion.

How does ManySignal use Microsoft Identity Protection risk signals?

ManySignal ingests Identity Protection risk events and incorporates them into its own risk scoring. When Identity Protection raises a high user or sign-in risk, ManySignal correlates this with other events (unusual resource access, mailbox delegation changes) to produce enriched, high-confidence alerts with investigation context.

Can ManySignal detect OAuth consent phishing attacks?

Yes. OAuth consent phishing (T1528) is a detection specifically targeting high-privilege OAuth application consent grants — especially for permissions like Mail.Read, Calendars.Read, Files.ReadWrite.All, or admin consent for all users in the tenant. ManySignal alerts on these grants immediately and surfaces the application's publisher verification status.

Does this pack cover Entra ID Privileged Identity Management?

Yes. PIM role activations outside business hours, activations from atypical locations, and role assignments that bypass PIM eligibility (direct permanent assignment) are all covered. PIM audit logs must be configured to flow to your Log Analytics workspace.

How does ManySignal handle Microsoft 365 Defender and Entra ID signal overlap?

ManySignal deduplicates Entra ID signals that are also surfaced in Microsoft 365 Defender incidents. When the same event appears in both sources, ManySignal merges the signals into a single alert with full context from both platforms, preventing double-alerting while preserving all available evidence.

Detect Entra ID identity threats before attackers establish M365 persistence

61 detection rules for Microsoft Entra ID with Identity Protection integration, PIM monitoring, and OAuth consent phishing coverage.