Azure AD Audit: Update User Risk and MFA Registration Policy

Flags Azure AD audit events showing updates to user risk and MFA registration policy.

FreeReviewedSigma · High · v5
Product
azure
Service
auditlogs
Author
Harjot Singh (@cyb3rjy0t) (SigmaHQ), DRL 1.1
Published
2024-08-13
Updated
2026-07-31

What it detects

This rule matches audit log events where the AAD Management UX updates the user risk and MFA registration policy. Changes to these settings can allow an attacker to weaken MFA enforcement or security thresholds, enabling follow-on access attempts and persistence. It relies on Azure audit log fields indicating the logged-by service, category, and the specific policy update operation name.

Changelog

v5
  1. v5
    Candidate ingested via manual entry.2026-07-31
  2. v4
    Candidate ingested via manual entry.2026-07-31
  3. v3
    Candidate ingested via manual entry.2026-07-31
  4. v2
    Candidate ingested via manual entry.2026-07-31
  5. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.