Azure AD LeakedCredentials Risk Event Indicates User Credential Exposure
Alerts on Azure AD risk events indicating user credentials were leaked (riskEventType: leakedCredentials).
FreeReviewedSigma · High · v5
- Product
- azure
- Service
- riskdetection
- Author
- Mark Morowczynski '@markmorow', Gloria Lee, '@gleeiamglo' (SigmaHQ), DRL 1.1
- Published
- 2023-09-03
- Updated
- 2026-07-31
ATT&CK techniques
ReconResource Dev
Initial Access
Execution
Persistence
Priv Esc
Defense Evasion
Cred Access
Discovery
Lateral Movement
Collection
C2
Exfiltration
Impact
What it detects
Identifies Azure AD risk detections where a risk event type is marked as leaked credentials for a user account. This matters because stolen or exposed valid credentials enable account takeover and subsequent unauthorized access. The rule relies on Azure risk telemetry fields that record the risk event type as leakedCredentials.
Reporting behind it
- learn.microsoft.comhttps://learn.microsoft.com/en-us/entra/id-protection/concept-identity-protection-risks#leaked-credentials
- learn.microsoft.comhttps://learn.microsoft.com/en-us/entra/architecture/security-operations-user-accounts#unusual-sign-ins
- github.comhttps://github.com/SigmaHQ/sigma/blob/master/rules/cloud/azure/identity_protection/azure_identity_protection_leaked_credentials.yml
Changelog
v5- v5Candidate ingested via manual entry.2026-07-31
- v4Candidate ingested via manual entry.2026-07-31
- v3Candidate ingested via manual entry.2026-07-31
- v2Candidate ingested via manual entry.2026-07-31
- v1No changelog recorded for this version.2026-07-30
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.
azure-ad-risk-detection-leaked-credentials-event-leakedcredentials-19128e5e
title: Azure AD LeakedCredentials Risk Event Indicates User Credential Exposure
id: 69cf4587-c9f7-47da-972b-18b70baf4ad3
status: test
description: Identifies Azure AD risk detections where a risk event type is marked as leaked credentials for a user account. This matters because stolen or exposed valid credentials enable account takeover and subsequent unauthorized access. The rule relies on Azure risk telemetry fields that record the risk event type as leakedCredentials.
references:
- https://learn.microsoft.com/en-us/entra/id-protection/concept-identity-protection-risks#leaked-credentials
- https://learn.microsoft.com/en-us/entra/architecture/security-operations-user-accounts#unusual-sign-ins
- https://github.com/SigmaHQ/sigma/blob/master/rules/cloud/azure/identity_protection/azure_identity_protection_leaked_credentials.yml
author: Mark Morowczynski '@markmorow', Gloria Lee, '@gleeiamglo', Huntrule Team
date: 2023-09-03
tags:
- attack.t1589
- attack.reconnaissance
logsource:
product: azure
service: riskdetection
detection:
selection:
riskEventType: leakedCredentials
condition: selection
falsepositives:
- A rare hash collision.
level: high
license: DRL-1.1
related:
- id: 19128e5e-4743-48dc-bd97-52e5775af817
type: derived