Azure Entra ID sign-in risk: new country (riskEventType newCountry)

Flags Azure AD risk events where a sign-in is assessed as originating from a new country for the user.

FreeReviewedSigma · High · v5
Product
azure
Service
riskdetection
Author
Mark Morowczynski '@markmorow', Gloria Lee, '@gleeiamglo' (SigmaHQ), DRL 1.1
Published
2023-09-03
Updated
2026-07-31
title: "Azure Entra ID sign-in risk: new country (riskEventType newCountry)"
id: c4a92791-a2d7-46bc-a89d-59cff116b7ed
status: test
description: This rule flags Azure Entra ID risk events where riskEventType is set to newCountry, indicating a sign-in from a country not previously seen for the account. Attackers may use travel or anonymization to evade baseline location-based monitoring, making these anomalies valuable for early investigation. The detection relies on risk telemetry from the Entra risk detection service that records the new-country risk event type.
references:
  - https://learn.microsoft.com/en-us/entra/id-protection/concept-identity-protection-risks#new-country
  - https://learn.microsoft.com/en-us/entra/architecture/security-operations-user-accounts#unusual-sign-ins
  - https://github.com/SigmaHQ/sigma/blob/master/rules/cloud/azure/identity_protection/azure_identity_protection_new_coutry_region.yml
author: Mark Morowczynski '@markmorow', Gloria Lee, '@gleeiamglo', Huntrule Team
date: 2023-09-03
tags:
  - attack.stealth
  - attack.t1078
  - attack.persistence
  - attack.privilege-escalation
  - attack.initial-access
logsource:
  product: azure
  service: riskdetection
detection:
  selection:
    riskEventType: newCountry
  condition: selection
falsepositives:
  - We recommend investigating the sessions flagged by this detection in the context of other sign-ins from the user.
level: high
license: DRL-1.1
related:
  - id: adf9f4d2-559e-4f5c-95be-c28dff0b1476
    type: derived