Azure AD Sign-in Success Without MFA (Single-Factor Authentication)

Alerts on successful Azure AD sign-ins where MFA was not required and only single-factor authentication was used.

FreeReviewedSigma · Low · v5
Product
azure
Service
signinlogs
Author
MikeDuddington, '@dudders1' (SigmaHQ), DRL 1.1
Published
2022-07-27
Updated
2026-07-31

ATT&CK techniques

Initial Access → Cred Access
  1. Recon

  2. Resource Dev

  3. Execution

  4. Discovery

  5. Lateral Movement

  6. Collection

  7. C2

  8. Exfiltration

  9. Impact

What it detects

This rule identifies successful Azure AD sign-ins where the authentication requirement is single-factor authentication, indicating MFA was not required for the attempt. Attackers may use weaker authentication paths to reduce friction and maintain stealth, especially if conditional access or policies are misconfigured or bypassed. Detection relies on Azure sign-in log fields indicating successful status and the reported authentication requirement.

Related detections9 linkedT1078.004 — drag to rearrange
Suspicious Google Cloud Function Create or Update Triggering Build
Possible Credential Stuffing Blocked by Conditional Access in Microsoft 365
Suspicious SES Account Sending Enablement and Identity Verification via CloudTrail
Possible Stolen AWS Credential Validation via STS GetCallerIdentity
Suspicious AWS Federated Console Login From Programmatic Credentials
Uncommon Security Info Registration Following AiTM Session Theft (via azure)
Suspicious M365 Legacy Authentication via BAV2ROPC Client via m365
Suspicious STS AssumeRole With Exfil Session Name via CloudTrail (via cloudtrail)
Suspicious AWS Console Login Without MFA
Azure AD Sign-in Success Without MFA (Single-Factor Authentication)
Pivot detection · T1078.004 · 9 related

Changelog

v5
  1. v5
    Candidate ingested via manual entry.2026-07-31
  2. v4
    Candidate ingested via manual entry.2026-07-31
  3. v3
    Candidate ingested via manual entry.2026-07-31
  4. v2
    Candidate ingested via manual entry.2026-07-31
  5. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.