Azure Audit Logs: Successful Disable Strong Authentication (MFA) User Action

Alerts on successful MFA disable actions in Azure audit logs that could weaken account authentication.

FreeUnreviewedSigmamediumv1
title: "Azure Audit Logs: Successful Disable Strong Authentication (MFA) User Action"
id: bc162554-8cc9-4350-9d3f-da037f0ebd01
status: test
description: This rule flags successful instances of the operation "Disable Strong Authentication," which indicates multi-factor authentication (MFA) has been turned off for a user. Attackers may disable MFA to weaken authentication controls and improve their ability to access accounts. It relies on Azure audit log events from the auditlogs service where the operation name matches and the result is recorded as success.
references:
  - https://learn.microsoft.com/en-us/azure/active-directory/authentication/howto-mfa-userstates
  - https://learn.microsoft.com/en-us/entra/identity/monitoring-health/reference-audit-activities#core-directory
  - https://research.splunk.com/cloud/482dd42a-acfa-486b-a0bb-d6fcda27318e/
  - https://analyticsrules.exchange/analyticrules/65c78944-930b-4cae-bd79-c3664ae30ba7/
  - https://www.elastic.co/docs/reference/security/prebuilt-rules/rules/integrations/azure/persistence_entra_id_mfa_disabled_for_user
  - https://github.com/SigmaHQ/sigma/blob/master/rules/cloud/azure/audit_logs/azure_mfa_disabled.yml
author: "@ionsor, Huntrule Team"
date: 2022-02-08
modified: 2026-04-30
tags:
  - attack.credential-access
  - attack.persistence
  - attack.defense-impairment
  - attack.t1556
logsource:
  product: azure
  service: auditlogs
detection:
  selection:
    operationName: Disable Strong Authentication
    properties.result: success
  condition: selection
falsepositives:
  - Authorized modification by administrators
level: medium
license: DRL-1.1
related:
  - id: 7ea78478-a4f9-42a6-9dcd-f861816122bf
    type: derived

What it detects

This rule flags successful instances of the operation "Disable Strong Authentication," which indicates multi-factor authentication (MFA) has been turned off for a user. Attackers may disable MFA to weaken authentication controls and improve their ability to access accounts. It relies on Azure audit log events from the auditlogs service where the operation name matches and the result is recorded as success.

Known false positives

  • Authorized modification by administrators

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.