Azure Audit Logs: Successful Disable Strong Authentication (MFA) User Action
Alerts on successful MFA disable actions in Azure audit logs that could weaken account authentication.
FreeUnreviewedSigmamediumv1
azure-audit-logs-successful-disable-strong-authentication-mfa-user-action-7ea78478
title: "Azure Audit Logs: Successful Disable Strong Authentication (MFA) User Action"
id: bc162554-8cc9-4350-9d3f-da037f0ebd01
status: test
description: This rule flags successful instances of the operation "Disable Strong Authentication," which indicates multi-factor authentication (MFA) has been turned off for a user. Attackers may disable MFA to weaken authentication controls and improve their ability to access accounts. It relies on Azure audit log events from the auditlogs service where the operation name matches and the result is recorded as success.
references:
- https://learn.microsoft.com/en-us/azure/active-directory/authentication/howto-mfa-userstates
- https://learn.microsoft.com/en-us/entra/identity/monitoring-health/reference-audit-activities#core-directory
- https://research.splunk.com/cloud/482dd42a-acfa-486b-a0bb-d6fcda27318e/
- https://analyticsrules.exchange/analyticrules/65c78944-930b-4cae-bd79-c3664ae30ba7/
- https://www.elastic.co/docs/reference/security/prebuilt-rules/rules/integrations/azure/persistence_entra_id_mfa_disabled_for_user
- https://github.com/SigmaHQ/sigma/blob/master/rules/cloud/azure/audit_logs/azure_mfa_disabled.yml
author: "@ionsor, Huntrule Team"
date: 2022-02-08
modified: 2026-04-30
tags:
- attack.credential-access
- attack.persistence
- attack.defense-impairment
- attack.t1556
logsource:
product: azure
service: auditlogs
detection:
selection:
operationName: Disable Strong Authentication
properties.result: success
condition: selection
falsepositives:
- Authorized modification by administrators
level: medium
license: DRL-1.1
related:
- id: 7ea78478-a4f9-42a6-9dcd-f861816122bf
type: derived
What it detects
This rule flags successful instances of the operation "Disable Strong Authentication," which indicates multi-factor authentication (MFA) has been turned off for a user. Attackers may disable MFA to weaken authentication controls and improve their ability to access accounts. It relies on Azure audit log events from the auditlogs service where the operation name matches and the result is recorded as success.
Known false positives
- Authorized modification by administrators
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.