Azure Audit Logs: Successful Disable Strong Authentication Indicates MFA Disabled

Alerts on successful MFA disable actions in Azure audit logs that could weaken account authentication.

FreeReviewedSigma · Medium · v5
Product
azure
Service
auditlogs
Author
@ionsor (SigmaHQ), DRL 1.1
Published
2022-02-08
Updated
2026-07-31

ATT&CK techniques

Persistence → Cred Access
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Priv Esc

  6. Discovery

  7. Lateral Movement

  8. Collection

  9. C2

  10. Exfiltration

  11. Impact

What it detects

This rule flags successful operations named "Disable Strong Authentication" in Azure audit logs, which corresponds to multi-factor authentication being turned off. Attackers may do this to reduce authentication friction and bypass MFA controls as part of credential access or persistence. It relies on audit log telemetry capturing the operation name and success result for the affected directory user or identity context.

Related detections9 linkedT1556 — drag to rearrange
Suspicious XZ Utils Backdoor Kill-Switch Environment String via process_creation
Suspicious AWS SAML Identity Provider Creation
Suspicious Okta Sign-On Policy Lifecycle Modification
Possible Shadow Credentials Abuse via msDS-KeyCredentialLink Modification
Windows Registry Tampering: DsrmAdminLogonBehavior Value Changes (DSRM)
Azure AD Audit: Trusted Root CA Added for Passwordless Certificate Authentication
Azure AD Audit Logs: Certificate-based authentication enabled via AuthenticationMethodsPolicy update
AWS CloudTrail: AWS Identity Center Identity Provider Configuration Changes
GitHub Audit: High-Risk Security Controls Disabled
Azure Audit Logs: Successful Disable Strong Authentication Indicates MFA Disabled
Pivot detection · T1556 · 9 related

Changelog

v5
  1. v5
    Candidate ingested via manual entry.2026-07-31
  2. v4
    Candidate ingested via manual entry.2026-07-31
  3. v3
    Candidate ingested via manual entry.2026-07-31
  4. v2
    Candidate ingested via manual entry.2026-07-31
  5. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.