Azure Entra ID Identity Protection Unlikely Travel Risk Events

Alerts on unlikelyTravel risk events tied to geographically distant sign-ins and potential deviation from user travel history.

FreeReviewedSigma · High · v5
Product
azure
Service
riskdetection
Author
Mark Morowczynski '@markmorow', Gloria Lee, '@gleeiamglo' (SigmaHQ), DRL 1.1
Published
2023-09-03
Updated
2026-07-31
title: Azure Entra ID Identity Protection Unlikely Travel Risk Events
id: 3059e7ed-d0fc-422b-9b63-b429f32a12d9
status: test
description: This rule flags identity risk events classified as unlikely travel, indicating sign-ins from geographically distant locations. Such travel patterns can signal account compromise when the location is atypical compared to a user’s prior sign-in behavior. The detection relies on risk event telemetry from Azure Entra ID Identity Protection indicating the event type.
references:
  - https://learn.microsoft.com/en-us/entra/id-protection/concept-identity-protection-risks#atypical-travel
  - https://learn.microsoft.com/en-us/entra/architecture/security-operations-user-accounts#unusual-sign-ins
  - https://github.com/SigmaHQ/sigma/blob/master/rules/cloud/azure/identity_protection/azure_identity_protection_atypical_travel.yml
author: Mark Morowczynski '@markmorow', Gloria Lee, '@gleeiamglo', Huntrule Team
date: 2023-09-03
tags:
  - attack.stealth
  - attack.t1078
  - attack.persistence
  - attack.privilege-escalation
  - attack.initial-access
logsource:
  product: azure
  service: riskdetection
detection:
  selection:
    riskEventType: unlikelyTravel
  condition: selection
falsepositives:
  - We recommend investigating the sessions flagged by this detection in the context of other sign-ins from the user.
level: high
license: DRL-1.1
related:
  - id: 1a41023f-1e70-4026-921a-4d9341a9038e
    type: derived