Azure Entra ID Riskdetection: Anonymous IP Address sign-in risk events

Detects Azure sign-in risk events labeled as anonymized/anonymous IP addresses.

FreeReviewedSigma · High · v5
Product
azure
Service
riskdetection
Author
Gloria Lee, '@gleeiamglo' (SigmaHQ), DRL 1.1
Published
2023-08-22
Updated
2026-07-31

ATT&CK techniques

Cred Access
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Discovery

  9. Lateral Movement

  10. Collection

  11. C2

  12. Exfiltration

  13. Impact

What it detects

This rule flags sign-in risk events where the risk event type indicates an anonymized/anonymous IP address, such as activity attributed to an anonymous browser or VPN. Attackers may use anonymity services to reduce traceability and increase the chances of successful credential access. It relies on Azure Entra ID risk detection telemetry, specifically the risk event type value recorded for each risk event.

Related detections9 linkedT1528 — drag to rearrange
Malicious OAuth Application Granted Full Mailbox and EWS Permissions (via m365)
Suspicious GAM OAuth Token Enumeration via Process Creation
Suspicious Entra ID Device Code Flow Authentication
Suspicious Delegated Permission Grant to Entra Agent Access Scope via Azure Audit Logs
Suspicious OAuth Application Registration with Localhost Reply URL via Azure AD
Malicious PRT Token Forging via AADInternals (via ps_script)
Possible VMware Workspace ONE SSRF via instanceHealth hostName At-Injection (via webserver)
Suspicious Entra Device Code Authentication with Office Client and Automated User Agent
Suspicious Access to Kubernetes Service Account Token via Curl or Wget (via process_creation)
Azure Entra ID Riskdetection: Anonymous IP Address sign-in risk events
Pivot detection · T1528 · 9 related

Changelog

v5
  1. v5
    Candidate ingested via manual entry.2026-07-31
  2. v4
    Candidate ingested via manual entry.2026-07-31
  3. v3
    Candidate ingested via manual entry.2026-07-31
  4. v2
    Candidate ingested via manual entry.2026-07-31
  5. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.