Azure AD Sign-ins Using Legacy Authentication Client Applications

Alerts on Azure sign-ins using legacy protocol client apps (IMAP/POP3/SMTP/EWS/ActiveSync), which may indicate risky authentication usage.

FreeReviewedSigma · High · v5
Product
azure
Service
signinlogs
Author
Yochana Henderson, '@Yochana-H' (SigmaHQ), DRL 1.1
Published
2022-06-17
Updated
2026-07-31

ATT&CK techniques

Initial Access → Cred Access
  1. Recon

  2. Resource Dev

  3. Execution

  4. Cred Access

  5. Discovery

  6. Lateral Movement

  7. Collection

  8. C2

  9. Exfiltration

  10. Impact

What it detects

This rule flags Azure AD sign-in events where authentication is attempted using legacy protocol client types (e.g., IMAP, POP3, MAPI, SMTP, Exchange ActiveSync, and Exchange Web Services). Attackers may use legacy authentication to gain or maintain access and to blend in with non-interactive or older client behaviors. The detection relies on Azure sign-in log telemetry including the sign-in activity type, client application classification, and the presence of a UPN in the event.

Related detections9 linkedT1110 — drag to rearrange
Bitbucket audit: User login failed authentication events
Azure Sign-in Success with Legacy Client User-Agent Indicators (MFA Bypass Suspicion)
Azure Sign-in Logs: Conditional Access Blocked Sign-in Failures (ResultType 53003)
Azure Sign-in Logs: MFA Denied Based on Authentication Requirement
Azure Sign-in Log MFA Interrupted via Strong Auth Failures
Azure Sign-in Logs: Conditional Access Blocks User Token Issuance (ResultType 53003)
Suspicious Google Cloud Function Create or Update Triggering Build
Malicious SQL Server - Brutforce Enumeration with Non Existing Users - Login (via application)
Malicious Brutforce Enumeration with Non Existing Users - Login (via security)
Azure AD Sign-ins Using Legacy Authentication Client Applications
Pivot detection · T1110 · 9 related

Changelog

v5
  1. v5
    Candidate ingested via manual entry.2026-07-31
  2. v4
    Candidate ingested via manual entry.2026-07-31
  3. v3
    Candidate ingested via manual entry.2026-07-31
  4. v2
    Candidate ingested via manual entry.2026-07-31
  5. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.