Azure Sign-in Logs: MFA Denied Based on Authentication Requirement

Flags Azure sign-ins requiring MFA where the status indicates "MFA Denied."

FreeReviewedSigma · Medium · v5
Product
azure
Service
signinlogs
Author
AlertIQ (SigmaHQ), DRL 1.1
Published
2022-03-24
Updated
2026-07-31

ATT&CK techniques

Initial Access → Cred Access
  1. Recon

  2. Resource Dev

  3. Execution

  4. Discovery

  5. Lateral Movement

  6. Collection

  7. C2

  8. Exfiltration

  9. Impact

What it detects

This rule flags Azure sign-in events where the authentication requirement is multi-factor authentication and the outcome includes the text "MFA Denied." Denying the MFA prompt can indicate an attacker who already has the account password or a user accidentally clicking deny, so it helps surface suspicious authentication attempts. It relies on telemetry from Azure sign-in logs, matching on MFA requirement and the "MFA Denied" status text.

Related detections9 linkedT1110 — drag to rearrange
Azure Sign-in Log MFA Interrupted via Strong Auth Failures
Bitbucket audit: User login failed authentication events
Azure Sign-in Success with Legacy Client User-Agent Indicators (MFA Bypass Suspicion)
Azure AD Sign-ins Using Legacy Authentication Client Applications
Azure Sign-in Logs: Conditional Access Blocked Sign-in Failures (ResultType 53003)
Azure Sign-in Logs: Conditional Access Blocks User Token Issuance (ResultType 53003)
Suspicious Google Cloud Function Create or Update Triggering Build
Malicious SQL Server - Brutforce Enumeration with Non Existing Users - Login (via application)
Malicious Brutforce Enumeration with Non Existing Users - Login (via security)
Azure Sign-in Logs: MFA Denied Based on Authentication Requirement
Pivot detection · T1110 · 9 related

Changelog

v5
  1. v5
    Candidate ingested via manual entry.2026-07-31
  2. v4
    Candidate ingested via manual entry.2026-07-31
  3. v3
    Candidate ingested via manual entry.2026-07-31
  4. v2
    Candidate ingested via manual entry.2026-07-31
  5. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.