Azure Sign-in Log MFA Interrupted via Strong Auth Failures

Identifies Azure sign-ins that fail during strong/MFA authentication, suggesting blocked credential attempts.

FreeReviewedSigma · Medium · v5
Product
azure
Service
signinlogs
Author
AlertIQ (SigmaHQ), DRL 1.1
Published
2021-10-10
Updated
2026-07-31

ATT&CK techniques

Initial Access → Cred Access
  1. Recon

  2. Resource Dev

  3. Execution

  4. Discovery

  5. Lateral Movement

  6. Collection

  7. C2

  8. Exfiltration

  9. Impact

What it detects

This rule identifies Azure sign-in attempts where strong authentication (MFA) was required and the strong authentication request failed. Such events can indicate an attacker has obtained valid credentials but cannot complete the MFA challenge. The detection relies on sign-in log fields matching specific result codes and result descriptions for strong authentication requirement and failure.

Related detections9 linkedT1078.004 — drag to rearrange
Azure Sign-in Logs: MFA Denied Based on Authentication Requirement
Suspicious AWS Console Phishing MFA Relay Endpoints
Bitbucket audit: User login failed authentication events
Azure Sign-in Success with Legacy Client User-Agent Indicators (MFA Bypass Suspicion)
Azure AD Sign-ins Using Legacy Authentication Client Applications
Azure Sign-in Logs: Conditional Access Blocked Sign-in Failures (ResultType 53003)
Azure Sign-in Logs: Conditional Access Blocks User Token Issuance (ResultType 53003)
Suspicious AWS AiTM Phishing Kit Endpoint Access via Proxy
Suspicious AiTM Session Cookie Exfiltration to log_cookie Endpoint
Azure Sign-in Log MFA Interrupted via Strong Auth Failures
Pivot detection · T1078.004 · 9 related

Changelog

v5
  1. v5
    Candidate ingested via manual entry.2026-07-31
  2. v4
    Candidate ingested via manual entry.2026-07-31
  3. v3
    Candidate ingested via manual entry.2026-07-31
  4. v2
    Candidate ingested via manual entry.2026-07-31
  5. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.