Microsoft 365 Audit: Disabling Strong Authentication (MFA)

Flags Microsoft 365 audit events indicating MFA/strong authentication was disabled.

FreeReviewedSigma · High · v4
Product
m365
Service
audit
Author
Splunk Threat Research Team (original rule), Harjot Singh @cyb3rjy0t (sigma rule) (SigmaHQ), DRL 1.1
Published
2023-09-18
Updated
2026-07-31

ATT&CK techniques

Persistence → Cred Access
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Priv Esc

  6. Discovery

  7. Lateral Movement

  8. Collection

  9. C2

  10. Exfiltration

  11. Impact

What it detects

This rule matches Microsoft 365 audit events where the operation contains 'Disable Strong Authentication,' indicating MFA/strong authentication has been turned off. Disabling MFA weakens account protections and can enable attackers to maintain access with stolen credentials. It relies on Microsoft 365 audit/service telemetry capturing the specific operation string.

Related detections3 linkedT1556.006 — drag to rearrange
Uncommon Security Info Registration Following AiTM Session Theft (via azure)
Azure AD Sign-in Success Without MFA (Single-Factor Authentication)
Okta MFA Deactivation or Full Factor Reset Event Detection
Microsoft 365 Audit: Disabling Strong Authentication (MFA)
Pivot detection · T1556.006 · 3 related

Changelog

v4
  1. v4
    Candidate ingested via manual entry.2026-07-31
  2. v3
    Candidate ingested via manual entry.2026-07-31
  3. v2
    Candidate ingested via manual entry.2026-07-31
  4. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.