Deepfake Social Engineering - MFA Swap Followed by Privileged Action

Detects users who modify their MFA settings (registration/update/delete) and subsequently perform privileged actions (such as adding role members or service principal credentials) within a short timeframe, while simultaneously observed active in communication applications like Teams, Zoom, or Webex. This behavior is indicative of potential account takeover where an adversary modifies authentication methods to gain persistent access, followed by privilege escalation.