Risky Sign-In During Active Out-of-Office Auto-Reply
This rule detects anomalous or risky sign-in events for user accounts that have recently configured an active out-of-office (OOF) auto-reply. An attacker may leverage a user's known absence to gain access to their email or other corporate resources using compromised credentials, as the user is less likely to notice suspicious account activity while away.
Microsoft Sentinel (KQL)

