Azure AD Federation Trust Modification (T1484.002)
Detects modifications to Azure AD domain federation settings or authentication methods that could indicate attempts to establish persistent access or bypass authentication controls (e.g., golden SAML attacks, domain-level backdoors). The rule monitors for successful operations related to domain federation, authentication changes, and domain management, excluding known administrative actions from internal Microsoft domains.
Microsoft Sentinel (KQL)

