Risky Sign-In During Active Out-of-Office Auto-Reply

This rule detects anomalous or risky sign-in events for user accounts that have recently configured an active out-of-office (OOF) auto-reply. An attacker may leverage a user's known absence to gain access to their email or other corporate resources using compromised credentials, as the user is less likely to notice suspicious account activity while away.