Anomalous B2B Guest Sign-In from New Location Followed by Sensitive Data Access
Detects Entra ID guest (B2B) users performing a sign-in from a previously unseen IP address or country (observed over the last 30 days), followed within a 4-hour window by sensitive file operations in SharePoint, OneDrive, or Teams (e.g., file downloads, exports, or sensitivity label changes). This pattern is indicative of potential account takeover or unauthorized access to sensitive corporate data.
Microsoft Sentinel (KQL)

