MFA Bypass via Potential Session Hijacking or Rapid Impossible Travel
Detects instances where a user successfully authenticates using Multi-Factor Authentication (MFA) from one location, followed by a Single-Factor Authentication (SFA) logon from a different location within a 10-minute window. This behavior is indicative of potential session hijacking or session cookie theft where an attacker reuses an authenticated session or manipulates the authentication flow to bypass MFA requirements.
Microsoft Sentinel (KQL)

