Entra ID PIM Role Activation Surge by Single User
Detects when a single user account performs 3 or more Privileged Identity Management (PIM) role activations within a 30-minute window. This behavior may indicate an attacker who has compromised a privileged account and is rapidly assuming multiple roles to perform lateral movement or privilege escalation.
Microsoft Sentinel (KQL)

