Conditional Access Bypass Attempt in Azure AD
Detects high volumes of sign-in failures or instances where Conditional Access policies are not applied, particularly for unregistered devices, indicating potential attempts to bypass security controls or perform brute-force attacks against cloud authentication.
Microsoft Sentinel (KQL)

