Password Spray Attack Against Azure Active Directory
This rule detects potential password spraying attacks against Azure Active Directory by identifying sign-in failures from a single source IP address targeting a large number of distinct user accounts within a short time window. It specifically filters for common authentication failure codes and checks for low volume of failures per account, which is characteristic of password spraying behavior.
Microsoft Sentinel (KQL)

