Azure AD Privileged Role Enumeration Detected
Detects high-frequency enumeration of privileged roles or role assignments within Azure AD (Entra ID) by a single user or IP address within a short time window. This activity often precedes more targeted attacks aimed at compromising highly privileged identities.
Microsoft Sentinel (KQL)

