MFA Push Bombing Attack Detected in Azure AD
Detects MFA push bombing attacks by identifying a high volume of MFA challenge failures (errorCode 500121) associated with a single user account within a short time window. This activity often indicates an attempt to overwhelm or fatigue a user into inadvertently approving an MFA request.
Microsoft Sentinel (KQL)

