Azure AD SSPR Triggered from Atypical Country

This rule detects successful self-service password reset (SSPR) operations performed by users from IP addresses geolocated to a country that does not match their typical sign-in activity over the past 30 days. This behavior may indicate account takeover where an adversary has compromised credentials and is resetting the password to maintain access or gain further persistence.