Azure AD SSPR Triggered from Atypical Country
This rule detects successful self-service password reset (SSPR) operations performed by users from IP addresses geolocated to a country that does not match their typical sign-in activity over the past 30 days. This behavior may indicate account takeover where an adversary has compromised credentials and is resetting the password to maintain access or gain further persistence.
Microsoft Sentinel (KQL)

