M365 Group Creation with Phishing Lure Display Names
Detects the addition of users to specific high-value or sensitive groups in Microsoft Entra ID (Azure AD), which could indicate potential unauthorized privilege escalation or persistence attempts by an attacker.
Microsoft Sentinel (KQL)

