Suspicious Azure AD Password Reset Activity
Detects suspicious activity involving multiple password resets for different users initiated by a single user within a one-hour timeframe in Azure AD. This could indicate an attacker attempting to gain control over multiple accounts.
Microsoft Sentinel (KQL)

