Suspicious Azure AD Sign-In from Unusual Location

This rule detects suspicious Azure AD sign-in activity where a user successfully signs in from multiple unusual cities within a 24-hour period. It specifically looks for sign-ins that are not from a trusted network and are not from a compliant device, aggregating successful sign-ins by UserPrincipalName and IpAddress, and flagging if there are 5 or more distinct cities.