Azure AD Brute Force Attack Detection

This rule detects potential brute force attacks against Azure AD accounts by identifying users with 10 or more failed sign-in attempts due to invalid credentials within a 5-minute window. It summarizes the failure count and associated IP addresses for each user.