Azure AD Brute Force Attack Detection
This rule detects potential brute force attacks against Azure AD accounts by identifying users with 10 or more failed sign-in attempts due to invalid credentials within a 5-minute window. It summarizes the failure count and associated IP addresses for each user.
Microsoft Sentinel (KQL)

