Storm-0501 Entra Connect Sync Account Cloud Object Abuse

Detects high frequency administrative modifications, such as user creation/deletion, password resets, or group membership changes, performed by service accounts associated with Azure AD Connect or Microsoft Entra Connect. This behavior may indicate account compromise where a service principal is being abused to perform bulk identity management operations.