Potential Conditional Access bypass
This use case detects a potential bypass of a conditional access policy. Most likely bypass would be your MFA policy, bypassing multi factor authentication via some sort of vulnerability or misconfiguration.
Microsoft Sentinel (KQL)

