Microsoft Entra Password Spray from Single Source

This rule detects potential password spraying activity by monitoring Microsoft Entra sign-in logs for multiple failed authentication attempts originating from the same source IP address targeting ten or more distinct user accounts within a ten-minute time window.