AAD Connect Sync Account DCSync Replication Outside Expected Host

Detects instances where an Azure AD Connect or MSOL synchronization account performs directory replication actions (DS-Replication-Get-Changes) from a host or at a time inconsistent with its 14-day established baseline. The rule further correlates these anomalies with Azure Audit logs or AzureActivity entries associated with the identity to identify potential cloud-originated abuse or credential compromise.