New MFA/Authenticator Method Registered Following Anomalous Sign-In

Detects modifications to Active Directory user accounts (Event IDs 4720, 4738) that coincide with suspicious MFA registration indicators—such as increased device counts, software token activations, or default device/token placeholders—within one hour of a successful user authentication event. This behavior is indicative of potential account takeover or persistence activities involving MFA manipulation.