Top 2026 2FA & AiTM Detection: New MFA Method Registered Immediately After Risky Sign-In

Detects the registration or modification of multi-factor authentication (MFA) security information in Entra ID or Okta that occurs within 15 minutes of a sign-in event flagged as risky. This behavioral pattern is a common indicator of persistence being established by an attacker after performing an adversary-in-the-middle (AiTM) attack, where they leverage a stolen session to register their own MFA factors to maintain long-term access.