Top 2026 2FA & AiTM Detection: Anomalous Device Join Following Risky Sign-In
Detects instances where a user account successfully registers or joins a device to Entra ID (Azure AD) immediately after performing a sign-in operation that was flagged with a medium or high-risk level. This pattern may indicate an adversary is attempting to enroll a malicious device to bypass conditional access policies or establish persistence in the environment using compromised credentials.
Sigma

