FIDO2 Removal Followed by Weaker MFA Method Sign-in

This rule detects potential account compromise by identifying scenarios where a user's security information (MFA methods) is modified, deleted, or updated, followed shortly after (within 24 hours) by a successful sign-in using a less secure authentication method (SMS, Voice, OATH, or Mobile App notification) instead of a stronger method like FIDO2 or Passkey.