MFA enrollment interrupt after spray-IP pivot to Azure Portal

Detects a suspected account takeover pattern where an Azure AD account logs into the Azure Portal shortly after experiencing failed authentication attempts from the same IP address. The detection correlates password spraying or VPN probing activity (multiple failed logins against different users from a single IP) with subsequent successful or near-successful logins (MFA enrollment interrupts) on the Azure Portal, signaling potential post-compromise activity.