Most Important Detection 2026: Golden SAML ADFS Token Forgery Attack

Detects potential Golden SAML activity by correlating Azure AD SAML sign-in events for privileged accounts with a lack of corresponding server-side ADFS authentication logs, unusual SAML issuer URIs, lack of on-premises authentication logs, or evidence of direct access to ADFS token-signing certificate private key material.