2026 Critical Enterprise Intrusion Chain Detection: Privileged Directory Role Granted Shortly After Risky Sign-In
This rule detects when a user is assigned a highly privileged role in Azure AD (e.g., Global Administrator, Security Administrator) shortly after that user has performed a sign-in event flagged as risky. This behavior is a strong indicator of account takeover or malicious privilege escalation within the cloud environment.
Cortex XDR

