2026 Critical Enterprise Intrusion Chain Detection: Legacy Auth Protocol Bypass on Compromised Identity from New Source IP

Detects successful user authentication to Microsoft Entra ID or Exchange Online using legacy authentication protocols (e.g., IMAP, POP3, SMTP AUTH, Exchange ActiveSync) that bypass modern MFA enforcement. The rule specifically alerts when these legacy sign-ins originate from a source IP address not previously associated with that specific user account, indicating potential credential abuse.