2026 Critical Enterprise Intrusion Chain Detection: MFA-Satisfied Sign-In Without Interactive Authentication Challenge
Detects successful sign-in events in Entra ID where MFA is marked as satisfied, but no interactive MFA challenge (e.g., Push, FIDO2, SMS) was recorded as completed in the authentication details. This behavior, when correlated with a new IP, device, or user-agent relative to a 30-day baseline, is highly indicative of session token replay or AitM (Adversary-in-the-Middle) attacks attempting to bypass MFA requirements.
Microsoft Sentinel (KQL)

