2026 Critical Cloud Identity Detection: Federated Domain or Identity Provider Trust Configuration Modification

Detects modifications to federated domain authentication, identity provider trusts, or federation settings in cloud environments (e.g., Entra ID, Okta). Unauthorized changes to these configurations can be used to establish persistence, enable SAML token forgery, or bypass Multi-Factor Authentication (MFA).