Federation Trust Settings Modified on Verified Domain (Golden SAML)

This rule detects modifications to domain federation settings in Azure Active Directory (Microsoft Entra ID), specifically when a domain is set to federated or when critical federation URLs (IssuerUri, ActiveLogOnUri, MetadataExchangeUri) are changed. Such modifications can indicate an attempt to establish malicious domain federation, allowing an adversary to authenticate as any user within the tenant.