Domain Federation Trust Settings Modified (Golden SAML Risk)
Detects changes to federation settings on an Entra ID domain, including modifications to IssuerUri, ActiveLogOnUri, MetadataExchangeUri, or SigningCertificate, as well as transitions between Managed and Federated authentication types. Such changes can facilitate 'Golden SAML' attacks by allowing an adversary to forge authentication tokens for the tenant.
Microsoft Sentinel (KQL)

