New Federated Domain Added Without Prior Verification (Storm-0558 style)

Detects the addition of a new federated domain or a modification to an existing domain's authentication settings to Federated, where the domain was not previously verified within a standard verification window. This technique is often used by adversaries to establish persistence and perform self-issued token forgery (e.g., SAML/JWT) by trusting an attacker-controlled identity provider.