Successful Azure CLI Sign-In Without MFA
This rule identifies successful sign-in events using the Azure CLI application where multi-factor authentication (MFA) was not enforced. This is a potential indicator of a misconfiguration where sensitive cloud management interfaces are accessible via single-factor authentication, or a sign of an adversary attempting to leverage a less secure authentication pathway.
Microsoft Sentinel (KQL)

