Anonymous IP / VPN / TOR Usage
This rule monitors Entra ID Sign-in logs for authentication events flagged by risk detections related to anonymizing infrastructure, such as VPNs, TOR exit nodes, or proxies. It identifies successful logins and aggregate sign-in volume from these IP addresses, flagging successful logins as critical due to the potential for valid account abuse through multi-hop proxy chains.
Microsoft Sentinel (KQL)

