Risky Sign-in with Device Registration

Last updated on:

About the rule

Rule Type

Advanced

Rule Description

Detects when there is amedium or high-risk sign-in session in Entra ID followed by a new device registration for the same user

Severity

Trouble

Rule Requirement

Criteria

Action1: actionname = "DETECTION_ACTION_M365_SUCCESSFUL_LOGON" AND (RISK_LEVEL = "high" OR RISK_LEVEL = "medium") Action2: actionname = "null" AND CALLER = Action1.CALLER sequence:Action1 followedby Action2 within 60m select Action1.CALLER,Action1.ERRORCODE,Action1.APPLICATIONNAME,Action1.IPADDRESS,Action1.COUNTRYCODE,Action1.RISK_LEVEL,Action1.RESULT,

Detection

Execution Mode

scheduled

Log Sources

Microsoft 365