Risky Sign-in with Device Registration
Last updated on:
In this page
About the rule
Rule Type
Advanced
Rule Description
Detects when there is amedium or high-risk sign-in session in Entra ID followed by a new device registration for the same user
Severity
Trouble
Rule Requirement
Criteria
Action1: actionname = "DETECTION_ACTION_M365_SUCCESSFUL_LOGON" AND (RISK_LEVEL = "high" OR RISK_LEVEL = "medium") Action2: actionname = "null" AND CALLER = Action1.CALLER sequence:Action1 followedby Action2 within 60m select Action1.CALLER,Action1.ERRORCODE,Action1.APPLICATIONNAME,Action1.IPADDRESS,Action1.COUNTRYCODE,Action1.RISK_LEVEL,Action1.RESULT,
Detection
Execution Mode
scheduled
Log Sources
Microsoft 365


