Disabled MFA to Bypass Authentication Mechanisms

 Original Source: [Sigma source]
Title: Disabled MFA to Bypass Authentication Mechanisms
Status: test
Description:Detection for when multi factor authentication has been disabled, which might indicate a malicious activity to bypass authentication mechanisms.
References:
  -https://learn.microsoft.com/en-us/azure/active-directory/authentication/howto-mfa-userstates
  -https://learn.microsoft.com/en-us/entra/identity/monitoring-health/reference-audit-activities#core-directory
  -https://research.splunk.com/cloud/482dd42a-acfa-486b-a0bb-d6fcda27318e/
  -https://analyticsrules.exchange/analyticrules/65c78944-930b-4cae-bd79-c3664ae30ba7/
  -https://www.elastic.co/docs/reference/security/prebuilt-rules/rules/integrations/azure/persistence_entra_id_mfa_disabled_for_user
Author: @ionsor
Date: 2022-02-08
modified:2026-04-30
Tags:
  • -'attack.credential-access'
  • -'attack.persistence'
  • -'attack.defense-impairment'
  • -'attack.t1556'
Logsource:
  • product: azure
  • service: auditlogs
Detection:
  selection:
    operationName: 'Disable Strong Authentication'
    properties.result: 'success'
  condition:selection
Falsepositives:
  -Authorized modification by administrators
Level: medium