You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Rules: First Seen ASN Associated with User for a Successful Azure AD Sign In Event
Description
This rule will trigger when a new ASN value is associated with a successful Entra ID sign in event for a particular username since the baseline period. This may be suspicious activity as a users IP address may change periodically, but typically users authenticate from a set of ASNs (one ASN value for their home network, another ASN value for their mobile device ) – a sign in with a new ASN not seen since the baseline period could be indicative of credential theft. Look at other events occurring for the user in question for the same time period to ascertain whether access was malicious or benign.
Additional Details
Detail
Value
Type
First Seen
Category
Initial Access
Apply Risk to Entities
user_username
Signal Name
First Seen ASN Associated with User for a Successful Azure AD Sign In Event
Summary Expression
{{user_username}} has sucessfully signed into an Azure resource with a first seen ASN of {{device_ip_asnOrg}} since the baseline period.