Azure AD coverage

336 Azure AD detection rules across 5 vendors. 165 targeting AuditLogs, 174 targeting SigninLogs. Each AuditLogs OperationName maps to a catalog entry under the Microsoft 365, Entra ID & Azure catalog.

AuditLogs

Administrative 3 rules
ApplicationManagement 12 rules
AzureRBACRoleManagementElevateAccess 1 rule
KeyManagement 1 rule
Policy 2 rules
RoleManagement 17 rules
UserManagement 10 rules
(unattributed) 121 rules

SigninLogs

Success 20 rules
MFA-challenged 8 rules
Blocked-by-CA 2 rules
Account-locked 4 rules
Invalid-credentials 9 rules
Disabled 5 rules
Other 9 rules
(unattributed) 131 rules