Entra ID coverage

339 Entra ID detection rules across 5 vendors. 158 targeting AuditLogs, 185 targeting SigninLogs. Within each table the groups are separated by how the rule was attributed.

AuditLogs

Attributed to an audit Category

146 rules mapped to an audit Category from the OperationName they filter (resolved exactly, by dash/whitespace normalization, or by a unanimous contains-match) or from a literal Category clause.

Administrative 1 rule
AdministrativeUnit 1 rule
ApplicationManagement 40 rules
AzureRBACRoleManagementElevateAccess 2 rules
CrossTenantAccessSettings 6 rules
Device 9 rules
DirectoryManagement 9 rules
GroupManagement 4 rules
KeyManagement 1 rule
Policy 14 rules
RoleManagement 34 rules
UserManagement 31 rules

Not attributed to a Category

12 rules that read AuditLogs but resolve to no audit Category: an OperationName not in the published activity reference, or an IdentityInfo / behavioral rule that names no operation.

(unattributed) 12 rules

SigninLogs

See the sign-in telemetry reference for the ResultType codes and signal fields the groups below key on.

Attributed to a sign-in result

73 rules that filter a ResultType code (AADSTS) or an outcome field, bucketed by the result.

Success 50 rules
Failed-sign-in 9 rules
Invalid-credentials 7 rules
Account-locked 2 rules
Password-expired 2 rules
Disabled 5 rules
MFA-challenged 7 rules
Blocked-by-CA 3 rules
Other 8 rules

Attributed to a sign-in signal, not a result

77 rules that key on a sign-in signal field (risk, target application, authentication requirement, Conditional Access status, or client app) rather than a result code.

Identity Protection (risk) 33 rules
Target application 33 rules
Authentication requirement 13 rules
Conditional Access status 3 rules
Client app (legacy authentication) 2 rules

Not attributed to a result or signal

66 rules that match across all sign-ins with a behavioral filter (location, IP address, volume) and name no result code or signal field.

All sign-ins (no result or risk filter) 66 rules