Entra ID coverage
339 Entra ID detection rules across 5 vendors. 158 targeting AuditLogs, 185 targeting SigninLogs. Within each table the groups are separated by how the rule was attributed. 146 rules mapped to an audit Category from the OperationName they filter (resolved exactly, by dash/whitespace normalization, or by a unanimous contains-match) or from a literal Category clause. 12 rules that read AuditLogs but resolve to no audit Category: an OperationName not in the published activity reference, or an IdentityInfo / behavioral rule that names no operation. See the sign-in telemetry reference for the ResultType codes and signal fields the groups below key on. 73 rules that filter a ResultType code (AADSTS) or an outcome field, bucketed by the result. 77 rules that key on a sign-in signal field (risk, target application, authentication requirement, Conditional Access status, or client app) rather than a result code. 66 rules that match across all sign-ins with a behavioral filter (location, IP address, volume) and name no result code or signal field.AuditLogs
Attributed to an audit Category
Administrative 1 rule
AdministrativeUnit 1 rule
ApplicationManagement 40 rules
AzureRBACRoleManagementElevateAccess 2 rules
CrossTenantAccessSettings 6 rules
Device 9 rules
DirectoryManagement 9 rules
GroupManagement 4 rules
KeyManagement 1 rule
Policy 14 rules
RoleManagement 34 rules
UserManagement 31 rules
Not attributed to a Category
(unattributed) 12 rules
SigninLogs
Attributed to a sign-in result
Success 50 rules
Failed-sign-in 9 rules
Invalid-credentials 7 rules
Account-locked 2 rules
Password-expired 2 rules
Disabled 5 rules
MFA-challenged 7 rules
Blocked-by-CA 3 rules
Other 8 rules
Attributed to a sign-in signal, not a result
Identity Protection (risk) 33 rules
Target application 33 rules
Authentication requirement 13 rules
Conditional Access status 3 rules
Client app (legacy authentication) 2 rules
Not attributed to a result or signal
All sign-ins (no result or risk filter) 66 rules