Sigma Rule Library

Users Authenticating To Other Azure AD Tenants

Detect when users in your Azure AD tenant are authenticating to other Azure AD Tenants.

View on GitHubOpen raw file

Detection logic

selection

resultType: 0
homeTenantId|expand: "%HomeTenantID%"

filter_main_hometenantid

resourceTenantId|contains|expand: "%HomeTenantID%"

Condition

selection and not 1 of filter_main_*

Raw YAML

title: Users Authenticating To Other Azure AD Tenants
id: 5f521e4b-0105-4b72-845b-2198a54487b9
status: test
description: Detect when users in your Azure AD tenant are authenticating to other Azure AD Tenants.
references:
    - https://learn.microsoft.com/en-gb/entra/architecture/security-operations-user-accounts#monitoring-external-user-sign-ins
author: MikeDuddington, '@dudders1'
date: 2022-06-30
modified: 2026-05-08
tags:
    - attack.privilege-escalation
    - attack.persistence
    - attack.initial-access
    - attack.stealth
    - attack.t1078.004
logsource:
    product: azure
    service: signinlogs
detection:
    selection:
        resultType: 0
        homeTenantId|expand: '%HomeTenantID%'
    filter_main_hometenantid:
        resourceTenantId|contains|expand: '%HomeTenantID%'
    condition: selection and not 1 of filter_main_*
falsepositives:
    - Unlikely
level: medium

False positives

  • Unlikely

References

Similar rules