Correlate Unfamiliar sign-in properties & atypical travel alerts

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Content Index


The combination of an Unfamiliar sign-in properties alert and an Atypical travel alert about the same user within a +10m or -10m window is considered a high severity incident.

Attribute Value
Type Analytic Rule
Solution Microsoft Entra ID Protection
ID a3df4a32-4805-4c6d-8699-f3c888af2f67
Severity High
Status Available
Kind Scheduled
Tactics InitialAccess
Techniques T1078
Required Connectors AzureActiveDirectoryIdentityProtection, BehaviorAnalytics
Source View on GitHub

Tables Used

This content item queries data from the following tables:

Table Transformations Ingestion API Lake-Only
IdentityInfo ?
SecurityAlert ?

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Analytic Rules · Back to Microsoft Entra ID Protection