Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊
Identifies successful sign-ins by privileged accounts using legacy clients such as Exchange ActiveSync, IMAP4, POP3, SMTP Auth, MAPI over HTTP, or other legacy clients. These protocols may bypass modern Conditional Access and MFA controls.
| Attribute | Value |
|---|---|
| Type | Hunting Query |
| Solution | Standalone Content |
| ID | 06184800-6d66-46ce-aabd-7e17e9cf3fb0 |
| Tactics | InitialAccess, CredentialAccess |
| Techniques | T1078.004, T1110.003 |
| Required Connectors | MicrosoftThreatProtection, AzureActiveDirectory |
| Source | [View on GitHub](https://github.com/Azure/Azure-Sentinel/blob/master/Hunting Queries/SigninLogs/PrivilegedAccountsUsingLegacyAuthentication.yaml) |
This content item queries data from the following tables:
| Table | Selection Criteria | Transformations | Ingestion API | Lake-Only |
|---|---|---|---|---|
IdentityInfo |
✓ | ✗ | ✓ |
Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊