Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊
Identifies successful sign-ins by accounts with directory or PIM roles when Conditional Access did not report success, including empty, not applied, not enabled, or failure states. Review these events for missing policy coverage and MFA enforcement.
| Attribute | Value |
|---|---|
| Type | Hunting Query |
| Solution | Standalone Content |
| ID | 87245d60-eefb-42dd-9748-cd1949c83a5e |
| Tactics | InitialAccess |
| Techniques | T1078.004 |
| Required Connectors | MicrosoftThreatProtection, AzureActiveDirectory |
| Source | [View on GitHub](https://github.com/Azure/Azure-Sentinel/blob/master/Hunting Queries/SigninLogs/PrivilegedSigninsWithoutConditionalAccessSuccess.yaml) |
This content item queries data from the following tables:
| Table | Selection Criteria | Transformations | Ingestion API | Lake-Only |
|---|---|---|---|---|
IdentityInfo |
✓ | ✗ | ✓ |
Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊