Sign-ins via External MFA Provider Within Key-Rollover Grace Window
This rule identifies sign-in events using an External Authentication Method (EAM) that occur within the 2-day cache window immediately following a certificate or key credential update for an application or service principal in Entra ID. This detection highlights a timeframe where an attacker potentially possessing a compromised old signing key could use it to forge tokens before the Entra cache refreshes.
Microsoft Sentinel (KQL)

