Privileged admin session followed by auth infrastructure change

Detects when a user account assigned to high-privileged roles (Global Administrator or Authentication Policy Administrator) performs sensitive operations such as application registration, service principal creation, or modifications to authentication policies within a short timeframe (4 hours) of a successful sign-in. This activity is often associated with the initial setup phases of MFA bypass or persistence techniques in Entra ID.