Impossible Travel: Rapid Sign-Ins from Distant Locations
Detects successful user sign-ins from geographically distant locations occurring within a timeframe that is physically impossible to traverse (implied speed > 900 km/h). The rule further filters for scenarios where the device used for authentication appears non-compliant or uses an unrecognized method, potentially indicating an attacker utilizing stolen credentials and bypassing MFA.
Microsoft Sentinel (KQL)

