TeamFiltration post-compromise VPN probe and staged M365 app recon chain

Detects a sequence of suspicious identity activities indicative of a post-account-takeover pivot. The rule identifies a user profile engaging in corporate VPN SAML SSO probing, triggering a MFA enrollment interrupt in Azure, and subsequently accessing multiple Microsoft 365 applications (Azure Portal, OfficeHome, SharePoint) within a 30-minute window.