TrustSink: CA Policy Retargeted After Auth Change

This rule detects scenarios where a user account modifies Conditional Access (CA) policies (specifically targeting user or group inclusion/exclusion settings) within one hour of that same user account modifying authentication method policies. This pattern is potentially indicative of an adversary weakening security controls by adjusting authentication requirements and subsequently tampering with CA policies to maintain persistence or bypass MFA.