TrustSink: Rogue External Authentication Method Registered

Detects modifications to Microsoft Entra ID (formerly Azure AD) authentication policies, specifically the registration, enablement, or modification of External Authentication Methods (EAMs). This activity can indicate an attempt to add a rogue authentication provider for persistent unauthorized access, bypassing standard MFA or conditional access policies.