2026 Critical Enterprise Intrusion Chain Detection: Post-Authentication Token Reuse Without MFA Challenge

Detects non-interactive sign-in events in Entra ID that occur without a preceding interactive sign-in session on the same device that successfully satisfied a multi-factor authentication (MFA) challenge. This behavior is indicative of token replay attacks or session hijacking where an adversary attempts to use harvested session cookies or tokens to access resources.