2026 Critical Enterprise Intrusion Chain Detection: Post-Authentication Token Reuse Without MFA Challenge
Detects non-interactive sign-in events in Entra ID that occur without a preceding interactive sign-in session on the same device that successfully satisfied a multi-factor authentication (MFA) challenge. This behavior is indicative of token replay attacks or session hijacking where an adversary attempts to use harvested session cookies or tokens to access resources.
Microsoft Sentinel (KQL)

