2026 Critical Enterprise Intrusion Chain Detection: Legacy Authentication Sign-In Bypassing Conditional Access Policy

Detects successful authentication attempts using legacy (basic) protocols that do not enforce modern Conditional Access policies (e.g., MFA, device compliance). The rule specifically flags these events if the originating IP address or geographic location is not observed in historical sign-in activity for the specific user, which may indicate account compromise via credential theft.