Privileged Account MFA/Security Info Method Changed
This rule detects modifications to multi-factor authentication (MFA) settings performed by privileged users (e.g., Global Admins) from IP addresses not previously associated with their account. The rule tracks actions such as registering new security information, changing default MFA methods, or deleting authentication methods. High-risk indicators like an unknown IP address for a privileged account are flagged for further investigation.
Splunk (SPL)

