Conditional Access Policy Disabled, Deleted, or Weakened
Detects unauthorized modifications to Microsoft Entra Conditional Access (CA) policies, including deleting policies, disabling them, removing MFA requirements, or excluding specific users. These actions are common techniques used by adversaries to establish persistence or facilitate unauthorized access by weakening security controls.
Microsoft Sentinel (KQL)

