AN0449
Analytic 0449
Identity Provider
Monitor for excessive or anomalous MFA push notifications or token requests, especially when login attempts originate from unusual IPs or geolocations and do not correspond to legitimate user-initiated sessions.
azure:signinlogs
Multiple MFA challenge requests without successful primary login
NSM:Connections
PushNotificationSent
[TimeWindow]
Threshold of MFA prompts per user within a short time period
[GeoIPAllowList]
Expected login locations for workforce; deviations can be tuned
AN0450
Analytic 0450
IaaS
Detect abnormal MFA activity within cloud service provider logs, such as repeated generation of MFA challenges for the same user session or mismatched MFA device and login origin.
AWS:CloudTrail
AssumeRole or ConsoleLogin with repeated MFA failures followed by repeated MFA requests
[FailedLoginThreshold]
Number of failed logins before raising detection
AN0451
Analytic 0451
Windows
Detect repeated failed login events followed by MFA challenges triggered in rapid succession, especially if originating from service accounts or anomalous IP addresses.
WinEventLog:Security
EventCode=4625
[ServiceAccountExclusion]
Exclude specific accounts where automated MFA requests are legitimate
AN0452
Analytic 0452
Linux
Monitor PAM and syslog entries for unusual frequency of login attempts that trigger MFA prompts, particularly when MFA challenges do not match expected user behavior.
auditd:AUTH
pam_unix or pam_google_authenticator invoked repeatedly within short interval
[AuthRetryThreshold]
Number of retries per user allowed before detection is triggered
AN0453
Analytic 0453
SaaS
Detect anomalous OAuth or SSO logins that repeatedly generate MFA challenges, particularly where MFA approvals are denied or timed out by the user.
saas:okta
MFAChallengeIssued
[MFAProvider]
Identify which MFA service provider logs are in use (Okta, Duo, Microsoft Authenticator)
AN0454
Analytic 0454
macOS
Detect user account logon attempts that trigger multiple MFA challenges through enterprise identity integrations, especially if MFA push requests are generated without successful interactive login.
macos:unifiedlog
authd generating multiple MFA token requests
[DeviceEnrollmentStatus]
Exclude unmanaged macOS devices that use different MFA providers