AN0814
Analytic 0814
Windows
Detects injection or tampering of DLLs in hybrid identity agents (e.g., AzureADConnectAuthenticationAgentService), registry or configuration changes tied to PTA/AD FS, and anomalous LSASS or AD FS module loads correlated with authentication anomalies.
WinEventLog:Sysmon
EventCode=7
WinEventLog:Security
EventCode=5136
WinEventLog:Security
Anomalous logon without MFA enforcement
[WatchedServices]
Hybrid identity services monitored for tampering, e.g., PTA agent, AD FS.
[TimeWindow]
Window correlating DLL/module load events with logon anomalies.
AN0815
Analytic 0815
Identity Provider
Detects registration of new PTA agents, conditional access changes disabling hybrid MFA enforcement, or suspicious updates to AD FS token-signing configurations.
azure:signinlogs
Register PTA Agent or Modify AD FS trust
m365:unified
New agent registration by non-admin user
[PrivilegedRoles]
Roles authorized to configure PTA/AD FS integrations.
AN0816
Analytic 0816
IaaS
Detects API calls registering or updating hybrid identity connectors, modification of cloud-to-on-premises federation trust, and unusual token issuance logs.
AWS:CloudTrail
UpdateFederationSettings or RegisterHybridConnector
[MonitoredFederations]
Federation trusts and connectors relevant to hybrid identity setup.
AN0817
Analytic 0817
Office Suite
Detects tenant-wide authentication or conditional access changes that weaken hybrid identity enforcement, including disabling AD FS or bypassing hybrid MFA policies.
m365:unified
Modify Federation Settings or Update Authentication Policy
[PolicyScope]
Scope of authentication and federation policies to be monitored.
AN0818
Analytic 0818
SaaS
Detects suspicious changes to SAML/OAuth federation configurations, such as new signing certificates, altered endpoints, or claims issuance rules granting elevated privileges.
saas:okta
Federation configuration update or signing certificate change
[FederationEndpoints]
Federation/SAML endpoints monitored for modification.