Hunting MFA Fatigue in Sentinel: Building the Detection One Line at a Time
Push-bombing leaves a loud shape in SigninLogs. A count, a threshold and a join are enough to catch it.
security · azure · data · the practical side
They're the seams nobody owns, the permissions nobody removed, and the detections nobody can read. I write about fixing that: practical, principle-based, from a decade-plus in security engineering, hybrid cloud and large-scale infrastructure.
Push-bombing leaves a loud shape in SigninLogs. A count, a threshold and a join are enough to catch it.
Provisioned versus overage, the hourly billing quirk, the E5 allocation, and what running out looks like mid-incident.
Enablement, SCUs, and the everyone-is-a-Contributor default you want to fix on day one.
Break-glass first, report-only always, and the other habits that keep a CA rollout from ending in a lockout.
Five operators, one mental model, and the discipline of never trusting a detection you can't read.