Identifies attempts to brute force a Microsoft 365 user account. An adversary may attempt a brute force attack to obtain unauthorized access to user accounts.
Rule type: threshold
Risk score: 73
Runs every: None
Maximum alerts per execution: 100
- Microsoft 365
- Continuous Monitoring
- Identity and Access
Rule license: Elastic License v2
## Config The Microsoft 365 Fleet integration, Filebeat module, or similarly structured data is required to be compatible with this rule.
event.dataset:o365.audit and event.provider:(Exchange or AzureActiveDirectory) and event.category:authentication and event.action:("UserLoginFailed" or "PasswordLogonInitialAuthUsingPassword") and event.outcome:failure
Framework: MITRE ATT&CKTM