ByteRay CQL Hub
← All queries

Disable Strong Authentication (Microsoft Entra ID)

Detects when strong authentication methods (such as MFA) are disabled or weakened for a user account in Microsoft Entra ID. This action reduces account security and may indicate a legitimate administrative change or a potential attempt to bypass authentication controls and should be reviewed.

CQL · Falcon Next-Gen SIEMCopy query
#Vendor="microsoft"
| #event.module = azure
| #event.dataset = azure.entraid.audit
| Vendor.activityDisplayName ="Disable Strong Authentication"

Detects when strong authentication methods (such as MFA) are disabled or weakened for a user account in Microsoft Entra ID. This action reduces account security and may indicate a legitimate administrative change or a potential attempt to bypass authentication controls and should be reviewed.

disable_strong_authentication_microsoft_entra_id.yml
T1556
Kundan Kumar
Detection
Other
2026-05-21
2026-05-21

Get this query running in your SIEM, with someone on call.

Our Managed SIEM team operates CrowdStrike Falcon Next-Gen SIEM in production, with over 350 battle-tested use cases and 24/7 incident response behind them.

Talk to the SIEM team