1200KM / detection
T1556.006 Multi-Factor Authentication — Detection Rules
Detection workspace for T1556.006 Multi-Factor Authentication: 3 Sigma sources, 0 Atlas concepts and 0 anomaly models. No live detection validation.
Source-backed rule directory
- Azure AD Only Single Factor Authentication Required · test · low · {"product":"azure","service":"signinlogs"}
- Disabling Multi Factor Authentication · test · high · {"service":"audit","product":"m365"}
- Okta MFA Reset or Deactivated · test · medium · {"product":"okta","service":"okta"}
Atlas deterministic concepts
No exact concept selected.
Anomaly models
No exact Atlas model in this snapshot.
ATT&CK analytic guidance
DET0190 Detect MFA Modification or Disabling Across Platforms
AN0543 Analytic 0543
Detects registry and Group Policy modifications that disable or weaken MFA, suspicious PowerShell usage modifying MFA-related attributes, and anomalous login sessions succeeding without expected MFA challenge.
AN0544 Analytic 0544
Detects conditional access policy changes, exclusion of accounts from MFA enforcement, or registration of new MFA factors by non-admin or anomalous users.
AN0545 Analytic 0545
Detects API calls to cloud secrets/MFA configurations where MFA enforcement policies are disabled or bypassed.
AN0546 Analytic 0546
Detects PAM module modifications or removal of MFA hooks in /etc/pam.d/ configurations, correlated with successful authentications lacking MFA prompts.
AN0547 Analytic 0547
Detects modifications to authorization plugins responsible for MFA enforcement and correlates with suspicious login sessions missing MFA prompts.
AN0548 Analytic 0548
Detects suspicious MFA method changes, such as registration of weaker factors (e.g., SMS), or removal of MFA requirements for specific accounts or groups.
AN0549 Analytic 0549
Detects MFA bypass attempts by modifying tenant-wide authentication policies or excluding high-value accounts from MFA enforcement.
Connected ecosystem references
Linked tags
Simulation, tools and telemetry
Threat actor context
These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.
Existing anomaly research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.