Azure secure score block legacy authentication
| Id | C27BB559-28C5-4924-A7DA-3BF04CD02C8F |
| Rulename | Azure secure score block legacy authentication |
| Description | This query searches for most compromising sign-in attempts come from legacy authentication. Older office clients such as Office 2010 do not support modern authentication and use legacy protocols such as IMAP, SMTP, and POP3. Legacy authentication does not support multi-factor authentication (MFA). Even if an MFA policy is configured in your environment, bad actors can bypass these enforcements through legacy protocols. |
| Severity | High |
| Tactics | CredentialAccess |
| Techniques | T1212 T1556 |
| Required data connectors | SenservaPro |
| Kind | Scheduled |
| Query frequency | 6h |
| Query period | 6h |
| Trigger threshold | 0 |
| Trigger operator | gt |
| Source Uri | https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/SenservaPro/Analytic Rules/BlockLegacyAuthentication.yaml |
| Version | 1.0.1 |
| Arm template | C27BB559-28C5-4924-A7DA-3BF04CD02C8F.json |
SenservaPro_CL
| where ControlName_s == 'AzureSecureScoreBlockLegacyAuthentication'
query: |
SenservaPro_CL
| where ControlName_s == 'AzureSecureScoreBlockLegacyAuthentication'
version: 1.0.1
triggerOperator: gt
relevantTechniques:
- T1212
- T1556
requiredDataConnectors:
- connectorId: SenservaPro
dataTypes:
- SenservaPro_CL
kind: Scheduled
tactics:
- CredentialAccess
triggerThreshold: 0
entityMappings:
- entityType: Account
fieldMappings:
- columnName: ControlName_s
identifier: Name
- columnName: TenantId
identifier: AadTenantId
- columnName: TenantDisplayName_s
identifier: DisplayName
- entityType: SecurityGroup
fieldMappings:
- columnName: Group_s
identifier: DistinguishedName
- entityType: AzureResource
fieldMappings:
- columnName: SourceSystem
identifier: ResourceId
description: |
'This query searches for most compromising sign-in attempts come from legacy authentication.
Older office clients such as Office 2010 do not support modern authentication and use legacy protocols such as IMAP, SMTP, and POP3.
Legacy authentication does not support multi-factor authentication (MFA).
Even if an MFA policy is configured in your environment, bad actors can bypass these enforcements through legacy protocols.'
queryFrequency: 6h
id: C27BB559-28C5-4924-A7DA-3BF04CD02C8F
severity: High
status: Available
queryPeriod: 6h
name: Azure secure score block legacy authentication
OriginalUri: https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/SenservaPro/Analytic Rules/BlockLegacyAuthentication.yaml