Azure AD Threat Intelligence — Detection Rule

Indicates user activity that is unusual for the user or consistent with known attack patterns.

Read the full analysis on IntelFusions