---
title: Entra ID external authentication methods policy created
description: Datadog, the leading service for cloud-scale monitoring.
breadcrumbs: >-
  Docs > Datadog Security > OOTB Rules > Entra ID external authentication
  methods policy created
---

> For the complete documentation index, see [llms.txt](https://docs.datadoghq.com/llms.txt).

# Entra ID external authentication methods policy created
Classification:attackTactic:[TA0003-persistence](https://attack.mitre.org/tactics/TA0003)Technique:[T1556-modify-authentication-process](https://attack.mitre.org/techniques/T1556) 
## Goal{% #goal %}

Detect when an account adds an external multifactor authentication (external MFA), previously known as external authentication methods, to the tenant. This may indicate an attacker preparing a malicious OIDC provider to authenticate as tenant users.

## Strategy{% #strategy %}

Monitor Microsoft Entra ID audit logs for the following event, `Authentication Methods Policy Create`.

## Triage and response{% #triage-and-response %}

1. Verify if this activity is associated with an authorized authentication method, and was intentionally added by an approved administrator.
1. Check for other signals and logs generated by the acting account, and look for deviations in the following properties:
   - Application
   - Device
   - Geolocation
   - IP address
   - User agent
1. If the activity appears suspicious, initiate your incident response process for further investigation.
