Entra ID external authentication methods policy created

Goal

Detect when an account adds an external multifactor authentication (external MFA), previously known as external authentication methods, to the tenant. This may indicate an attacker preparing a malicious OIDC provider to authenticate as tenant users.

Strategy

Monitor Microsoft Entra ID audit logs for the following event, Authentication Methods Policy Create.

Triage and response

  1. Verify if this activity is associated with an authorized authentication method, and was intentionally added by an approved administrator.
  2. Check for other signals and logs generated by the acting account, and look for deviations in the following properties:
    • Application
    • Device
    • Geolocation
    • IP address
    • User agent
  3. If the activity appears suspicious, initiate your incident response process for further investigation.