Hi Team,
I have integrated O365 to chronicle SIEM and want to create a usecase for MFA activities. Specifically, if a user adds new device, deletes a device or deletes MFA then it should trigger alert.
Can it be done using O365 los only or do I have to integrate Azure AD as well.
is these any usecase available????