This use case tests for the ability to detect when a threat actor logs in from a suspicious country. Once a threat actor logs in to an Office 365 account, they have full access to the email account.
Barracuda XDR
XDR Azure Threat Simulation - PIM Roles
