I think Microsoft security peeps may want to go through their logs for Microsoft Azure Active Directory Connect app usage from 23rd October 2024 onwards - we’re all seeing the same thing, low and slow brute force, comes up as single factor auth (probably because Entra AD Connect is needed for directory sync for MFA to function).