Login attempts using Legacy Authentication (Azure)
This query over Azure AD sign-in activity highlights use of legacy authentication protocol in the environment. Because conditional access policies are not evaluated when legacy authentication is used, legacy authentication can be used to circumvent all Azure Conditional Access policies.
Source: Github - Microsoft
MITRE ATT&CK Tactics
Investigate the failed logins using Sentinel and see if the affected user accounts were used somewhere else in your network. Eventually reset password for impacted user accounts.