Entra ID & IdentityDetection & ResponseRetrospectives

Detecting Access Token Theft: Entra Sign-In Logs and Sentinel KQL

By OnCloudSec Research Team · Published Oct 6, 2026 · 1 min read

Retrospective: this article looks back at events from September 2018, written in 2026 with the benefit of hindsight.

Token theft lets an attacker act as a user without their password or MFA. Detection focuses on tokens being used in ways that don't match the device and location where they were issued.

Signals worth watching

  • The same session used from two different IP addresses or countries in a short time.
  • Non-interactive sign-ins (token refreshes) from locations the user has never used interactively.
  • Successful access with no matching interactive sign-in or MFA event.
  • Access from hosting providers or anonymizing networks shortly after a normal sign-in.
  • Entra ID Protection detections such as anomalous token and attacker in the middle (Entra ID P2).

Where the data lives

  • Interactive sign-in logs (SigninLogs) and non-interactive sign-in logs (AADNonInteractiveUserSignInLogs).
  • Entra ID Protection risk detections.
  • Defender XDR alerts correlating endpoint infostealer activity with cloud sign-ins.

A starting query

Find sessions used from more than one IP address:

union SigninLogs, AADNonInteractiveUserSignInLogs
| where ResultType == "0" and isnotempty(SessionId)
| summarize IPs = dcount(IPAddress), IPList = make_set(IPAddress, 10),
    Countries = make_set(Location, 10) by UserPrincipalName, SessionId
| where IPs > 1

Mobile networks and VPNs change IPs legitimately; focus on sessions spanning different countries or hosting providers.

Response

  1. Revoke all sessions for the user.
  2. Reset credentials and review MFA methods registered.
  3. Check for persistence: inbox rules, OAuth consents, new devices registered.
  4. Investigate the endpoint — infostealer malware is a common source of stolen tokens.
detect access token theftFacebook View As token theft2018

More on this story