Detecting Access Token Theft: Entra Sign-In Logs and Sentinel KQL
Retrospective: this article looks back at events from September 2018, written in 2026 with the benefit of hindsight.
Token theft lets an attacker act as a user without their password or MFA. Detection focuses on tokens being used in ways that don't match the device and location where they were issued.
Signals worth watching
- The same session used from two different IP addresses or countries in a short time.
- Non-interactive sign-ins (token refreshes) from locations the user has never used interactively.
- Successful access with no matching interactive sign-in or MFA event.
- Access from hosting providers or anonymizing networks shortly after a normal sign-in.
- Entra ID Protection detections such as anomalous token and attacker in the middle (Entra ID P2).
Where the data lives
- Interactive sign-in logs (
SigninLogs) and non-interactive sign-in logs (AADNonInteractiveUserSignInLogs). - Entra ID Protection risk detections.
- Defender XDR alerts correlating endpoint infostealer activity with cloud sign-ins.
A starting query
Find sessions used from more than one IP address:
union SigninLogs, AADNonInteractiveUserSignInLogs
| where ResultType == "0" and isnotempty(SessionId)
| summarize IPs = dcount(IPAddress), IPList = make_set(IPAddress, 10),
Countries = make_set(Location, 10) by UserPrincipalName, SessionId
| where IPs > 1
Mobile networks and VPNs change IPs legitimately; focus on sessions spanning different countries or hosting providers.
Response
- Revoke all sessions for the user.
- Reset credentials and review MFA methods registered.
- Check for persistence: inbox rules, OAuth consents, new devices registered.
- Investigate the endpoint — infostealer malware is a common source of stolen tokens.