Detecting Admin Tool Social Engineering: Entra Sign-In Logs and Sentinel KQL
Retrospective: this article looks back at events from July 2020, written in 2026 with the benefit of hindsight.
Attackers who social-engineer employees often go straight for administrative tools. Detecting unusual admin access helps you catch them before they act.
Signals worth watching
- An admin signing in from a new device or location shortly after an unusual help desk call or a reported phishing attempt.
- PIM role activations at unusual times, without justification, or by people who rarely activate.
- Sign-ins to admin portals and internal admin apps immediately after an MFA registration change.
- Bursts of account changes (email address, phone number, MFA methods) for many users by one admin.
- Sign-ins from known phishing proxy infrastructure (Entra ID Protection "attacker in the middle" detection).
Where the data lives
- Entra ID sign-in logs for admin portals and internal applications.
- PIM audit logs for role activations.
- Entra ID audit logs for account changes.
- Defender XDR alerts linking phishing emails or URL clicks to subsequent sign-ins.
A starting query
PIM activations outside business hours:
AuditLogs
| where OperationName == "Add member to role completed (PIM activation)"
| extend Hour = datetime_part("hour", TimeGenerated)
| where Hour < 7 or Hour > 19
| project TimeGenerated, InitiatedBy, TargetResources, ResultReason
Adjust hours to your time zone and on-call patterns.
Response
- Contact the admin through a known channel to confirm.
- If not confirmed, deactivate the role, revoke sessions and reset credentials.
- Review all changes made during the session.
- Check whether the admin received a suspicious call or message.