Entra ID & IdentityDetection & ResponseRetrospectives

Detecting Cross-Tenant Token Abuse: Entra Sign-In Logs and Sentinel KQL

By OnCloudSec Research Team · Published Oct 6, 2026 · 1 min read

Retrospective: this article looks back at events from September 2025, written in 2026 with the benefit of hindsight.

When identity platform flaws limit logging of the initial access, you can still detect what attackers do next. These detections focus on cross-tenant activity and privileged changes.

Signals worth watching

  • Sign-ins where the home tenant differs from your tenant for accounts with privileged roles.
  • Privileged changes (role assignments, new users, app credential additions) with unusual initiators, missing initiator details or unfamiliar app IDs.
  • Microsoft Graph or Azure AD Graph API calls from unfamiliar applications.
  • Changes to cross-tenant access settings.

Where the data lives

  • Entra ID sign-in logs (HomeTenantId, ResourceTenantId, CrossTenantAccessType).
  • Entra ID audit logs.
  • Microsoft Graph activity logs (MicrosoftGraphActivityLogs table).

A starting query

Cross-tenant sign-ins to your tenant:

SigninLogs
| where HomeTenantId != ResourceTenantId
| summarize Count = count() by HomeTenantId, UserPrincipalName, AppDisplayName, CrossTenantAccessType
| sort by Count desc

Privileged audit events with unusual initiators:

AuditLogs
| where OperationName in ("Add member to role", "Add user", "Add service principal credentials",
    "Update conditional access policy", "Set federation settings on domain")
| extend InitiatorUPN = tostring(InitiatedBy.user.userPrincipalName), InitiatorApp = tostring(InitiatedBy.app.displayName)
| where isempty(InitiatorUPN) and isempty(InitiatorApp) or InitiatorApp !in ("Your-Known-Automation-App")
| project TimeGenerated, OperationName, InitiatedBy, TargetResources

Response

  1. Validate any unexplained privileged change immediately.
  2. Revert unauthorized changes and investigate.
  3. Engage Microsoft support if you suspect a platform-level issue.
detect cross-tenant token abuseEntra actor token flaw2025

More on this story