Entra ID & IdentityDetection & ResponseRetrospectives

Detecting Golden SAML: Entra Sign-In Logs and Sentinel KQL

By OnCloudSec Research Team · Published Oct 6, 2026 · 1 min read

Retrospective: this article looks back at events from December 2020, written in 2026 with the benefit of hindsight.

Golden SAML attacks forge tokens with a stolen AD FS signing certificate, letting attackers sign in to Microsoft 365 as anyone. These detections help identify signs of the technique and related federation abuse.

Signals worth watching

  • Export of the AD FS token-signing certificate or access to the AD FS configuration database (Defender for Identity detects suspicious AD FS DKM key reads).
  • Sign-ins to Entra ID using federated authentication without a corresponding authentication event on the AD FS server.
  • Changes to federation settings in Entra ID: new federated domains, modified signing certificates, changed issuer URIs.
  • Sign-ins with unusual token properties or MFA claims that don't match your AD FS configuration.

Where the data lives

  • Microsoft Defender for Identity sensors on AD FS servers.
  • AD FS audit logs (event IDs 1200 and 1202) forwarded to Sentinel.
  • Entra ID audit logs for domain and federation changes.
  • Entra ID sign-in logs for federated sign-ins.

A starting query

Federation and domain changes in Entra ID:

AuditLogs
| where OperationName in ("Set federation settings on domain", "Set domain authentication",
    "Add unverified domain", "Verify domain", "Update domain")
| project TimeGenerated, OperationName, InitiatedBy, TargetResources

Correlating Entra federated sign-ins with AD FS events requires both log sources in Sentinel; Microsoft and the community publish analytics rules for this correlation.

Response

  1. Treat confirmed Golden SAML as a full identity compromise.
  2. Rotate the AD FS token-signing certificate twice in rapid succession.
  3. Revoke refresh tokens for all users.
  4. Review Entra ID for persistence: apps, service principals, federation changes.
  5. Accelerate migration to cloud authentication.
detect golden samlSolarWinds / Golden SAML2020

More on this story