Detecting Golden SAML: Entra Sign-In Logs and Sentinel KQL
Retrospective: this article looks back at events from December 2020, written in 2026 with the benefit of hindsight.
Golden SAML attacks forge tokens with a stolen AD FS signing certificate, letting attackers sign in to Microsoft 365 as anyone. These detections help identify signs of the technique and related federation abuse.
Signals worth watching
- Export of the AD FS token-signing certificate or access to the AD FS configuration database (Defender for Identity detects suspicious AD FS DKM key reads).
- Sign-ins to Entra ID using federated authentication without a corresponding authentication event on the AD FS server.
- Changes to federation settings in Entra ID: new federated domains, modified signing certificates, changed issuer URIs.
- Sign-ins with unusual token properties or MFA claims that don't match your AD FS configuration.
Where the data lives
- Microsoft Defender for Identity sensors on AD FS servers.
- AD FS audit logs (event IDs 1200 and 1202) forwarded to Sentinel.
- Entra ID audit logs for domain and federation changes.
- Entra ID sign-in logs for federated sign-ins.
A starting query
Federation and domain changes in Entra ID:
AuditLogs
| where OperationName in ("Set federation settings on domain", "Set domain authentication",
"Add unverified domain", "Verify domain", "Update domain")
| project TimeGenerated, OperationName, InitiatedBy, TargetResources
Correlating Entra federated sign-ins with AD FS events requires both log sources in Sentinel; Microsoft and the community publish analytics rules for this correlation.
Response
- Treat confirmed Golden SAML as a full identity compromise.
- Rotate the AD FS token-signing certificate twice in rapid succession.
- Revoke refresh tokens for all users.
- Review Entra ID for persistence: apps, service principals, federation changes.
- Accelerate migration to cloud authentication.