Detecting Help Desk Account Compromise: Defender XDR and Sentinel Hunting Queries
Retrospective: this article looks back at events from April 2019, written in 2026 with the benefit of hindsight.
A compromised help desk account — or a manipulated help desk agent — can reset credentials across your organization. Detecting unusual support activity limits the damage.
Signals worth watching
- One support account resetting passwords or MFA methods for many users in a short period.
- Resets of privileged accounts by help desk staff.
- Support accounts signing in from unusual locations or devices.
- Password or MFA resets followed by sign-ins from new locations for the affected user.
- Support activity outside normal working hours.
Where the data lives
- Entra ID audit logs: "Reset user password," "Admin registered security info," "Admin deleted security info," "Update user."
- Sign-in logs for support accounts and affected users.
- PIM audit history for role activations.
A starting query
AuditLogs
| where OperationName in ("Reset user password", "Admin registered security info",
"Admin deleted security info", "Reset password (by admin)")
| extend Actor = tostring(InitiatedBy.user.userPrincipalName)
| summarize Actions = count(), Targets = dcount(tostring(TargetResources[0].userPrincipalName))
by Actor, bin(TimeGenerated, 1h)
| where Targets > 10
Tune the threshold to your help desk's normal volume.
Response
- Contact the support agent's manager to confirm activity.
- If suspicious, disable the support account and revoke sessions.
- Review each affected user for subsequent sign-ins and changes.
- Revert unauthorized MFA method changes.