Microsoft 365Detection & ResponseRetrospectives

Detecting Help Desk Account Compromise: Defender XDR and Sentinel Hunting Queries

By OnCloudSec Research Team · Published Oct 6, 2026 · 1 min read

Retrospective: this article looks back at events from April 2019, written in 2026 with the benefit of hindsight.

A compromised help desk account — or a manipulated help desk agent — can reset credentials across your organization. Detecting unusual support activity limits the damage.

Signals worth watching

  • One support account resetting passwords or MFA methods for many users in a short period.
  • Resets of privileged accounts by help desk staff.
  • Support accounts signing in from unusual locations or devices.
  • Password or MFA resets followed by sign-ins from new locations for the affected user.
  • Support activity outside normal working hours.

Where the data lives

  • Entra ID audit logs: "Reset user password," "Admin registered security info," "Admin deleted security info," "Update user."
  • Sign-in logs for support accounts and affected users.
  • PIM audit history for role activations.

A starting query

AuditLogs
| where OperationName in ("Reset user password", "Admin registered security info",
    "Admin deleted security info", "Reset password (by admin)")
| extend Actor = tostring(InitiatedBy.user.userPrincipalName)
| summarize Actions = count(), Targets = dcount(tostring(TargetResources[0].userPrincipalName))
    by Actor, bin(TimeGenerated, 1h)
| where Targets > 10

Tune the threshold to your help desk's normal volume.

Response

  1. Contact the support agent's manager to confirm activity.
  2. If suspicious, disable the support account and revoke sessions.
  3. Review each affected user for subsequent sign-ins and changes.
  4. Revert unauthorized MFA method changes.
detect help desk account compromiseOutlook.com support account2019

More on this story