Detecting Help Desk Social Engineering: Entra Sign-In Logs and Sentinel KQL
Retrospective: this article looks back at events from September 2023, written in 2026 with the benefit of hindsight.
Help desk social engineering usually ends with a password or MFA reset followed by an attacker sign-in. These detections connect the two.
Signals worth watching
- MFA methods deleted or replaced by help desk staff, followed by a sign-in from a new device or location.
- Temporary Access Pass issued, then used from an unfamiliar IP.
- Resets for privileged users or executives.
- Several resets requested for the same user in a short period.
- A reset followed by privileged actions (role activation, Conditional Access changes, access to identity provider admin consoles).
Where the data lives
- Entra ID audit logs: "Admin deleted security info," "Admin registered security info," "Create Temporary Access Pass," "Reset user password."
- Entra ID sign-in logs.
- Ticketing system records (to confirm a legitimate request existed).
A starting query
MFA reset followed by a sign-in from a new IP within two hours:
let resets = AuditLogs
| where OperationName in ("Admin deleted security info", "Admin registered security info", "Create Temporary Access Pass method for user")
| extend Target = tostring(TargetResources[0].userPrincipalName)
| project ResetTime = TimeGenerated, Target, Actor = tostring(InitiatedBy.user.userPrincipalName);
SigninLogs
| where ResultType == "0"
| join kind=inner resets on $left.UserPrincipalName == $right.Target
| where TimeGenerated between (ResetTime .. ResetTime + 2h)
| project ResetTime, TimeGenerated, UserPrincipalName, Actor, IPAddress, Location, DeviceDetail
Response
- Contact the user via a known channel.
- If not legitimate, disable the account, revoke sessions and remove attacker-registered methods.
- Review actions taken after sign-in.
- Review the help desk interaction and verification steps used.