Detecting MFA Push Bombing: Entra Sign-In Logs and Sentinel KQL
Retrospective: this article looks back at events from September 2022, written in 2026 with the benefit of hindsight.
MFA push bombing generates bursts of MFA requests. Even with number matching, attackers try variations. These detections help catch attempts early.
Signals worth watching
- Many MFA requests to one user in a short window (for example, more than five in 10 minutes).
- MFA denials or timeouts followed by an approval.
- User reports via the Report suspicious activity feature.
- Contact attempts from "IT" via personal messaging apps (learned through user reports).
- A successful sign-in from a new device or location right after a burst of MFA requests.
Where the data lives
- Entra ID sign-in logs (MFA details and result codes).
- Entra ID Protection risk detections (user-reported suspicious activity raises risk).
- Defender XDR alerts.
A starting query
Bursts of MFA attempts per user:
SigninLogs
| where TimeGenerated > ago(1d)
| where AuthenticationRequirement == "multiFactorAuthentication"
| summarize Attempts = count(), Denied = countif(ResultType == "500121"),
Succeeded = countif(ResultType == "0") by UserPrincipalName, bin(TimeGenerated, 10m)
| where Attempts > 5
Response
- Contact the user via a known channel.
- If the user approved a prompt they didn't initiate, revoke sessions, reset the password and review registered MFA methods.
- Investigate where the credentials came from — infostealer infection on a personal device is common.
- Move high-risk users to phishing-resistant MFA.