Microsoft 365Detection & ResponseRetrospectives

Detecting Password Spraying: Defender XDR and Sentinel Hunting Queries

By OnCloudSec Research Team · Published Oct 6, 2026 · 1 min read

Retrospective: this article looks back at events from March 2018, written in 2026 with the benefit of hindsight.

Password spraying tries a small number of common passwords against many accounts, staying below lockout thresholds. Detecting it requires looking across accounts, not at any single one.

Signals worth watching

  • Failed sign-ins from one IP or a small IP range against many different accounts.
  • Failures concentrated on legacy authentication protocols.
  • The same failure pattern repeating at regular intervals (a few attempts per account per hour).
  • Smart lockout events across multiple users.
  • A successful sign-in from the same source after many failures.

Where the data lives

  • Entra ID sign-in logs (interactive and non-interactive).
  • Entra ID Protection password spray risk detection (Entra ID P2).
  • Microsoft Defender for Identity for on-premises Active Directory spraying.

A starting query

SigninLogs
| where ResultType in ("50126", "50053")
| summarize FailedUsers = dcount(UserPrincipalName), Attempts = count(),
    Apps = make_set(AppDisplayName, 10), ClientApps = make_set(ClientAppUsed, 10)
    by IPAddress, bin(TimeGenerated, 1h)
| where FailedUsers > 15

Then join to successful sign-ins (ResultType == "0") from the same IP addresses to find accounts that may have been compromised.

Response

  1. Block the source IPs if they are not legitimate.
  2. Reset passwords for any account with a successful sign-in from the spraying source, and revoke sessions.
  3. Confirm legacy authentication is blocked and MFA is enforced.
  4. Add the guessed passwords' patterns (season plus year, company name) to your banned password list.
detect password sprayingMabna password spraying2018

More on this story