Detecting Password Spraying: Defender XDR and Sentinel Hunting Queries
Retrospective: this article looks back at events from March 2018, written in 2026 with the benefit of hindsight.
Password spraying tries a small number of common passwords against many accounts, staying below lockout thresholds. Detecting it requires looking across accounts, not at any single one.
Signals worth watching
- Failed sign-ins from one IP or a small IP range against many different accounts.
- Failures concentrated on legacy authentication protocols.
- The same failure pattern repeating at regular intervals (a few attempts per account per hour).
- Smart lockout events across multiple users.
- A successful sign-in from the same source after many failures.
Where the data lives
- Entra ID sign-in logs (interactive and non-interactive).
- Entra ID Protection password spray risk detection (Entra ID P2).
- Microsoft Defender for Identity for on-premises Active Directory spraying.
A starting query
SigninLogs
| where ResultType in ("50126", "50053")
| summarize FailedUsers = dcount(UserPrincipalName), Attempts = count(),
Apps = make_set(AppDisplayName, 10), ClientApps = make_set(ClientAppUsed, 10)
by IPAddress, bin(TimeGenerated, 1h)
| where FailedUsers > 15
Then join to successful sign-ins (ResultType == "0") from the same IP addresses to find accounts that may have been compromised.
Response
- Block the source IPs if they are not legitimate.
- Reset passwords for any account with a successful sign-in from the spraying source, and revoke sessions.
- Confirm legacy authentication is blocked and MFA is enforced.
- Add the guessed passwords' patterns (season plus year, company name) to your banned password list.