Multi-CloudDetection & ResponseRetrospectives

Detecting Remote Access Without MFA: Sentinel and GuardDuty Detections

By OnCloudSec Research Team · Published Oct 6, 2026 · 1 min read

Retrospective: this article looks back at events from February 2024, written in 2026 with the benefit of hindsight.

Remote access without MFA is a top ransomware entry point. These detections look for single-factor access and the activity that typically follows.

Signals worth watching

  • Successful remote access logins where MFA wasn't required or performed.
  • Remote access from unusual countries, hosting providers or anonymizing networks.
  • Logins by accounts that haven't used remote access before.
  • New remote access sessions followed by internal reconnaissance (network scanning, AD enumeration), RDP to many hosts or use of admin tools.
  • Logins outside normal hours.

Where the data lives

  • Gateway logs (Citrix, VPN) forwarded to Sentinel via Syslog/CEF or vendor connectors.
  • Entra ID sign-in logs (if integrated).
  • Endpoint telemetry for post-login activity.
  • Active Directory logs.

A starting query

Single-factor sign-ins to remote access apps integrated with Entra ID:

SigninLogs
| where ResultType == "0"
| where AppDisplayName has_any ("Citrix", "VPN", "Gateway", "Remote")
| where AuthenticationRequirement == "singleFactorAuthentication"
| project TimeGenerated, UserPrincipalName, AppDisplayName, IPAddress, Location, ConditionalAccessStatus

Post-login reconnaissance

DeviceProcessEvents
| where ProcessCommandLine has_any ("nltest /domain_trusts", "net group \"domain admins\"", "AdFind", "Get-ADComputer")
| project Timestamp, DeviceName, AccountName, ProcessCommandLine

Response

  1. Terminate sessions and disable affected accounts.
  2. Enforce MFA on the portal immediately.
  3. Hunt for lateral movement and ransomware staging.
  4. Engage incident response if reconnaissance or credential theft is confirmed.
detect remote access without mfaChange Healthcare2024

More on this story