Entra ID & IdentityDetection & ResponseRetrospectives

Detecting Session Token Theft HAR Files: Entra Sign-In Logs and Sentinel KQL

By OnCloudSec Research Team · Published Oct 6, 2026 · 1 min read

Retrospective: this article looks back at events from October 2023, written in 2026 with the benefit of hindsight.

Session tokens taken from HAR files, infostealer logs or phishing proxies are used to access accounts without signing in. Detection focuses on session reuse from unexpected contexts.

Signals worth watching

  • A session (same session ID) used from a different IP address, ASN or country than where it began.
  • Admin console access with no recent interactive sign-in or MFA.
  • Activity from a device or browser that doesn't match the original sign-in's device details.
  • Entra ID Protection detections: anomalous token, token issuer anomaly, attacker in the middle.
  • Vendor notifications of support system compromise.

Where the data lives

  • Entra ID interactive and non-interactive sign-in logs (including SessionId).
  • Identity Protection risk detections.
  • Admin audit logs from your identity provider and SaaS apps.

A starting query

Sessions spanning multiple ASNs:

union SigninLogs, AADNonInteractiveUserSignInLogs
| where ResultType == "0" and isnotempty(SessionId)
| summarize ASNs = dcount(AutonomousSystemNumber), IPs = make_set(IPAddress, 10),
    Apps = make_set(AppDisplayName, 10) by UserPrincipalName, SessionId
| where ASNs > 1

Mobile users switching between Wi-Fi and cellular will appear; prioritize admin accounts and hosting-provider ASNs.

Response

  1. Revoke all sessions for the user.
  2. Review admin actions taken during the suspicious session.
  3. Identify the token source (support upload, infostealer, phishing).
  4. Enable token protection and stricter session controls for affected roles.
detect session token theft har filesOkta support HAR files2023

More on this story