Detecting VPN Logins Without MFA: Sentinel and GuardDuty Detections
Retrospective: this article looks back at events from May 2021, written in 2026 with the benefit of hindsight.
Sign-ins without MFA to remote access systems are a leading ransomware entry point. These detections highlight them.
Signals worth watching
- Successful VPN or gateway logins for accounts not enrolled in MFA.
- Single-factor sign-ins to Entra ID applications that should require MFA.
- Logins by dormant accounts (no activity in 90+ days).
- VPN logins from new countries or hosting providers.
- Remote access logins followed by internal scanning or admin tool use.
Where the data lives
- Entra ID sign-in logs (if remote access integrates with Entra ID).
- VPN and gateway logs forwarded via Syslog/CEF to Microsoft Sentinel.
- Active Directory logs for accounts used.
A starting query
Dormant accounts suddenly signing in:
let lookback = SigninLogs
| where TimeGenerated between (ago(120d) .. ago(1d)) and ResultType == "0"
| summarize LastSeen = max(TimeGenerated) by UserPrincipalName;
SigninLogs
| where TimeGenerated > ago(1d) and ResultType == "0"
| join kind=leftouter lookback on UserPrincipalName
| where isnull(LastSeen) or LastSeen < ago(90d)
| project TimeGenerated, UserPrincipalName, AppDisplayName, IPAddress, LastSeen
Response
- Disable the account and terminate sessions.
- Investigate activity from the session.
- Check for related accounts with leaked credentials.
- Enforce MFA on the access path.
- Colonial Pipeline (May 2021): One Legacy VPN Password Without MFA Incident Teardowns
- How to Find Remote Access Accounts That Bypass MFA How-To & Hardening
- CIO Brief: Colonial Pipeline and the Business Case for MFA on Everything CIO Briefings