Multi-CloudDetection & ResponseRetrospectives

Detecting VPN Logins Without MFA: Sentinel and GuardDuty Detections

By OnCloudSec Research Team · Published Oct 6, 2026 · 1 min read

Retrospective: this article looks back at events from May 2021, written in 2026 with the benefit of hindsight.

Sign-ins without MFA to remote access systems are a leading ransomware entry point. These detections highlight them.

Signals worth watching

  • Successful VPN or gateway logins for accounts not enrolled in MFA.
  • Single-factor sign-ins to Entra ID applications that should require MFA.
  • Logins by dormant accounts (no activity in 90+ days).
  • VPN logins from new countries or hosting providers.
  • Remote access logins followed by internal scanning or admin tool use.

Where the data lives

  • Entra ID sign-in logs (if remote access integrates with Entra ID).
  • VPN and gateway logs forwarded via Syslog/CEF to Microsoft Sentinel.
  • Active Directory logs for accounts used.

A starting query

Dormant accounts suddenly signing in:

let lookback = SigninLogs
| where TimeGenerated between (ago(120d) .. ago(1d)) and ResultType == "0"
| summarize LastSeen = max(TimeGenerated) by UserPrincipalName;
SigninLogs
| where TimeGenerated > ago(1d) and ResultType == "0"
| join kind=leftouter lookback on UserPrincipalName
| where isnull(LastSeen) or LastSeen < ago(90d)
| project TimeGenerated, UserPrincipalName, AppDisplayName, IPAddress, LastSeen

Response

  1. Disable the account and terminate sessions.
  2. Investigate activity from the session.
  3. Check for related accounts with leaked credentials.
  4. Enforce MFA on the access path.
detect vpn logins without mfaColonial Pipeline2021

More on this story