Entra ID & IdentityHow-To & HardeningRetrospectives

How to Monitor Entra ID for Cross-Tenant and Undocumented Token Abuse

By OnCloudSec Research Team · Published Oct 6, 2026 · 1 min read

Retrospective: this article looks back at events from September 2025, written in 2026 with the benefit of hindsight.

Cross-tenant and undocumented token flaws are rare but serious. Customers can't prevent provider bugs, but can reduce exposure and improve visibility. Here is how to monitor Entra ID for cross-tenant activity and legacy token use.

Step 1: Review cross-tenant access settings

In the Entra admin center under External Identities → Cross-tenant access settings:

  • Review default inbound and outbound settings.
  • Configure organization-specific settings for partners.
  • Consider tenant restrictions v2 to control which external tenants your users can access.

Step 2: Retire Azure AD Graph dependencies

Microsoft has been retiring the legacy Azure AD Graph API. Identify applications in your tenant that still request Azure AD Graph permissions (resource 00000002-0000-0000-c000-000000000000 / Windows Azure Active Directory) and migrate them to Microsoft Graph.

Step 3: Monitor cross-tenant sign-ins

Entra sign-in logs include fields for the home tenant and resource tenant. Monitor:

  • Users from external tenants signing in to your resources.
  • Your users accessing external tenants (outbound).

Step 4: Monitor directory changes regardless of source

Because some provider-side flaws produce little sign-in evidence, monitor outcomes: new admin role assignments, new users, new app credentials, changes to Conditional Access and federation. These appear in audit logs even if the initial access is unusual.

Step 5: Use Microsoft Graph activity logs

Enable Microsoft Graph activity logs (via diagnostic settings) to record API requests to Microsoft Graph in your tenant, including the calling app and identity.

Step 6: Stay informed

Subscribe to Microsoft Security Response Center advisories and Entra "What's new" updates.

Verify

Confirm alerts exist for privileged changes and that Graph activity logs are flowing.

monitor entra id cross tenant accessEntra actor token flaw2025

More on this story