Entra ID & IdentityDetection & ResponseRetrospectives

Detecting Admin Tool Social Engineering: Entra Sign-In Logs and Sentinel KQL

By OnCloudSec Research Team · Published Oct 6, 2026 · 1 min read

Retrospective: this article looks back at events from July 2020, written in 2026 with the benefit of hindsight.

Attackers who social-engineer employees often go straight for administrative tools. Detecting unusual admin access helps you catch them before they act.

Signals worth watching

  • An admin signing in from a new device or location shortly after an unusual help desk call or a reported phishing attempt.
  • PIM role activations at unusual times, without justification, or by people who rarely activate.
  • Sign-ins to admin portals and internal admin apps immediately after an MFA registration change.
  • Bursts of account changes (email address, phone number, MFA methods) for many users by one admin.
  • Sign-ins from known phishing proxy infrastructure (Entra ID Protection "attacker in the middle" detection).

Where the data lives

  • Entra ID sign-in logs for admin portals and internal applications.
  • PIM audit logs for role activations.
  • Entra ID audit logs for account changes.
  • Defender XDR alerts linking phishing emails or URL clicks to subsequent sign-ins.

A starting query

PIM activations outside business hours:

AuditLogs
| where OperationName == "Add member to role completed (PIM activation)"
| extend Hour = datetime_part("hour", TimeGenerated)
| where Hour < 7 or Hour > 19
| project TimeGenerated, InitiatedBy, TargetResources, ResultReason

Adjust hours to your time zone and on-call patterns.

Response

  1. Contact the admin through a known channel to confirm.
  2. If not confirmed, deactivate the role, revoke sessions and reset credentials.
  3. Review all changes made during the session.
  4. Check whether the admin received a suspicious call or message.
detect admin tool social engineeringTwitter admin tool hack2020

More on this story