Entra ID & IdentityDetection & ResponseRetrospectives

Detecting Cloud SSO Compromise: Entra Sign-In Logs and Sentinel KQL

By OnCloudSec Research Team · Published Oct 6, 2026 · 1 min read

Retrospective: this article looks back at events from March 2025, written in 2026 with the benefit of hindsight.

When an SSO or identity provider is compromised, attackers may use stolen credentials or forged tokens to access connected applications. These detections help identify suspicious SSO activity.

Signals worth watching

  • Sign-ins to SSO-connected applications from new IPs, countries or hosting providers.
  • Sign-ins for many users from the same unusual IP.
  • Sign-ins at odd times for accounts that normally follow business hours.
  • Changes to SSO configuration: new identity providers, modified certificates, new application integrations.
  • Admin sign-ins to the SSO platform from unfamiliar locations.

Where the data lives

  • Entra ID sign-in logs if Entra is your IdP or federated with another.
  • SSO platform logs (for third-party IdPs, ingested into your SIEM).
  • Application audit logs for downstream apps.
  • Entra ID audit logs for federation and application changes.

A starting query

Federated sign-ins (from an external IdP) for many users from one IP:

SigninLogs
| where ResultType == "0"
| where isnotempty(tostring(parse_json(tostring(AuthenticationDetails))))
| summarize Users = dcount(UserPrincipalName) by IPAddress, AppDisplayName, bin(TimeGenerated, 1h)
| where Users > 10

Federation configuration changes:

AuditLogs
| where OperationName has_any ("Set federation settings on domain", "Set domain authentication",
    "Add identity provider", "Update identity provider")
| project TimeGenerated, OperationName, InitiatedBy, TargetResources

Response

  1. Rotate credentials and certificates for the SSO integration.
  2. Revoke sessions for affected users.
  3. Review downstream application activity.
  4. Restrict SSO admin access and confirm configuration integrity.
detect cloud sso compromiseOracle Cloud SSO breach claims2025

More on this story