Microsoft 365Detection & ResponseRetrospectives

Detecting Compromised Admin Account: Defender XDR and Sentinel Hunting Queries

By OnCloudSec Research Team · Published Oct 6, 2026 · 1 min read

Retrospective: this article looks back at events from September 2017, written in 2026 with the benefit of hindsight.

Compromised administrator accounts give attackers control of an entire Microsoft 365 tenant. Detecting unusual admin behavior early is one of the highest-value detections you can build.

Signals worth watching

  • Admin sign-ins from new countries, hosting providers or anonymizing networks.
  • New members added to Global Administrator or other privileged roles.
  • New credentials or permissions added to applications and service principals.
  • Changes to Conditional Access policies, authentication methods or federation settings.
  • Mailbox permissions granted broadly (for example, full access to many mailboxes).
  • Audit log settings disabled or retention reduced.

Where the data lives

  • Entra ID audit logs: role assignments, app changes, policy changes.
  • Entra ID sign-in logs: admin sign-ins with location and device details.
  • Microsoft Defender XDR: alerts correlating identity, email and cloud app activity.
  • Unified audit log: Exchange and SharePoint admin actions.

A starting query

Alert when someone is added to a privileged role:

AuditLogs
| where OperationName == "Add member to role"
| extend Role = tostring(TargetResources[0].modifiedProperties[1].newValue)
| extend Actor = tostring(InitiatedBy.user.userPrincipalName)
| project TimeGenerated, Actor, Role, TargetResources

Review the role name field in your own tenant's data — the position in modifiedProperties can vary.

Response

  1. Confirm the change with the admin who made it, using an out-of-band channel.
  2. If unconfirmed, remove the role, revoke sessions and reset credentials.
  3. Review every change made by the account in the preceding days.
  4. Check for persistence: new apps, federation settings, mail forwarding rules.
detect compromised admin accountDeloitte email breach2017

More on this story