Entra ID & IdentityDetection & ResponseRetrospectives

Detecting Credential Stuffing Attacks: Entra Sign-In Logs and Sentinel KQL

By OnCloudSec Research Team · Published Oct 6, 2026 · 1 min read

Retrospective: this article looks back at events from December 2016, written in 2026 with the benefit of hindsight.

Credential stuffing uses username and password pairs leaked from other breaches to try to sign in to your Microsoft 365 tenant. Detection is about spotting many failed sign-ins spread across many accounts — and the occasional success hidden among them.

What it looks like

  • High volumes of failed sign-ins with "invalid username or password" across many users.
  • Attempts from a wide range of IP addresses, often residential proxies or hosting providers.
  • Sign-in attempts against accounts that do not exist or have been disabled.
  • A small number of successful sign-ins from the same infrastructure.

Where the data lives

Entra ID sign-in logs, streamed to Microsoft Sentinel or a Log Analytics workspace. Entra ID Protection also raises risk detections such as password spray and leaked credentials if you have Entra ID P2.

A starting query

This query surfaces IP addresses that failed sign-ins against many distinct accounts in an hour:

SigninLogs
| where ResultType == "50126"
| summarize Accounts = dcount(UserPrincipalName), Attempts = count()
    by IPAddress, bin(TimeGenerated, 1h)
| where Accounts > 10
| sort by Accounts desc

Then check for successful sign-ins (ResultType == "0") from the same IP addresses.

Tuning

Shared egress IPs — VPNs, proxies, mobile carriers — can look like attackers. Add known corporate IP ranges to a watchlist and exclude them.

Response

  1. Confirm whether any account succeeded and whether MFA was satisfied.
  2. Reset passwords and revoke sessions for affected accounts.
  3. Block the offending IP ranges if they are not legitimate.
  4. Most importantly, make sure MFA is enforced for everyone — then a correct password alone is not enough.
detect credential stuffing attacksYahoo breach2016

More on this story