Detecting Cross-Tenant Token Abuse: Entra Sign-In Logs and Sentinel KQL
Retrospective: this article looks back at events from September 2025, written in 2026 with the benefit of hindsight.
When identity platform flaws limit logging of the initial access, you can still detect what attackers do next. These detections focus on cross-tenant activity and privileged changes.
Signals worth watching
- Sign-ins where the home tenant differs from your tenant for accounts with privileged roles.
- Privileged changes (role assignments, new users, app credential additions) with unusual initiators, missing initiator details or unfamiliar app IDs.
- Microsoft Graph or Azure AD Graph API calls from unfamiliar applications.
- Changes to cross-tenant access settings.
Where the data lives
- Entra ID sign-in logs (
HomeTenantId,ResourceTenantId,CrossTenantAccessType). - Entra ID audit logs.
- Microsoft Graph activity logs (
MicrosoftGraphActivityLogstable).
A starting query
Cross-tenant sign-ins to your tenant:
SigninLogs
| where HomeTenantId != ResourceTenantId
| summarize Count = count() by HomeTenantId, UserPrincipalName, AppDisplayName, CrossTenantAccessType
| sort by Count desc
Privileged audit events with unusual initiators:
AuditLogs
| where OperationName in ("Add member to role", "Add user", "Add service principal credentials",
"Update conditional access policy", "Set federation settings on domain")
| extend InitiatorUPN = tostring(InitiatedBy.user.userPrincipalName), InitiatorApp = tostring(InitiatedBy.app.displayName)
| where isempty(InitiatorUPN) and isempty(InitiatorApp) or InitiatorApp !in ("Your-Known-Automation-App")
| project TimeGenerated, OperationName, InitiatedBy, TargetResources
Response
- Validate any unexplained privileged change immediately.
- Revert unauthorized changes and investigate.
- Engage Microsoft support if you suspect a platform-level issue.
- Entra ID Actor Token Flaw (Sept 2025): A Cross-Tenant Global Admin Bug Incident Teardowns
- How to Monitor Entra ID for Cross-Tenant and Undocumented Token Abuse How-To & Hardening
- CIO Brief: Even Identity Platforms Have Catastrophic Bugs CIO Briefings