Entra ID & IdentityDetection & ResponseRetrospectives

Detecting MFA Fatigue Attacks: Entra Sign-In Logs and Sentinel KQL

By OnCloudSec Research Team · Published Oct 6, 2026 · 1 min read

Retrospective: this article looks back at events from March 2022, written in 2026 with the benefit of hindsight.

MFA fatigue attacks generate distinctive patterns: many MFA prompts, many denials, then sometimes an approval. Detecting them early lets you lock down the account before an attacker gets in.

Signals worth watching

  • Multiple MFA push requests for one user within minutes.
  • Repeated MFA denials followed by a successful approval.
  • User reports of suspicious activity (Report suspicious activity feature).
  • MFA prompts outside the user's working hours or from unusual locations.
  • A help desk call from the "user" shortly after denials.

Where the data lives

  • Entra ID sign-in logs: result codes and authentication details for MFA attempts (for example, 500121 for failed strong authentication).
  • Entra ID Protection risk detections (including user-reported suspicious activity).
  • Defender XDR alerts for suspicious MFA activity.

A starting query

Users with many failed MFA attempts followed by success:

SigninLogs
| where TimeGenerated > ago(1d)
| summarize Failures = countif(ResultType == "500121"), Successes = countif(ResultType == "0"),
    FirstFail = minif(TimeGenerated, ResultType == "500121"), LastSuccess = maxif(TimeGenerated, ResultType == "0")
    by UserPrincipalName, IPAddress
| where Failures >= 5 and Successes > 0 and LastSuccess > FirstFail

Response

  1. Treat as likely compromise: revoke sessions and reset credentials.
  2. Contact the user through a known channel.
  3. Review activity after the successful sign-in.
  4. Move the user to phishing-resistant MFA.
detect mfa fatigue attacksLapsus$2022

More on this story