Detecting MFA Fatigue Attacks: Entra Sign-In Logs and Sentinel KQL
Retrospective: this article looks back at events from March 2022, written in 2026 with the benefit of hindsight.
MFA fatigue attacks generate distinctive patterns: many MFA prompts, many denials, then sometimes an approval. Detecting them early lets you lock down the account before an attacker gets in.
Signals worth watching
- Multiple MFA push requests for one user within minutes.
- Repeated MFA denials followed by a successful approval.
- User reports of suspicious activity (Report suspicious activity feature).
- MFA prompts outside the user's working hours or from unusual locations.
- A help desk call from the "user" shortly after denials.
Where the data lives
- Entra ID sign-in logs: result codes and authentication details for MFA attempts (for example,
500121for failed strong authentication). - Entra ID Protection risk detections (including user-reported suspicious activity).
- Defender XDR alerts for suspicious MFA activity.
A starting query
Users with many failed MFA attempts followed by success:
SigninLogs
| where TimeGenerated > ago(1d)
| summarize Failures = countif(ResultType == "500121"), Successes = countif(ResultType == "0"),
FirstFail = minif(TimeGenerated, ResultType == "500121"), LastSuccess = maxif(TimeGenerated, ResultType == "0")
by UserPrincipalName, IPAddress
| where Failures >= 5 and Successes > 0 and LastSuccess > FirstFail
Response
- Treat as likely compromise: revoke sessions and reset credentials.
- Contact the user through a known channel.
- Review activity after the successful sign-in.
- Move the user to phishing-resistant MFA.