Detecting Password Spray Attacks: Defender XDR and Sentinel Hunting Queries
Retrospective: this article looks back at events from March 2019, written in 2026 with the benefit of hindsight.
Password spray attacks distribute attempts to avoid detection. Combining Entra ID's built-in detections with your own queries gives you the best chance of catching them.
Signals worth watching
- Entra ID Protection Password spray risk detections.
- Many failed sign-ins across many accounts from a small set of IPs.
- Failures concentrated on a single application or protocol.
- Smart lockout events (error code 50053) across several users.
- Successful sign-ins from IPs involved in failures.
Where the data lives
SigninLogsandAADNonInteractiveUserSignInLogsin Sentinel.AADUserRiskEventsfor Identity Protection detections.- Defender XDR, which correlates identity alerts with email and endpoint signals.
A starting query: spray followed by success
let sprayIPs = SigninLogs
| where TimeGenerated > ago(1d) and ResultType == "50126"
| summarize Users = dcount(UserPrincipalName) by IPAddress
| where Users > 10
| project IPAddress;
SigninLogs
| where TimeGenerated > ago(1d) and ResultType == "0"
| where IPAddress in (sprayIPs)
| project TimeGenerated, UserPrincipalName, IPAddress, AppDisplayName, AuthenticationRequirement
Successful sign-ins where AuthenticationRequirement is single-factor deserve immediate attention.
Response
- Revoke sessions and reset passwords for accounts with successful sign-ins.
- Confirm MFA registration for those users.
- Block the source IPs if not legitimate.
- Review why single-factor sign-in was possible — usually a policy exclusion or legacy protocol.