Microsoft 365Detection & ResponseRetrospectives

Detecting Password Spray Attacks: Defender XDR and Sentinel Hunting Queries

By OnCloudSec Research Team · Published Oct 6, 2026 · 1 min read

Retrospective: this article looks back at events from March 2019, written in 2026 with the benefit of hindsight.

Password spray attacks distribute attempts to avoid detection. Combining Entra ID's built-in detections with your own queries gives you the best chance of catching them.

Signals worth watching

  • Entra ID Protection Password spray risk detections.
  • Many failed sign-ins across many accounts from a small set of IPs.
  • Failures concentrated on a single application or protocol.
  • Smart lockout events (error code 50053) across several users.
  • Successful sign-ins from IPs involved in failures.

Where the data lives

  • SigninLogs and AADNonInteractiveUserSignInLogs in Sentinel.
  • AADUserRiskEvents for Identity Protection detections.
  • Defender XDR, which correlates identity alerts with email and endpoint signals.

A starting query: spray followed by success

let sprayIPs = SigninLogs
| where TimeGenerated > ago(1d) and ResultType == "50126"
| summarize Users = dcount(UserPrincipalName) by IPAddress
| where Users > 10
| project IPAddress;
SigninLogs
| where TimeGenerated > ago(1d) and ResultType == "0"
| where IPAddress in (sprayIPs)
| project TimeGenerated, UserPrincipalName, IPAddress, AppDisplayName, AuthenticationRequirement

Successful sign-ins where AuthenticationRequirement is single-factor deserve immediate attention.

Response

  1. Revoke sessions and reset passwords for accounts with successful sign-ins.
  2. Confirm MFA registration for those users.
  3. Block the source IPs if not legitimate.
  4. Review why single-factor sign-in was possible — usually a policy exclusion or legacy protocol.
detect password spray attacksCitrix password spraying2019

More on this story