Detecting Remote Access Without MFA: Sentinel and GuardDuty Detections
Retrospective: this article looks back at events from February 2024, written in 2026 with the benefit of hindsight.
Remote access without MFA is a top ransomware entry point. These detections look for single-factor access and the activity that typically follows.
Signals worth watching
- Successful remote access logins where MFA wasn't required or performed.
- Remote access from unusual countries, hosting providers or anonymizing networks.
- Logins by accounts that haven't used remote access before.
- New remote access sessions followed by internal reconnaissance (network scanning, AD enumeration), RDP to many hosts or use of admin tools.
- Logins outside normal hours.
Where the data lives
- Gateway logs (Citrix, VPN) forwarded to Sentinel via Syslog/CEF or vendor connectors.
- Entra ID sign-in logs (if integrated).
- Endpoint telemetry for post-login activity.
- Active Directory logs.
A starting query
Single-factor sign-ins to remote access apps integrated with Entra ID:
SigninLogs
| where ResultType == "0"
| where AppDisplayName has_any ("Citrix", "VPN", "Gateway", "Remote")
| where AuthenticationRequirement == "singleFactorAuthentication"
| project TimeGenerated, UserPrincipalName, AppDisplayName, IPAddress, Location, ConditionalAccessStatus
Post-login reconnaissance
DeviceProcessEvents
| where ProcessCommandLine has_any ("nltest /domain_trusts", "net group \"domain admins\"", "AdFind", "Get-ADComputer")
| project Timestamp, DeviceName, AccountName, ProcessCommandLine
Response
- Terminate sessions and disable affected accounts.
- Enforce MFA on the portal immediately.
- Hunt for lateral movement and ransomware staging.
- Engage incident response if reconnaissance or credential theft is confirmed.
- Change Healthcare (Feb 2024): A Citrix Portal Without MFA and a Health System Outage Incident Teardowns
- How to Enforce MFA on Every Remote Access Portal How-To & Hardening
- CIO Brief: Change Healthcare and the Systemic Risk of One Missing Control CIO Briefings