Entra ID & IdentityDetection & ResponseRetrospectives

Detecting SMS MFA Interception: Entra Sign-In Logs and Sentinel KQL

By OnCloudSec Research Team · Published Oct 6, 2026 · 1 min read

Retrospective: this article looks back at events from August 2018, written in 2026 with the benefit of hindsight.

SMS codes can be intercepted through SIM swaps and phishing. You often can't see the interception itself, but you can detect what happens next: a sign-in that passes MFA but doesn't look like the real user.

Signals worth watching

  • A successful sign-in satisfying MFA via SMS from a new country, device or network.
  • A user's phone number changed in their authentication methods, followed by sign-ins.
  • MFA registration changes followed quickly by access to sensitive resources.
  • Help desk password resets followed by sign-ins from unfamiliar locations.

Where the data lives

  • Entra ID sign-in logs: the AuthenticationDetails field shows which method satisfied MFA.
  • Entra ID audit logs: "User registered security info," "User changed default security info" and admin changes to authentication methods.
  • Entra ID Protection risk detections for unfamiliar sign-in properties.

A starting query

Find recent phone number changes to a user's security info:

AuditLogs
| where OperationName in ("User registered security info", "User changed default security info",
    "Admin updated security info")
| extend User = tostring(TargetResources[0].userPrincipalName)
| project TimeGenerated, OperationName, User, InitiatedBy, Result

Correlate with sign-ins for the same user in the following 24 hours from new locations.

Response

  1. Contact the user through a known channel to confirm the change.
  2. If unconfirmed, revoke sessions, remove the phone method and reset credentials.
  3. Check mailbox rules and data access during the suspicious window.
  4. Move the user to app-based or phishing-resistant MFA.
detect sms mfa interceptionReddit SMS 2FA2018

More on this story