Entra ID & IdentityDetection & ResponseNews

Detecting Suspicious Activity From SSO-Connected Third-Party Platforms

By OnCloudSec Research Team · Published Oct 6, 2026 · 1 min read

Weaknesses in third-party platforms connected to your SSO can let attackers gain access as employees. These detections help spot misuse.

Signals worth watching

  • New accounts on connected platforms claiming company email addresses without SSO.
  • Email address changes to company domains on community or support platforms.
  • Privilege grants (moderator, staff, admin) on connected platforms outside normal processes.
  • SSO sign-ins to connected apps from unusual IPs or devices.
  • Requests to the platform's authentication endpoints with malformed or unusual assertions (in platform or WAF logs).

Where the data lives

  • Connected platform audit logs (admin actions, account changes).
  • Entra ID sign-in logs for SSO-integrated apps.
  • WAF and web server logs for self-hosted platforms.
  • Defender for Cloud Apps for supported SaaS.

A starting query

Sign-ins to SSO-connected community and support apps from new countries:

SigninLogs
| where AppDisplayName has_any ("Discourse", "Community", "Support", "Zendesk", "Docs")
| where ResultType == "0"
| summarize Countries = make_set(Location, 10), Count = count() by UserPrincipalName, AppDisplayName, bin(TimeGenerated, 1d)
| where array_length(Countries) > 1

Adjust app names to your environment.

Platform-side checks

Export admin and role-change logs from each platform weekly (or via API to your SIEM) and alert on new staff or admin assignments.

Response

  1. Remove unauthorized privileges and accounts.
  2. Review content and data accessed.
  3. Patch the platform and fix validation logic.
  4. Check for access to connected internal systems.

Sources

  1. Source
detect sso-connected third-party platform abuseHacktron breaks into OpenAI2026

More on this story