How to Monitor Entra ID for Cross-Tenant and Undocumented Token Abuse
Retrospective: this article looks back at events from September 2025, written in 2026 with the benefit of hindsight.
Cross-tenant and undocumented token flaws are rare but serious. Customers can't prevent provider bugs, but can reduce exposure and improve visibility. Here is how to monitor Entra ID for cross-tenant activity and legacy token use.
Step 1: Review cross-tenant access settings
In the Entra admin center under External Identities → Cross-tenant access settings:
- Review default inbound and outbound settings.
- Configure organization-specific settings for partners.
- Consider tenant restrictions v2 to control which external tenants your users can access.
Step 2: Retire Azure AD Graph dependencies
Microsoft has been retiring the legacy Azure AD Graph API. Identify applications in your tenant that still request Azure AD Graph permissions (resource 00000002-0000-0000-c000-000000000000 / Windows Azure Active Directory) and migrate them to Microsoft Graph.
Step 3: Monitor cross-tenant sign-ins
Entra sign-in logs include fields for the home tenant and resource tenant. Monitor:
- Users from external tenants signing in to your resources.
- Your users accessing external tenants (outbound).
Step 4: Monitor directory changes regardless of source
Because some provider-side flaws produce little sign-in evidence, monitor outcomes: new admin role assignments, new users, new app credentials, changes to Conditional Access and federation. These appear in audit logs even if the initial access is unusual.
Step 5: Use Microsoft Graph activity logs
Enable Microsoft Graph activity logs (via diagnostic settings) to record API requests to Microsoft Graph in your tenant, including the calling app and identity.
Step 6: Stay informed
Subscribe to Microsoft Security Response Center advisories and Entra "What's new" updates.
Verify
Confirm alerts exist for privileged changes and that Graph activity logs are flowing.
- Entra ID Actor Token Flaw (Sept 2025): A Cross-Tenant Global Admin Bug Incident Teardowns
- Detecting Cross-Tenant Token Abuse: Entra Sign-In Logs and Sentinel KQL Detection & Response
- CIO Brief: Even Identity Platforms Have Catastrophic Bugs CIO Briefings