Skip to content
Threat Feed

Product

Microsoft Entra ID

32 briefs RSS
high threat

Monitoring High-Risk Sign-ins in Microsoft Entra ID

This brief details the detection of compromised cloud accounts by leveraging Microsoft Identity Protection telemetry to identify high-risk authentication events indicative of credential abuse.

exploited Microsoft Entra ID +3 cloud identity account-compromise
1r 1t
high advisory

Microsoft Security Updates — July 2026

Roundup of Microsoft security advisories published in July 2026.

PoC PowerShell +511 roundup
11c 354i updated
medium advisory

Microsoft Entra ID Guest Account Promoted to Member

A sophisticated threat actor, having compromised an existing guest account in Microsoft Entra ID, can establish persistent access and elevate privileges by performing a Guest-to-Member account conversion, which grants full directory read access and bypasses Conditional Access restrictions, enabling stealthy long-term access and reconnaissance.

Microsoft Entra ID cloud identity persistence azure microsoft-entra-id
1r 1t
high advisory

Microsoft Entra ID Temporary Access Pass (TAP) Abuse for MFA Bypass and Persistence

An attacker with elevated privileges abuses the Microsoft Entra ID Temporary Access Pass (TAP) feature to bypass multi-factor authentication (MFA), gain unauthorized access to target user accounts, and establish persistence by registering new authentication methods.

Microsoft Entra ID cloud identity azure entra-id mfa-bypass persistence lateral-movement initial-access
3r 2t
high advisory

Microsoft 365 OAuth Device Code Phishing Exploits Non-Compliant Devices

Attackers are actively exploiting the OAuth device code flow in Microsoft 365 to bypass multi-factor authentication (MFA) and gain initial access, leveraging phishing kits like Kali365 and tradecraft similar to Storm-2372 to harvest MFA-satisfied tokens from non-compliant or attacker-controlled devices, and subsequently establishing persistence through device registration.

Microsoft 365 +4 cloud saas identity microsoft-365 initial-access phishing persistence
2r 3t
high advisory

Entra ID Microsoft Authentication Broker DRS Sign-In from Suspicious ASN

Detects Microsoft Entra ID sign-in activity where the Microsoft Authentication Broker requests the Device Registration Service from a suspicious ASN, indicating potential OAuth phishing or adversary-in-the-middle device registration.

Microsoft Entra ID cloud identity azure entra_id sign-in_logs threat_detection initial_access persistence +1
2r 3t
high threat

Storm-2949 Abuses SSPR for Cloud-Wide Data Exfiltration

Storm-2949 compromised cloud identities through social engineering and abused the Self-Service Password Reset (SSPR) process to bypass MFA and gain persistent access, enabling lateral movement and data exfiltration from Microsoft 365 and Azure environments.

Microsoft Entra ID +3 Storm-2949 cloud-security credential-access data-exfiltration social-engineering
2r 6t
medium advisory

Tycoon2FA AiTM Phishing via Microsoft Entra ID Sign-Ins

Detects Microsoft Entra ID sign-ins consistent with Tycoon2FA phishing-as-a-service (PhaaS) adversary-in-the-middle (AiTM) activity targeting Microsoft 365 and Gmail, where the Microsoft Authentication Broker requests tokens for Microsoft Graph or Exchange Online, or the Office web client application authenticates to itself, combined with Node.js-style user agents (node, axios, undici).

Microsoft Entra ID +3 tycoon2fa aitm entra_id phishing credential_access
2r 2t
medium advisory

Entra ID Sign-in Brute Force Attempt Against Microsoft 365

A high volume of failed Microsoft Entra ID sign-in attempts against Microsoft 365 services within a short time period indicates a potential brute-force attack, which could lead to unauthorized access to Microsoft 365 services.

Microsoft 365 +4 azure entra-id microsoft-365 brute-force credential-access
2r 1t
medium advisory

M365 Identity Login from Atypical Travel Location

This rule detects successful Microsoft 365 portal logins from rare locations, potentially indicating an adversary attempting to access an account from an unusual location or behind a VPN.

Microsoft 365 +1 cloud identity o365 initial-access
2r 1t
high advisory

Entra ID OAuth Phishing via Auth Broker to DRS

Detection of OAuth phishing in Microsoft Entra ID through Microsoft Authentication Broker (MAB) and Device Registration Service (DRS) indicated by the same user principal and session ID originating from multiple IP addresses within a short timeframe, indicative of unauthorized token acquisition.

Microsoft Entra ID +3 entra-id oauth-phishing initial-access
2r 1t 2i
low advisory

Entra ID Service Principal Creation for Persistence

An adversary may create a new service principal in Microsoft Entra ID to establish persistence and potentially impersonate legitimate services or applications, blending in with normal activity.

Microsoft Entra ID +1 azure entra_id service_principal persistence
2r 1t
high advisory

Entra ID Privilege Escalation to User Access Administrator

A user has elevated their access to User Access Administrator for their Azure Resources, potentially leading to privilege escalation and unauthorized access; this activity is flagged only if the user hasn't performed it in the last 14 days.

Microsoft Azure +1 azure entra_id privilege_escalation
2r 2t
high advisory

Multiple Entra ID Protection Alerts Indicate Potential Account Compromise

Multiple Microsoft Entra ID Protection alerts associated with a single user in a short timeframe may indicate an ongoing attack or compromised account, stemming from suspicious sign-in activity such as anomalous IP addresses or risky sign-ins.

Microsoft Entra ID cloud azure entra_id identity_protection
2r 3t
high advisory

Entra ID OAuth Device Code Flow Phishing

Attackers are leveraging device code phishing to steal application access tokens from users of Entra ID OAuth applications, by tricking users into entering codes into attacker-controlled polling clients, leading to unauthorized access to cloud resources.

Microsoft Entra ID +2 entra-id oauth device-code-phishing credential-access
2r 3t
high advisory

Entra ID Protection Alert Followed by Device Registration

Detection of a Microsoft Entra ID protection alert followed by a new device registration attempt by the same user, potentially indicating account compromise and unauthorized device registration for persistence.

Microsoft Entra ID +1 azure entra_id persistence device_registration
2r 2t
medium threat

Entra ID Unusual ROPC Login Attempt

Detects unusual resource owner password credential (ROPC) login attempts by a user principal in Microsoft Entra ID, potentially indicating account compromise or password spraying.

exploited Microsoft Entra ID azure entra-id ropc initial-access
2r 2t
medium advisory

BloodHound Suite User-Agent Detected in Entra ID Sign-ins

Detection of BloodHound tools like AzureHound and SharpHound being used to enumerate Microsoft Entra ID and Microsoft 365 environments, potentially indicating reconnaissance activity by red teams or malicious actors.

Microsoft Azure +2 azuread bloodhound enumeration discovery
3r 6t
medium advisory

Entra ID Illicit Consent Grant via Registered Application

Attackers register malicious applications within Entra ID and deceive users into granting extensive permissions through OAuth consent, enabling unauthorized access to sensitive data like emails and files.

Microsoft Entra ID azure entra-id oauth illicit-consent
2r 3t
medium advisory

Entra ID Service Principal Sign-in from Unusual Source ASN

Detects Entra ID service principal sign-ins from a source ASN that is unusual based on a history window, potentially indicating compromised credentials or a rogue application.

Microsoft Entra ID azure entra_id service_principal initial_access
2r 2t
medium advisory

Entra ID OAuth User Impersonation to Microsoft Graph

Detects potential session hijacking or token replay in Microsoft Entra ID, where a user signs in and subsequently accesses Microsoft Graph from a different IP address using the same session ID, indicating a successful OAuth phishing attack, session hijacking, or token replay attack.

Microsoft Entra ID +2 azure entra_id oauth graph_api token_replay session_hijacking initial_access defense_evasion
2r 2t
medium advisory

TeamFiltration Tool User-Agent Detected in Entra ID Sign-ins

The TeamFiltration tool, used for Entra ID and Microsoft 365 enumeration and password spraying, is detected via specific user-agent strings in sign-in logs.

Microsoft Entra ID +2 azure o365 teamfiltration credential-access
2r 7t 1i
medium advisory

M365 Identity OAuth Illicit Consent Grant by Rare Client and User

Adversaries may register a malicious application in Microsoft Entra ID and trick users into granting excessive permissions via OAuth consent, allowing the malicious application to access resources in Microsoft 365 on behalf of the user, potentially leading to data exfiltration.

Microsoft 365 +2 o365 oauth consent-grant phishing initial-access
2r 3t
critical advisory

Entra ID Protection Admin Confirmed Compromise

An administrator's confirmation of a compromised user or sign-in in Microsoft Entra ID Protection signals a high-confidence account compromise requiring immediate investigation and remediation.

Microsoft Entra ID azure entra_id identity_protection compromised_account
3r 3t
high advisory

Entra ID Protection - Sign-in Risk Detection

This brief covers detection of sign-in risk events identified by Microsoft Entra ID Protection, including anonymized IP addresses, unlikely travel, and password spray attacks, which can indicate compromised accounts or malicious activity.

Microsoft Entra ID +1 azure entra-id identity-protection sign-in-risk initial-access
3r 4t
medium advisory

Entra ID OAuth Authorization Code Grant for Unusual User, App, and Resource

Detects the first-time use of an OAuth 2.0 authorization code grant flow for a specific combination of user, application, and resource in Microsoft Entra ID, potentially indicating OAuth phishing attacks like ConsentFix, where attackers steal authorization codes.

Microsoft Entra ID +2 entra-id oauth phishing initial-access
2r 3t
low advisory

Entra ID Custom Domain Added or Verified

Detection of custom domain additions or verifications in Entra ID, a precursor to potentially malicious domain federation for Golden SAML attacks.

Microsoft Entra ID azure entra-id domain-federation golden-saml
2r 1t
high advisory

Azure AD Admin Consent Bypassed by Service Principal

A service principal in Azure Active Directory is assigning app roles without standard admin consent, potentially leading to unauthorized privilege escalation by exploiting automation to assign sensitive permissions without proper oversight.

Azure Active Directory +1 azuread admin-consent service-principal privilege-escalation
2r 1t
medium advisory

Unusual Microsoft Graph Email Access via OAuth Application

An adversary might use a phished OAuth refresh token or Primary Refresh Token (PRT) with a first-party application to access email resources via Microsoft Graph API, particularly focusing on unusual application and user combinations.

Microsoft Graph API +2 azure graphapi oauth email
2r 2t
high advisory

Entra ID High Risk Sign-in Detected

This rule detects high-risk sign-ins in Microsoft Entra ID, as identified by Identity Protection, where the sign-in is flagged with a risk level of `high` during the authentication process, indicating a strong likelihood of account compromise.

Microsoft Entra ID azure entra_id initial_access high_risk_signin
2r 1t
low advisory

Entra ID User Sign-in with Unusual Non-Managed Device

Detects Microsoft Entra ID user sign-ins from devices not typically used or managed, indicating potential account compromise or unauthorized access via device registration for persistence.

Microsoft Entra ID azure entra-id persistence device-registration
2r 2t
medium advisory

Entra ID Conditional Access Policy (CAP) Modified

An adversary may modify existing Conditional Access Policies (CAPs) in Microsoft Entra ID to weaken access controls and maintain persistence in the environment with a compromised identity.

Microsoft Entra ID azure entra_id conditional_access_policy persistence defense_evasion
2r 2t