A hardened Entra tenant still needs centralized visibility. Local retention limits and weak correlation leave long-lived identity attacks undetected.
Preface
Identity telemetry must be centralized, hunted, and acted on quickly. Local Entra logs alone are not enough against sophisticated operators.
Problem
Without SIEM correlation, teams may miss sequences such as password spray success followed by new application credential registration. That gap enables persistence and quiet exfiltration.
Solution
Align with NIST SP 800-86 and build a Sentinel hunting framework:
- Stream SignInLogs, AuditLogs, and NonInteractiveUserSignInLogs into Sentinel.
- Build KQL detections for anomalous admin actions, credential additions, and proxy-routed sign-ins.
- Automate response playbooks to disable accounts or revoke sessions on high-severity alerts.
KQL: Unauthorized Application Credential Additions
AuditLogs
| where OperationName has "Add owner to application" or OperationName has "Add service principal credential"
| extend TargetApp = tostring(TargetResources[0].displayName)
| extend InitiatedBy = tostring(InitiatedBy.user.userPrincipalName)
| project TimeGenerated, OperationName, TargetApp, InitiatedBy, ResultReason