Plan
active
PowerShell guide for auditing Entra ID login logs and detecting password sprays
- Engineer — Learn: Practical reminder that cloud identity login logs (Entra ID sign-in logs) deserve the same daily scrutiny as on-prem logs; useful if you haven’t wired these into a monitoring workflow yet, but no patch or config change required.
- SOC/IR — Plan: Adopt or adapt the PowerShell queries shown to pull Entra successful/failed login data for routine password-spray hunting; worth scheduling as a log-source coverage improvement if Entra sign-in logs aren’t already feeding your SIEM.
- Leader — Skip
This entry was curated and judged by AI (Claude) with automated enrichment
(CISA KEV / EPSS / public PoC). Verify against the original source before
acting. Found a bad verdict?
Report it —
confirmed errors go to the corrections log.