As cited
Citation snapshot as of .
identity access
Even MOAR Powershell, looking at Entra logins - the good, the bad and the password sprays
This tutorial demonstrates how to query Microsoft Entra sign-in logs using PowerShell to identify failed logins, password spray attacks, and unexpected geographic access patterns. The author provides specific commands to extract location data and failure reasons from audit logs, then filter results to highlight anomalous activity such as logins from unexpected countries or rotating proxy services.
Why it matters: Organizations using cloud-based identity systems should regularly audit their sign-in logs to detect password sprays and unauthorized access attempts; this guidance helps practitioners uncover attacks and tighten conditional access policies.
- Source published
- First seen by Cybersecurity Tracker