signin_success_stats
Detect breached accounts by aggregating successful Entra sign-ins per source IP, surfacing shared IPs and legacy-protocol logins for investigation.
Instructions
Tenant-wide successful sign-in aggregation by source IP -- the view that finds a breach.
signin_failure_stats shows who is being attacked; this shows whether
anyone got in. The breach signature is one source IP signing in
successfully as several different accounts, most often over a legacy
protocol (clientAppUsed such as "Authenticated SMTP" or "IMAP4",
which carry no MFA). shared_ips lists the IPs with successes for
min_distinct_users or more distinct accounts, most-shared first (up
to 50 IPs, shared_ips_capped when more qualified; account names up
to 25 per IP), with the client apps and the countries seen.
legacy_auth_users lists the accounts that succeeded over a legacy
protocol at all, with how many IPs and countries they came from.
A campus NAT, a VDI farm or a shared proxy also puts many accounts
behind one IP, so a shared IP is a lead, not a verdict: the caller
excludes its own egress ranges and reads the client apps and countries
before calling anything a breach. Graph cannot filter sign-ins on
status/errorCode server-side, so like signin_failure_stats this
walks the sign-in log for the window and aggregates client-side. The
walk covers interactive sign-ins only (Graph's default listing): every
legacy-protocol authentication is logged as interactive, so none is
missed, but non-interactive token refreshes are not counted;
capped=true means the page budget or the deadline (ENTRAADM_DEADLINE,
default 45 s) ran out first and the counts are a lower bound -- narrow
hours for a full count.
Read-only (AuditLog.Read.All application permission, or -- for azure-cli auth -- the Reports Reader directory role).
Args:
hours: How far back to look, clamped to [1, 720] (30 days).
max_pages: Page budget (default: ENTRAADM_MAX_PAGES_DEFAULT).
min_distinct_users: Distinct accounts an IP needs to appear in
shared_ips (default 2, clamped to >= 2).
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| hours | No | ||
| max_pages | No | ||
| min_distinct_users | No |