isc.sans.edu 8/21/2026, 3:51:28 AM · external

PowerShell tips to spot Azure login attacks after cloud migration

PowerShell tips to spot Azure login attacks after cloud migration
CyberSIXT Evidence Panel Source marked as original reporting

THE article, authored by Rob VandenBrink, emphasizes the importance of reviewing login logs after migrating to cloud services. It discusses the use of PowerShell commands to analyze both successful and failed logins in Microsoft Entra. Key points include:

1. The necessity of examining Azure login logs, especially after moving to the cloud, to identify security issues like password spray attacks.

2. Instructions for using PowerShell commands to filter logs for failed logins and extract geo-location details to diagnose issues.

3. Highlighting the presence of unexpected successful logins from unauthorized countries and recommending adjustments to conditional access policies based on findings.

The overall guidance is to actively monitor logs to strengthen security postures against potential threats.

View full article

Article by CyberSIXT