Risky sign-ins are one of the most useful identity signals you can monitor in Microsoft Sentinel, especially if your environment is heavily dependent on Microsoft 365 and Entra ID for access. For UK SMEs, the value is not just in spotting suspicious logons. It is in getting enough context to decide quickly whether an account…
First seen on securityboulevard.com
Jump to article: securityboulevard.com/2026/08/kql-queries-for-detecting-risky-entra-id-sign-ins-in-sentinel/
![]()

