Anomalous sign-in location by user account and authenticating application
Description
'This query examines Microsoft Entra ID sign-ins for each application and identifies the most anomalous change in a user's location profile. The goal is to detect user account compromise, possibly via a specific application vector.'
Query · kql
SigninLogs // Forces Log Analytics to recognize that the query should be run over full time range | extend locationString= strcat(tostring(LocationDetails["countryOrRegion"]), "/", tostring(LocationDetails["state"]), "/", tostring(LocationDetails["city"]), ";") | project TimeGenerated, AppDisplayName, UserPrincipalName, locationString // Create time series | make-series dLocationCount = dcount(locationString) on TimeGenerated step 1d by UserPrincipalName, AppDisplayName // Compute best fit line for each entry | extend (RSquare, Slope, Variance, RVariance, Interception, LineFit) = series_fit_line(dLocationCount) // Chart the 3 most interesting lines // A 0-value slope corresponds to an account being completely stable over time for a given Azure Active Directory application | top 3 by Slope desc | extend timestamp = TimeGenerated, AccountCustomEntity = UserPrincipalName | render timechart