The New MFA Method Was Registered 11 Minutes After the Login
The sign-in was successful.
The password worked. MFA was satisfied. Nothing in the first few minutes looked dramatic.
Eleven minutes later, the account registered a new authentication method.
That second event changed the meaning of the first.
Agent Foskett stopped treating them as separate records and started building a timeline.

Identity Compromise Investigation
The sign-in looked ordinary. The timeline did not.
The first event did not look like a compromise
The timeline changed the investigation
- 1
- 2
- 3
- 4
- 5
- 6
- 7
- 8
02:03 Successful sign-in 02:07 New session activity 02:14 Authentication method registered 02:16 Account signs in again Question: Who controlled the account at 02:14?
Start with the sign-in evidence
- 1
- 2
- 3
- 4
- 5
- 6
- 7
- 8
- 9
IdentityLogonEvents
| where Timestamp > ago(7d)
| where AccountUpn =~ "alex.morgan@contoso.com"
| project Timestamp, AccountUpn, ActionType,
Application, IPAddress, Location, DeviceName
| order by Timestamp ascLook for authentication-method changes
- 1
- 2
- 3
- 4
- 5
- 6
- 7
- 8
- 9
- 10
AuditLogs
| where TimeGenerated > ago(7d)
| where Category =~ "UserManagement"
| where OperationName has_any ("authentication method", "security info")
| where tostring(TargetResources) has "alex.morgan@contoso.com"
| project TimeGenerated, OperationName, Result,
InitiatedBy, TargetResources, AdditionalDetails
| order by TimeGenerated ascDiscover the exact operations in your tenant
- 1
- 2
- 3
- 4
- 5
- 6
- 7
AuditLogs
| where TimeGenerated > ago(30d)
| where Category =~ "UserManagement"
| where OperationName has_any ("authentication", "security info", "MFA")
| summarize Events = count() by OperationName
| order by Events desc
