Agent Foskett Investigation • Microsoft Entra • Identity Security • Zero Trust

The Sign-in Was Successful... So Everyone Moved On

The password was correct.

MFA was approved.

Conditional Access allowed the session.

There were no failed logons and no obvious alerts.

Everything looked normal.

Nobody investigated what happened afterwards.

Agent Foskett investigating a successful Microsoft Entra sign-in and the suspicious identity activity that followed
Identity Investigation

The sign-in succeeded. The behaviour that followed did not belong.

Build the complete sign-in timeline
Correlate authentication with later activity
Investigate behaviour, not only failure

Authentication succeeded

Every control appeared to work exactly as expected.
Valid credentialsThe username and password were accepted without a failed authentication event.
MFA approvedThe second authentication factor completed successfully and the user received access.
Conditional Access passedThe policy evaluation allowed the session because the configured grant controls were satisfied.

The investigation almost ended there

A successful sign-in is often treated as proof that the activity was legitimate. It is only proof that the authentication requirements were satisfied.
No obvious failureThere was no brute-force pattern, password spray or repeated authentication failure to attract attention.
No immediate alertThe first event appeared ordinary because the attacker used a valid session rather than noisy malware.
The wrong stopping pointThe authentication result was reviewed, but the post-authentication behaviour was not.

What happened next

The activity after authentication transformed a normal-looking sign-in into an identity compromise investigation.
identity-timeline.txt
  1. 1
  2. 2
  3. 3
  4. 4
  5. 5
  6. 6
  7. 7
  8. 8
  9. 9
08:47  Successful Microsoft Entra sign-in
08:53  SharePoint accessed
09:02  312 files downloaded
09:04  OneDrive opened
09:07  New authentication method added
09:11  Consent granted to an enterprise application
09:15  Global Administrator role assigned

Microsoft Entra told the identity story

The investigation required more than the final sign-in status.
Sign-in LogsShowed the account, location, IP address, device information, application and session result.
Authentication DetailsRevealed which methods were used, whether MFA was satisfied and how the session met the authentication requirement.
Conditional AccessConfirmed which policies were evaluated, which controls applied and why access was granted.
Risky Sign-insAdded identity risk signals that may not have blocked the session but still changed the investigation priority.
Audit LogsRecorded authentication-method changes, role assignments, enterprise application consent and other directory activity.
Authentication MethodsHelped determine whether a new factor had been registered to maintain access after the initial compromise.

Microsoft Defender completed the investigation

Identity telemetry explained the session. Defender activity showed what the session was used to do.
Mailbox accessReview email activity, message actions, inbox-rule changes and suspicious use of Exchange Online.
SharePoint and OneDriveIdentify abnormal file access, large downloads and sensitive content viewed after authentication.
Endpoint telemetryDetermine whether the session came from the expected device and whether related process, network or file activity existed.

Why attackers prefer successful authentication

The quietest attack path is the one that satisfies the controls already in place.
No brute force requiredStolen credentials remove the need for repeated failed attempts that would normally trigger detection.
No malware requiredCloud services can be abused directly through a valid browser session and legitimate applications.
No obvious failureThe controls report success while the attacker continues operating inside the trusted session.

Agent Foskett's investigation mindset

Do not end the investigation with the authentication result.
Do not ask only: Did authentication fail?A successful sign-in can still be the beginning of a compromise.
Ask: What happened afterwards?Follow access into files, mailboxes, enterprise applications, roles and authentication methods.
Ask: Should the session have continued?Evaluate whether risk, device state, location, privilege and behaviour justified continued access.

The investigation timeline

The sign-in was only the first event in a much larger identity story.
08:47 — Sign-in succeedsValid credentials, MFA and Conditional Access produce a successful authentication result.
09:02 — Data access expandsSharePoint and OneDrive activity moves beyond the user's normal pattern.
09:07 — Persistence beginsA new authentication method is added to preserve future access.
09:11 — Application consent changesAn enterprise application receives permissions that extend the attacker's reach.
09:15 — Privilege increasesThe account receives a privileged role and the impact of the compromise expands.
09:17 — Investigation startsThe successful sign-in is finally reviewed as the beginning of the incident rather than the end.

What administrators should verify

A successful sign-in should be reviewed in the context of identity risk, privilege and subsequent cloud activity.
Review the complete sign-in recordCheck location, device, application, authentication details, Conditional Access and risk—not only the final status.
Review directory changesLook for new authentication methods, role assignments, consent grants and account changes after the sign-in.
Review resource accessCorrelate the identity with Exchange, SharePoint, OneDrive, Teams and endpoint telemetry.

Investigation findings

The successful sign-in did not prove that the session was legitimate.
The controls workedThe session satisfied the authentication and access requirements that had been configured.
The identity was still compromisedValid authentication did not make the later activity normal, expected or safe.
The behaviour revealed the incidentThe investigation was proven by the post-authentication timeline, not by a failed login.
Authentication is not the end of the investigation.
Follow the identity, the privilege and the behaviour that came afterwards.
Visit the Entra Academy

Final thought

Modern attacks do not always begin with a failed login. Sometimes they begin with a successful one.
The sign-in succeededThe configured authentication and access controls returned a successful result.
The investigation continuedThe real evidence appeared in what the identity accessed, changed and became afterwards.
Zero Trust kept askingSuccessful authentication did not remove the need to continuously verify the session.
Develop IT. Protect IT.
GEMXIT PTY LTD | GEMXIT UK LTD
Talk to GEMXIT

The Sign-in Was Successful So Everyone Moved On

This Agent Foskett investigation examines a successful Microsoft Entra sign-in where valid credentials, MFA and Conditional Access all allowed access. The incident became visible only after investigators correlated the sign-in with later SharePoint, OneDrive, authentication-method, enterprise application and privileged-role activity.

Microsoft Entra Sign-in Logs And Identity Investigation

The investigation explains how Sign-in Logs, Authentication Details, Conditional Access results, Risky Sign-ins, Audit Logs and Authentication Methods can be combined to build the complete post-authentication timeline.

Zero Trust And Successful Authentication

GEMXIT helps organisations investigate Microsoft Entra identity threats, successful sign-ins, MFA activity, Conditional Access, risky users, privileged access, enterprise applications and Microsoft Defender telemetry.