Executive Summary
Security researchers at SANS Internet Storm Center have documented widespread password spray attacks targeting Microsoft Entra ID (formerly Azure AD) environments, with attackers systematically attempting authentication against multiple user accounts using common passwords. The attacks, detected through PowerShell-based log analysis of Entra ID audit logs, showed attackers leveraging rotating proxy services to evade IP-based blocking while targeting organizations that had migrated to cloud services but failed to implement proper monitoring. Multiple organizations were found to have inadequate conditional access policies, allowing attackers to probe authentication systems from unexpected geographic locations and compromise accounts through credential stuffing techniques.
This incident highlights the critical gap many organizations face when transitioning to cloud infrastructure - abandoning the rigorous log monitoring practices they maintained for on-premises systems, creating blind spots that attackers actively exploit through automated credential attacks.
Why This Matters Now
With the accelerated cloud migration post-pandemic, organizations are increasingly vulnerable to credential attacks as they often neglect proper audit log monitoring in cloud environments, while threat actors have industrialized password spray campaigns using sophisticated proxy rotation techniques.
Attack Path Analysis
Attackers conducted credential-based attacks against Entra ID environments through password spraying and rotating proxy services to bypass geographic restrictions. They leveraged successful authentication from unexpected countries and potentially compromised accounts to establish persistence. Lateral movement occurred through authenticated sessions across cloud services and resources. Command and control was maintained through legitimate cloud channels and possibly IPv6 connections to evade detection. Data exfiltration likely occurred through authorized cloud service access using compromised credentials. Impact included unauthorized access to organizational resources and potential data exposure.
Kill Chain Progression
This analysis maps confirmed threat intelligence to the full cloud kill chain to show where defensive gaps would emerge as an attack progresses.
Initial Compromise
Description
Password spray attacks conducted against Entra ID using rotating proxy services to bypass conditional access policies and geographic restrictions
MITRE ATT&CK® Techniques
Brute Force
Password Spraying
Valid Accounts
Cloud Accounts
Exploit Public-Facing Application
Cloud Accounts
Disable or Modify Cloud Firewall
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
CISA Zero Trust Maturity Model 2.0 – Identity and Access Management
Control ID: ID.AM-2
NYDFS 23 NYCRR 500 – Multi-Factor Authentication
Control ID: 500.12
PCI DSS 4.0 – Authentication Policies and Procedures
Control ID: 8.2.4
DORA – Identification and Classification of ICT Risk
Control ID: Article 8
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21.2(a)
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Financial Services
Password spray attacks against Entra logins pose critical risks to financial authentication systems, requiring enhanced conditional access policies and geographic login restrictions.
Health Care / Life Sciences
Failed authentication monitoring essential for HIPAA compliance; geographic anomaly detection prevents unauthorized access to patient data through credential attacks.
Government Administration
Entra login monitoring critical for detecting state-sponsored credential attacks from unexpected countries, requiring zero trust segmentation and enhanced visibility controls.
Information Technology/IT
IT sectors must implement comprehensive audit log analysis and conditional access policies to prevent credential attacks targeting cloud authentication infrastructures.
Sources
- Even MOAR Powershell, looking at Entra logins - the good, the bad and the password sprays, (Fri, Aug 21st)https://isc.sans.edu/diary/rss/33268Verified
- CISA Alert AA22-174A: Russian State-Sponsored and Criminal Cyber Threats to Critical Infrastructurehttps://www.cisa.gov/news-events/cybersecurity-advisories/aa22-174aVerified
- Microsoft Identity and access management security best practiceshttps://docs.microsoft.com/en-us/azure/security/fundamentals/identity-management-best-practicesVerified
- NIST Special Publication 800-63B: Authentication and Lifecycle Managementhttps://pages.nist.gov/800-63-3/sp800-63b.htmlVerified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.
Aviatrix Zero Trust CNSF would constrain this credential-based attack through segmented access controls and east-west traffic enforcement. Multi-stage segmentation would likely reduce attacker blast radius across cloud services even with compromised credentials.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: Network-level segmentation would likely constrain authenticated attacker reach to specific cloud resource segments rather than broad organizational access
Control: Zero Trust Segmentation
Mitigation: Segmentation policies would likely restrict privilege escalation paths by constraining access between cloud service tiers and administrative boundaries
Control: East-West Traffic Security
Mitigation: East-west traffic controls would likely constrain lateral movement between cloud workloads and reduce reachable asset scope within the environment
Control: Multicloud Visibility & Control
Mitigation: Multicloud visibility would likely constrain command channel establishment by limiting outbound communication paths and monitoring cross-cloud traffic flows
Control: Egress Security & Policy Enforcement
Mitigation: Egress controls would likely constrain data exfiltration scope by limiting outbound data paths and restricting external service access channels
Residual impact would likely be limited to specific segmented cloud resource groups rather than organization-wide exposure across all services
Impact at a Glance
Affected Business Functions
- Email and Communication Systems
- Identity and Access Management
- Cloud-Based Productivity Services
- Remote Work Infrastructure
Estimated downtime: N/A
Estimated loss: N/A
Potential unauthorized access to corporate email accounts, cloud-based documents, and business applications if credential attacks were successful. The detection of password spray attacks indicates attempted compromise of user credentials which could lead to access to Microsoft 365 applications including Outlook Web Access (OWA), SharePoint, and other integrated business services.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation with least privilege policies to prevent lateral movement between cloud services and applications
- • Deploy Multicloud Visibility & Control to detect anomalous authentication patterns from unexpected geographic locations and suspicious automation
- • Strengthen Egress Security & Policy Enforcement to monitor and control outbound traffic from compromised accounts to unauthorized destinations
- • Enable Threat Detection & Anomaly Response capabilities to baseline normal authentication patterns and alert on credential attack indicators
- • Establish comprehensive monitoring of Entra ID sign-in logs with automated analysis to identify password spray attacks and geographic anomalies in real-time



