Close Menu
NCIJ Network NCIJ Network
    What's Hot

    4 takeaways from POLITICO’s interviews with French presidential candidates Le Pen, Mélenchon, Attal – POLITICO

    September 24, 2026

    Why did an OpenAI system hack Australia’s health system – and can it be stopped in the future?

    September 24, 2026

    Placeholder third-party[.]com Referenced Across 1,700+ Repositories Now Serves Malicious Content

    September 24, 2026
    Facebook X (Twitter) Instagram
    Trending
    • 4 takeaways from POLITICO’s interviews with French presidential candidates Le Pen, Mélenchon, Attal – POLITICO
    • Why did an OpenAI system hack Australia’s health system – and can it be stopped in the future?
    • Placeholder third-party[.]com Referenced Across 1,700+ Repositories Now Serves Malicious Content
    • Stablecoins kept growing through crypto’s $2.1 trillion wipeout
    • NASA’s Machines for Mars Make Beer Bubbly 
    • NHS staff investigated over access to dead teenager’s medical records
    • In Nepal, women seek ownership rights to the lands they tend
    • Claim that migrants intercepted by rescue ships in the Channel automatically get refugee status misunderstands asylum rules – Full Fact
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Thursday, September 24
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    How to detect OAuth client ID spoofing in Microsoft Entra ID before account takeover

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKAugust 10, 2026 Cybersecurity No Comments2 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email
    SigninLogs
    | where TimeGenerated > ago(1h)
    | where ResultType in ("50034", "50126", "700016") or isempty(AppDisplayName)
    | summarize
        DistinctClientIDs = dcount(AppId),
        ResultCodes = make_set(ResultType),
        Usernames = make_set(UserPrincipalName)
      by SourceIPAddress, UserAgent, bin(TimeGenerated, 15m)
    | where DistinctClientIDs > 5
    | where ResultCodes has "700016"

    The two variables that matter most are DistinctClientIDs, because a single source cycling through many unregistered app IDs is the tell that per-application thresholds miss, and the presence of AADSTS700016 in that same window, which elevates the event from configuration noise to possible credential validation in progress. Layer in username-pattern detection, alphabetic or dictionary progression across attempts from the same source, to catch the OutFlareAZ-style wordlist pattern specifically.

    Tune the DistinctClientIDs threshold against your own tenant’s baseline before trusting it in production. A dev team running CI against a handful of test app registrations can produce a smaller version of the same shape, and Conditional Access policies scoped only to named applications will not catch a fabricated client ID that never matches an intended application scope in the first place.

    Wire the rule into existing SOAR or ticketing workflows rather than a standalone dashboard nobody checks on a Friday afternoon. A detection that fires into the same queue as password-spray and impossible-travel alerts gets triaged with the same urgency; one that lands in an isolated identity-hygiene report gets read weeks later, if at all.

    account client detect Entra Microsoft OAuth spoofing takeover
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Placeholder third-party[.]com Referenced Across 1,700+ Repositories Now Serves Malicious Content

    Kontext Security Emerges With $4 Million for AI Agent Runtime Controls

    OpenAI Agents Probed Websites for Vulnerabilities While Fetching Public Data

    Corp MDM Spyware Targets Logistics Firms, Steals New SMS and Redirects Calls

    Windows 11 KB5124010 update released with 46 changes and fixes

    CISA: Ransomware gangs now exploiting critical TeamCity flaw

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    4 takeaways from POLITICO’s interviews with French presidential candidates Le Pen, Mélenchon, Attal – POLITICO

    September 24, 2026

    Why did an OpenAI system hack Australia’s health system – and can it be stopped in the future?

    September 24, 2026

    Placeholder third-party[.]com Referenced Across 1,700+ Repositories Now Serves Malicious Content

    September 24, 2026

    Stablecoins kept growing through crypto’s $2.1 trillion wipeout

    September 24, 2026
    Latest Posts

    Spain’s Pedro Sánchez is a progressive outlier in Europe – and over Ceuta, he is being made to pay for it | Eoghan Gilmartin

    August 6, 2026

    Putin Signs Law For Russia To Regulate Crypto Exchanges

    August 6, 2026

    Canadian pleads guilty to Snowflake cloud data-theft attacks

    August 6, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    4 takeaways from POLITICO’s interviews with French presidential candidates Le Pen, Mélenchon, Attal – POLITICO

    September 24, 2026

    Why did an OpenAI system hack Australia’s health system – and can it be stopped in the future?

    September 24, 2026

    Placeholder third-party[.]com Referenced Across 1,700+ Repositories Now Serves Malicious Content

    September 24, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.