Blank Entra Logs Can Hide Credential Checks

Defenders who wait for a normal successful sign-in can miss account probing in Microsoft Entra ID. Attackers are using spoofed OAuth client IDs to test usernames and passwords through failure codes and blank app fields, not through a clean login event. Proofpoint says the technique shows up in Entra sign-in logs as an empty or unknown application name, with AADSTS700016 signaling that a username and password pair is correct. It has already appeared in multiple large-scale campaigns across thousands of Microsoft Entra tenants. That makes log rules tied to named applications or successful sign-ins a weak control for spotting password spraying and user enumeration. The gap is in the telemetry itself: a valid credential can be confirmed without leaving the record defenders expect to see.

Part of the PlainSec briefing for 2026-07-15

Sources