Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

Detect suspicious new employee accounts by comparing each account’s creator, source, attributes, access changes, and early sign-ins with your approved onboarding process. In Microsoft Entra, correlate audit, provisioning, sign-in, and risk records: a user created outside the normal workflow, granted unexpected privileges, or created and deleted within 24 hours deserves investigation—but none of those signals alone proves compromise.

Define what normal account creation looks like

Set the baseline before writing alerts. Document which systems are approved to create employees’ accounts—such as an HR platform or managed directory—and who may create or delete users. Specify expected naming formats, directory attributes, onboarding timing, and the groups and applications each employee type should receive.

Also record normal authentication patterns, including expected locations and egress IPs, devices, browsers, and MFA behavior. Microsoft’s Microsoft Entra security operations for user accounts recommends defining normal and expected behavior first. Tune alert thresholds against your organization’s observed activity; a deviation is a lead to check, not a verdict.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Which identity and access logs to correlate

No single log answers the whole question. Join account lifecycle events to provisioning activity, sign-ins, and access changes so you can see who or what created the identity, what happened to it, and whether it was used.

#1 Best Overall
Log or context What it helps establish
Identity audit logs Which directory or account changes occurred, who initiated them, and which identity was targeted. Microsoft Entra account-operations guidance.
Provisioning logs Actions a provisioning service performed on a user, such as creating, updating, or deleting the object. Microsoft recommends these logs for service-performed actions in its audit log activity reference.
Provisioning configuration audit events Whether an automated provisioning configuration was created, changed, paused, disabled, or restarted. Review these alongside service actions; a configuration change may explain an otherwise unusual provisioning event. Microsoft Entra audit log activity reference.
Sign-in logs Whether and how the identity authenticated, including available location, device, application, and access-policy context. See Microsoft Entra interactive sign-ins and the account-operations guidance.
Risk and privileged-account monitoring Whether a risk signal, unexpected privilege, or sign-in deviation calls for higher-priority review. Microsoft Entra security operations for privileged accounts.
Central monitoring or SIEM Whether events can be correlated, alerted on, and retained beyond the identity platform’s configured retention. See Microsoft’s account guidance and privileged-account guidance.

Investigate the account’s origin and lifecycle

Check who or what created it

In the identity audit log, find the successful user-add event and inspect its initiator and target. Compare the creator and source with your approved provisioning systems and authorized operators. Check whether the new identity’s domain, naming format, and directory attributes match your onboarding rules. An account created by an unapproved actor or process should be investigated, even if its name looks plausible.

Look for creation followed by deletion

Microsoft’s account-operations guidance suggests searching for successful user-add and user-delete events close together, using less than 24 hours as an example interval. A short-lived account may have been used and removed before it attracted attention, or the pattern may expose overly broad provisioning permissions. Correlate the timestamps, initiator, target, and any sign-ins or access changes in between; the pattern is an investigation lead, not proof of malicious activity.

Rank #2
Thetis FIDO2 Security Key (USB-A, 2-Pack) - Hardware MFA & Passkey Access for Business, School ERP & Employee Accounts | Compatible with Windows, Google Workspace, Apple ID, Coinbase, Salesforce
  • FIDO2 & Passkey Ready: Business-ready and FIDO2 L1 certified. This key is supported by major management suites and is ideal for both individual and enterprise deployment. Works seamlessly with Gmail, Facebook, GitHub, Dropbox, Coinbase, and more.
  • Universal Connectivity (USB-A ): Features a built-in USB-A connector—simply unfold the key and plug it into your compatible PC or laptop for seamless authentication on the go.
  • Dedicated Manager App: Use the Thetis Manager App for the initial hardware PIN setup. Setting the PIN on the device first ensures a smooth registration process. Once the PIN is configured, you can begin registering the key across your favorite FIDO2-compatible online services.
  • Ultra-Durable & Portable: Featuring a rotating metal cover, this key is water, crush, and tamper-resistant. It fits easily on a keychain and requires no batteries or network connectivity.
  • Check FIDO2 compatibility before purchase - Known limitations: ID Austria is not supported (requires FIDO2 Level 2). Windows Hello login only works with Windows Enterprise editions that support Entra ID, and NFC is NOT supported.

Separate routine provisioning from changes to automation

Use provisioning logs to see what the service did to the user object, then check audit events for changes to the provisioning configuration itself. A routine HR-driven creation and a newly enabled, restarted, or altered provisioning configuration are different explanations for an account appearing. Establish which applies before treating an expected automated action as suspicious—or overlooking a change to the process that creates accounts.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Review the new account’s first sign-ins

Check interactive and non-interactive sign-in activity where applicable. Confirm first that the employee and account should have access; then compare the sign-in’s location, IP address, device, browser, application or resource, Conditional Access result, and risk context with the expected baseline. Microsoft’s interactive sign-in documentation describes details including location, Conditional Access application, and cross-tenant access information. A successful authentication is not automatically benign.

Rank #3
Thetis Pro For Business - FIDO2 Security Key L1 MFA & NFC Passkey Access For School ERP, Employee Online Account, Compatible with Coinbase Google Workspace Apple ID Window Salesforce,Dual USB A +USB C
  • FIDO2 & Passkey Ready: Business-ready and FIDO2 L1 certified. This key is supported by major management suites and is ideal for both individual and enterprise deployment. Works seamlessly with Gmail, Facebook, GitHub, Dropbox, Coinbase, and more.
  • Dedicated Manager App: Use the Thetis Manager App for the initial hardware PIN setup. Setting the PIN on the device first ensures a smooth registration process. Once the PIN is configured, you can begin registering the key across your favorite FIDO2-compatible online services.
  • Universal Connectivity (USB-C, USB-A, & NFC): Designed for PCs, Macs, iPhones, and Android. For mobile use, simply unfold the key, align it with your phone’s NFC antenna, and hold for a few seconds to authenticate.
  • Enhanced MFA (FIDO2 & TOTP/HOTP): Strengthen your security with flexible options. Use the Manager App to access TOTP/HOTP features for accounts that do not yet support FIDO2.
  • Check FIDO2 compatibility before purchase - Known limitations: ID Austria is not supported (requires FIDO2 Level 2). Windows Hello login only works with Windows Enterprise editions that support Entra ID. NFC is supported only through mobile authentication, Not MacOS/windows.

Sign-in records and available fields depend on the tenant and platform configuration. Microsoft notes that, as of April 11, 2025, new sign-ins that obtain a refresh token with FIDO2 keys are logged in non-interactive sign-in logs. Account for that behavior when reviewing a new identity’s activity.

Prioritize unexpected access and privilege

Compare the account’s access with what its employee group should receive. Review unexpected group membership, role assignments, credentials or authentication-method changes, and access to resources beyond onboarding needs. Privileged identities warrant tighter scrutiny: correlate role or permission changes with sign-ins, failures, risk state, location, device, MFA, password changes, and activity outside expected controls. Apply thresholds based on your own environment; Microsoft’s guidance does not establish a universal number of failed sign-ins or an MFA threshold that proves suspicious behavior.

Rank #4
Thetis PRO-C for Business - USB C FIDO2 Security Key L1 MFA & Passkey Access for School ERP, Employee Online Account, Compatible with Coinbase Google Workspace Apple ID Window Salesfore - 2 Pack
  • FIDO2 & Passkey Ready: Business-ready and FIDO2 L1 certified. This key is supported by major management suites and is ideal for both individual and enterprise deployment. Works seamlessly with Gmail, Facebook, GitHub, Dropbox, Coinbase, and more.
  • Dedicated Manager App: Use the Thetis Manager App for the initial hardware PIN setup. Setting the PIN on the device first ensures a smooth registration process. Once the PIN is configured, you can begin registering the key across your favorite FIDO2-compatible online services.
  • Universal Connectivity (USB-C & NFC): The Thetis PRO-A features integrated USB Type C and NFC for a near-instant account unlock. Simply unfold the key and hold it to your smartphone’s NFC antenna to authenticate on the go.
  • Enhanced MFA (FIDO2 & TOTP/HOTP): Strengthen your security with flexible options. Use the Manager App to access TOTP/HOTP features for accounts that do not yet support FIDO2.
  • Check FIDO2 compatibility before purchase - Known limitations: ID Austria is not supported (requires FIDO2 Level 2). Windows Hello login only works with Windows Enterprise editions that support Entra ID. NFC is supported only through mobile authentication, Not MacOS/windows.

Turn the checks into a practical workflow

  1. Write down the baseline. List approved identity sources, permitted creators, expected attributes and naming formats, onboarding windows, normal locations and egress IPs, group and application access by employee type, and typical authentication and MFA behavior.
  2. Review account audit events. For each successful user addition or deletion, record the initiator, target, timestamp, and whether the creator and source are approved. Flag mismatched attributes or an unapproved origin for review.
  3. Correlate the provisioning trail. Inspect service actions on the user object and check whether provisioning configuration changes preceded the event. Match routine activity to the approved onboarding flow.
  4. Examine early authentication. Review interactive and non-interactive sign-ins, as applicable, and compare the account’s access and sign-in context with its expected role and baseline.
  5. Check access and risk. Trace role, group, credential, and authentication-method changes, then prioritize unexpected privilege or access alongside risk signals and unusual sign-in context.
  6. Preserve evidence and escalate. Keep the lifecycle event, actor and target, provisioning details, sign-in context, access changes, and timestamps together. If evidence indicates unauthorized creation or use, follow your incident process to contain access, preserve evidence, and validate whether the approved onboarding source or privileged provisioning path changed.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Retain and centralize the records

Microsoft’s account-operations guidance describes 30-day audit-log retention and recommends exporting logs to Azure Monitor or a SIEM for longer-term retention. Treat 30 days as guidance for the stated context, not a guarantee for every tenant or destination: verify the retention configured in your tenant and receiving system, and choose a period that supports your investigation needs.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

CISA’s SCuBA diagnostic-configuration guidance lists identity-related streams including AuditLogs, SignInLogs, RiskyUsers, UserRiskEvents, NonInteractiveUserSignInLogs, ServicePrincipalSignInLogs, and MicrosoftGraphActivityLogs. Use it as a collection reference, not as a universal event schema; available streams and fields depend on the environment. See CISA SCuBA guidance.

Best Value
Custom Same Day Access Prox Cards,26 bit, Compatible HID 1386 ISOProx (50)
  • 𝟱𝟬 𝗣𝗔𝗖𝗞 𝗢𝗙 𝗖𝗔𝗥𝗗𝗔𝗖𝗖𝗘𝗦𝗦 𝗖𝗔𝗥𝗗𝗦: Format H10301, 125 kHz Prox card frequency, replaces 1326 & 1386 HID door access cards
  • 𝗦𝗔𝗠𝗘 𝗗𝗔𝗬 𝗖𝗨𝗦𝗧𝗢𝗠 𝗘𝗡𝗖𝗢𝗗𝗘𝗗 𝗖𝗔𝗥𝗗𝗦: Card number range & Facility code
  • 𝗖𝗔𝗥𝗗 𝗥𝗔𝗡𝗚𝗘 𝗡𝗨𝗠𝗕𝗘𝗥: Printed on each card
  • 𝗣𝗥𝗜𝗡𝗧𝗔𝗕𝗟𝗘 𝗢𝗡 𝗕𝗢𝗧𝗛 𝗦𝗜𝗗𝗘𝗦 𝗪𝗜𝗧𝗛 𝗜𝗗 𝗖𝗔𝗥𝗗 𝗣𝗥𝗜𝗡𝗧𝗘𝗥: Fargo, Zebra, Evolis, Datacard & Magicard printers (NOT INKJET)
  • 𝗙𝗜𝗥𝗦𝗧 𝗧𝗜𝗠𝗘 𝗕𝗨𝗬𝗘𝗥𝗦: 𝗢𝗡𝗘 𝗖𝗔𝗥𝗗 𝗪𝗜𝗟𝗟 𝗕𝗘 𝗦𝗘𝗡𝗧 𝗢𝗡 𝗗𝗔𝗬 𝗢𝗙 𝗢𝗥𝗗𝗘𝗥. After you verify it works with your system, we will send the rest of your order. Instructions included in box.

Compare plausible explanations before deciding

  • Approved creator or source versus an unapproved one.
  • Expected account attributes versus unexpected ones.
  • Routine provisioning activity versus a provisioning-configuration change.
  • Expected onboarding access versus unexpected access or privilege.
  • Ordinary employee account versus privileged identity.
  • Normal sign-in context versus unusual location, device, application, policy result, or risk context.

These comparisons help direct investigation; none is standalone proof of compromise. Microsoft Entra-specific event names, fields, licensing, retention, and export options can vary by tenant and change over time. For another identity platform, apply the same correlation approach using its equivalent audit, provisioning, sign-in, and risk records.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.