Using Microsoft Graph and PowerShell - Risk Detection Commands
Executive Summary
The article extends a prior SANS Internet Storm Center diary on using Microsoft Graph with PowerShell, detailing commands and scripts for identifying risky logins. It explains how to query sign‑in events, filter for high‑risk indicators, and interpret the results to detect potential compromise or anomalous access patterns.
Intelligence Metadata - Source Publisher: SANS Internet Storm Center - Published Date: 2026-08-20T13:09:50+00:00 - Category: threat-intel
Original Description: Building on the last diary on Using MS Graph and Powershell, let&#;x26;#;39;s look at "Risky" logins.
"Success means having the courage, the determination, and the will to become the person you believe you were meant to be."
— George Sheehan
Source: SANS Internet Storm Center