TL;DR: A large Azure exfiltration campaign shows how compromised Entra ID identities, partial telemetry, and costly log routing can let attackers move data out of tenants without timely detection, according to DataBahn. The real failure is not logging existence but telemetry completeness, coverage mapping, and queryable evidence when identity data is already in motion.
NHIMG editorial — based on content published by DataBahn: Millions of Records, One Compromised Identity Layer
By the numbers:
- When AWS credentials are exposed publicly, attackers attempt access within an average of 17 minutes and as quickly as 9 minutes in some cases.
- NHIs outnumber human identities by 25x to 50x in modern enterprises.
- Only 5.7% of organisations have full visibility into their service accounts.
Questions worth separating out
Q: What breaks when identity telemetry is incomplete in Azure environments?
A: When identity telemetry is incomplete, attackers can use valid Azure or Entra ID credentials while key signs of abuse never reach detection.
Q: Why do compromised identities make cloud exfiltration harder to spot?
A: Compromised identities blend into normal authentication flows, so the attacker is not forcing entry in an obvious way.
Q: How do teams know if identity security controls are actually working?
A: Identity security controls are working when teams can show a current view of high-risk entitlements, detect privilege drift quickly, and remove access before exposure spreads.
Practitioner guidance
- Map identity telemetry to specific detection techniques Build a live matrix showing which Entra ID and Azure events support detection for valid account use, bulk export abuse, and credential misuse.
- Validate telemetry completeness end to end Test whether sign-in logs, token events, export events, and directory changes arrive whole, in order, and within acceptable latency.
- Treat bulk directory export as a monitored data-loss path Alert on large or unusual exports of user attributes, reporting lines, and directory structures from Azure and Entra ID.
What's in the full article
DataBahn's full article covers the operational detail this post intentionally leaves for the source:
- Compass AI Agent workflow for ATT&CK-mapped coverage tracking across identity telemetry
- Signal AI Agent checks for telemetry completeness, field loss, and routing drift
- Lumen AI Agent query flow for stitching identity evidence across SIEM, data lake, and cold storage
- Examples of how the in-stream intelligence layer turns coverage gaps into visible signals
👉 Read DataBahn's analysis of Azure identity telemetry gaps and exfiltration risk →
Azure identity telemetry gaps: is your SIEM seeing the full picture?
Explore further
Telemetry completeness is now an identity control, not just a logging concern. If teams cannot prove that Entra ID and Azure identity events are reaching detection with full fidelity, then they do not truly control the identity layer. This is a governance failure because the environment may appear monitored while critical evidence is missing in transit. Practitioners should treat telemetry completeness as part of identity assurance, not an afterthought.
A question worth separating out:
Q: Who is accountable when identity logs miss an exfiltration pattern?
A: Accountability usually sits across IAM, security operations, and platform owners, because each controls a different part of the evidence chain. If coverage was never mapped, or if routing drift was not reviewed, the failure is operational governance, not just analyst misses.
👉 Read our full editorial: Azure identity telemetry gaps turn exfiltration into a blind spot