Published on11 June 2022Sentinel hunting queries for users logging in to AzureAD or Exchange Online PowerShellAzureSentinelSIEMthreat-huntingsecurityLooking for suspicious activity in Azure Sentinel based on non-admin users logging in to AzureAD or Exchange Online PowerShell