🚩Monitor for any interactive login from AAD on-prem account (MSOL_). Can be done by setting Honey Token activity in Defender for Identity.
🚩 Make sure your AAD Connect sync account is not global admin.
Hope you found it interesting, happy hunting!
11/11