Sends POST request to http://login.microsoftonline.com/common/oauth2/v2.0/token with username and password
POST request leaks info about whether user exists, password is correct, MFA is enabled or conditional access policies are applied
Failure and Success of MSOLspray
Detect
Successful logons of MSOLSpray will show up in interactive, but not necessarily mean that they logged into the account. Especially if MFA is enabled.
Failed Logon attempts happening within seconds for multiple accounts.
The resource ID 00000002-0000-0000-c000-000000000000 is Active Directory PowerShell in Azure and is used by ADrecon, AADInternals, MSOLSpray, and many more.