Identity logs are usually the first place a real intrusion shows up — sign-ins, MFA changes, admin role grants.