Using Microsoft Sentinel and KQL to query successful sign-ins that have used a Temporary Access Pass.

By User

UserPrincipalName SigninCount
john.smith@domain.com 1
admin@domain.com 2