Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊
Reference for AADServicePrincipalSignInLogs table in Azure Monitor Logs.
| Attribute | Value |
|---|---|
| Category | Entra |
| Basic Logs Eligible | ✓ Yes (source) |
| Supports Transformations | ✓ Yes (source) |
| Ingestion API Supported | ✗ No |
| Lake-Only Ingestion | ✓ Yes (source) |
| Azure Monitor Tables Reference | View Documentation |
Source: Azure Monitor documentation
| Column Name | Type | Description |
|---|---|---|
| _BilledSize | real | The record size in bytes |
| _IsBillable | string | Specifies whether ingesting the data is billable. When _IsBillable is false ingestion isn't billed to your Azure account |
| AADTenantId | string | ID of the AAD tenant. |
| Agent | string | Details of agentic sign-in. |
| AppId | string | Unique GUID representing the app ID in the Azure Active Directory |
| AppOwnerTenantId | string | The tenant identifier of the owenr of the application in Azure Active Directory |
| AuthenticationContextClassReferences | string | The authentication contexts of the sign-in |
| AuthenticationProcessingDetails | string | Provides the details associated with authentication processor |
| AutonomousSystemNumber | string | Autonomous System Number for the network. |
| Category | string | Category of the sign-in event |
| ClientCredentialType | string | The type of client credential used. Examples include client assertion, client secret, etc. |
| ConditionalAccessAudiences | string | Details of the conditional access audiences being applied for the sign-in. |
| ConditionalAccessPolicies | string | Details of the conditional access policies being applied for the sign-in |
| ConditionalAccessStatus | string | Status of all the conditionalAccess policies related to the sign-in |
| CorrelationId | string | ID to provide sign-in trail |
| CreatedDateTime | datetime | Datetime of the sign-in activity. |
| DurationMs | long | The duration of the operation in milliseconds |
| FederatedCredentialId | string | Th identifier of an application's federated identity credential if a federated identity credential was used to sign in. |
| Id | string | Unique ID representing the sign-in activity |
| Identity | string | The identity from the token that was presented when you made the request. It can be a user account, system account, or service principal |
| IPAddress | string | IP address of the client used to sign in |
| Level | string | The severity level of the event |
| Location | string | The region of the resource emitting the event |
| LocationDetails | string | Details of the sign-in location |
| NetworkLocationDetails | string | Provides the details associated with Authentication processor. |
| OperationName | string | For sign-ins, this value is always Sign-in activity |
| OperationVersion | string | The REST API version that's requested by the client |
| ResourceDisplayName | string | Name of the resource that the service principal signed into |
| ResourceGroup | string | Resource group for the logs |
| ResourceIdentity | string | ID of the resource that the service principal signed into |
| ResourceOwnerTenantId | string | The tenant identifier of the owner of the resource referenced in the sign in |
| ResourceServicePrincipalId | string | Service Principal Id of the resource |
| ResultDescription | string | Provides the error description for the sign-in operation |
| ResultSignature | string | Contains the error code, if any, for the sign-in operation |
| ResultType | string | The result of the sign-in operation can be Success or Failure |
| ServicePrincipalCredentialKeyId | string | Key id of the service principal that initiated the sign-in |
| ServicePrincipalCredentialThumbprint | string | Thumbprint of the service principal that initiated the sign-in |
| ServicePrincipalId | string | ID of the service principal who initiated the sign-in |
| ServicePrincipalName | string | Service Principal Name of the service principal who initiated the sign-in |
| SessionId | string | Id of the session that was generated during the signIn. |
| SourceSystem | string | The type of agent the event was collected by. For example, OpsManager for Windows agent, either direct connect or Operations Manager, Linux for all Linux agents, or Azure for Azure Diagnostics |
| TenantId | string | The Log Analytics workspace ID |
| TimeGenerated | datetime | The date and time of the event in UTC |
| Type | string | The name of the table |
| UniqueTokenIdentifier | string | Unique token identifier for the request |
| UserAgent | string | User Agent for the sign-in |
Official Microsoft Learn documentation for field/column information:
This table is used by the following solutions:
This table is ingested by the following connectors:
| Connector | Selection Criteria |
|---|---|
| Microsoft Entra ID |
In solution Lumen Defender Threat Feed:
| Analytic Rule | Selection Criteria |
|---|---|
| Lumen TI IPAddress in IdentityLogonEvents |
In solution Microsoft Entra ID: OperationName == "Remove service principal"OperationName has_all "Update application"
| Analytic Rule |
|---|
| Suspicious Service Principal creation activity |
In solution Hybrid Attack - Cloud & Identity:
| Hunting Query | Selection Criteria |
|---|---|
| Key Vault harvest to SPN sign-in then out-of-scope resource access | |
| Key Vault secret harvest followed by novel SPN sign-in from non-1P IP | |
| Novel SPN sign-in followed by Azure RBAC write | |
| Novel identity then Key Vault secret burst | |
| Secret Added to Dormant Service Principal | |
| Service principal Conditional Access anomaly | ConditionalAccessStatus in "failure,notApplied"ResultType in "0,Success" |
| Service principal credential change followed by novel SP sign-in |
In solution AzureSecurityBenchmark:
| Workbook | Selection Criteria |
|---|---|
| AzureSecurityBenchmark |
In solution CybersecurityMaturityModelCertification(CMMC)2.0:
| Workbook | Selection Criteria |
|---|---|
| CybersecurityMaturityModelCertification_CMMCV2 |
In solution Hybrid Attack - Cloud & Identity: OperationName in "Add app role assignment to service principal,Add delegated permission grant,Add service principal credentials,Admin deleted security info,Admin registered security info,Admin updated security info,Consent to application,GetBlob,ListBlobs,ListBlobsHierarchySegment,ListContainersSegment,Set domain authentication,Set federation settings on domain,User changed default security info,User deleted security info,User registered security info,User updated security info"OperationName has_any "clusterrolebindings,rolebindings"OperationName has_any "cronjobs,daemonsets"OperationName has_any "cronjobs/create,daemonsets/create"
| Workbook |
|---|
| HybridAttack-Cloud&Identity |
In solution MaturityModelForEventLogManagementM2131:
| Workbook | Selection Criteria |
|---|---|
| MaturityModelForEventLogManagement_M2131 |
In solution Microsoft Entra ID: OperationName in "Add conditional access policy,Add member to group,Add member to restricted management administrative unit,Delete conditional access policy,Remove member from group,Remove member from restricted management administrative unit,Update conditional access policy,Update group"
| Workbook |
|---|
| ConditionalAccessSISM |
| Parser | Schema | Product | Selection Criteria |
|---|---|---|---|
| ASimAuthenticationAADServicePrincipalSignInLogs | Authentication | Microsoft Entra ID |
References by type: 0 connectors, 4 content items, 0 ASIM parsers, 0 other parsers.
| Selection Criteria | Connectors | Content Items | ASIM Parsers | Other Parsers | Total |
|---|---|---|---|---|---|
OperationName == "Remove service principal"OperationName has_all "Update application" |
- | 1 | - | - | 1 |
ConditionalAccessStatus in "failure,notApplied"ResultType in "0,Success" |
- | 1 | - | - | 1 |
OperationName in "Add app role assignment to service principal,Add delegated permission grant,Add service principal credentials,Admin deleted security info,Admin registered security info,Admin updated security info,Consent to application,GetBlob,ListBlobs,ListBlobsHierarchySegment,ListContainersSegment,Set domain authentication,Set federation settings on domain,User changed default security info,User deleted security info,User registered security info,User updated security info"OperationName has_any "clusterrolebindings,rolebindings"OperationName has_any "cronjobs,daemonsets"OperationName has_any "cronjobs/create,daemonsets/create" |
- | 1 | - | - | 1 |
OperationName in "Add conditional access policy,Add member to group,Add member to restricted management administrative unit,Delete conditional access policy,Remove member from group,Remove member from restricted management administrative unit,Update conditional access policy,Update group" |
- | 1 | - | - | 1 |
| Total | 0 | 4 | 0 | 0 | 4 |
| Value | Connectors | Content Items | ASIM Parsers | Other Parsers | Total |
|---|---|---|---|---|---|
failure |
- | 1 | - | - | 1 |
notApplied |
- | 1 | - | - | 1 |
| Value | Connectors | Content Items | ASIM Parsers | Other Parsers | Total |
|---|---|---|---|---|---|
Remove service principal |
- | 1 | - | - | 1 |
has_all Update application |
- | 1 | - | - | 1 |
Add app role assignment to service principal |
- | 1 | - | - | 1 |
Add delegated permission grant |
- | 1 | - | - | 1 |
Add service principal credentials |
- | 1 | - | - | 1 |
Admin deleted security info |
- | 1 | - | - | 1 |
Admin registered security info |
- | 1 | - | - | 1 |
Admin updated security info |
- | 1 | - | - | 1 |
Consent to application |
- | 1 | - | - | 1 |
GetBlob |
- | 1 | - | - | 1 |
ListBlobs |
- | 1 | - | - | 1 |
ListBlobsHierarchySegment |
- | 1 | - | - | 1 |
ListContainersSegment |
- | 1 | - | - | 1 |
Set domain authentication |
- | 1 | - | - | 1 |
Set federation settings on domain |
- | 1 | - | - | 1 |
User changed default security info |
- | 1 | - | - | 1 |
User deleted security info |
- | 1 | - | - | 1 |
User registered security info |
- | 1 | - | - | 1 |
User updated security info |
- | 1 | - | - | 1 |
has_any clusterrolebindings |
- | 1 | - | - | 1 |
has_any rolebindings |
- | 1 | - | - | 1 |
has_any cronjobs |
- | 1 | - | - | 1 |
has_any daemonsets |
- | 1 | - | - | 1 |
has_any cronjobs/create |
- | 1 | - | - | 1 |
has_any daemonsets/create |
- | 1 | - | - | 1 |
Add conditional access policy |
- | 1 | - | - | 1 |
Add member to group |
- | 1 | - | - | 1 |
Add member to restricted management administrative unit |
- | 1 | - | - | 1 |
Delete conditional access policy |
- | 1 | - | - | 1 |
Remove member from group |
- | 1 | - | - | 1 |
Remove member from restricted management administrative unit |
- | 1 | - | - | 1 |
Update conditional access policy |
- | 1 | - | - | 1 |
Update group |
- | 1 | - | - | 1 |
| Value | Connectors | Content Items | ASIM Parsers | Other Parsers | Total |
|---|---|---|---|---|---|
0 |
- | 1 | - | - | 1 |
Success |
- | 1 | - | - | 1 |
Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊