Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊
Account information from various sources, including Microsoft Entra ID
| Attribute | Value |
|---|---|
| Category | Internal |
| Basic Logs Eligible | ✗ No (source) |
| Supports Transformations | ✓ Yes (source) |
| Ingestion API Supported | ✗ No |
| Lake-Only Ingestion | ✓ Yes |
| Azure Monitor Tables Reference | View Documentation |
| Defender XDR Advanced Hunting Schema | View Documentation |
Source: Azure Monitor documentation
| Column Name | Type | Description |
|---|---|---|
| _BilledSize | real | The record size in bytes |
| _IsBillable | string | Specifies whether ingesting the data is billable. When _IsBillable isfalseingestion isn't billed to your Azure account |
| AccountCloudSID | string | The Azure AD security identifier of the account |
| AccountCreationTime | datetime | The date the user account was created (UTC) |
| AccountDisplayName | string | The user account display name |
| AccountDomain | string | Domain name of the user account |
| AccountName | string | User name of the account |
| AccountObjectId | string | The Microsoft Entra ID object ID for the account |
| AccountSID | string | The on premises security identifier of the account |
| AccountTenantId | string | The Microsoft Entra ID Tenant ID of the account |
| AccountUPN | string | User principal name of the account |
| AdditionalMailAddresses | dynamic | Additional email addresses of the user |
| Applications | string | All known applications this user account accessed |
| AssignedRoles | dynamic | AAD roles the user account is assigned to |
| BlastRadius | string | The potential impact of the user account in the org (low/medium/high) |
| ChangeSource | string | The source of the latest change of the entity |
| City | string | The city of the user account as defined in AAD |
| CompanyName | string | The name for the company in which the user works. |
| Country | string | The country of the user account as defined in AAD |
| DeletedDateTime | datetime | The date and time the user was deleted |
| Department | string | The user account department as defined in AAD |
| EmployeeId | string | The employee identifier assigned to the user by the organization |
| EntityRiskScore | dynamic | The risk score of the entity as part of the UEBA scoring process |
| ExtensionProperty | dynamic | ExtensionProperty fields from Azure AD |
| GivenName | string | The user account given name |
| GroupMembership | dynamic | Azure AD Groups the user account is a member |
| InvestigationPriority | int | The Investigation Priority score of the account |
| InvestigationPriorityPercentile | int | The account score compared to the organization |
| IsAccountEnabled | bool | Indication if the account is enabled in AAD or not |
| IsMFARegistered | bool | Indication if MFA is registered for this user account or not |
| IsServiceAccount | bool | The account is a service account. |
| JobTitle | string | The user account job title as defined in AAD |
| LastSeenDate | datetime | Date of the last activity observed in this account |
| MailAddress | string | The user account primary email address |
| Manager | string | The user accounts manager alias |
| OnPremisesDistinguishedName | string | Active Directory distinguished name (DN). A DN is a sequence of relative distinguished names (RDN) connected by commas. |
| OnPremisesExtensionAttributes | string | OnPremisesExtensionAttributes field from Azure AD |
| Phone | string | The phone number of the user account as defined in AAD |
| RelatedAccounts | dynamic | Various accounts that correlate to a certain user |
| RiskLevel | string | The AAD risk level (Low/Medium/High) of the user account |
| RiskLevelDetails | string | Details regarding the AAD risk level |
| RiskState | string | Indication if the account is at risk now or if the risk was remediated |
| SAMAccountName | string | The SAM account name of the account. |
| ServicePrincipals | dynamic | Azure AD service principals that are owned by the user |
| SourceSystem | string | The type of agent the event was collected by. For example,OpsManagerfor Windows agent, either direct connect or Operations Manager,Linuxfor all Linux agents, orAzurefor Azure Diagnostics |
| State | string | The geographical state of the user account as defined in AAD |
| StreetAddress | string | The office street address of the user account as defined in AAD |
| Surname | string | The user account surname |
| Tags | string | Relevant information on the user account which is important for investigation: Sensitive\ VIP\ Administrator |
| TenantId | string | The Log Analytics workspace ID |
| TimeGenerated | datetime | Time when the event was generated (UTC) |
| Type | string | The name of the table |
| UACFlags | string | User Access control flags from AD & AAD |
| UserAccountControl | dynamic | Security attributes of the user account in the AD domain |
| UserState | string | The current state in AAD of the account (Active/Disabled/Dormant/Lockout) |
| UserStateChangedOn | datetime | Date of the last time the account state was changed (UTC) |
| UserType | string | The user type as appears in Azure AD |
Official Microsoft Learn documentation for field/column information:
This table is used by the following solutions:
In solution Azure Activity:
| Analytic Rule | Selection Criteria |
|---|---|
| Suspicious granting of permissions to an account |
In solution Business Email Compromise - Financial Fraud:
| Analytic Rule | Selection Criteria |
|---|---|
| Authentication Method Changed for Privileged Account | |
| Privileged Account Permissions Changed |
In solution Microsoft Defender XDR:
| Analytic Rule | Selection Criteria |
|---|---|
| Local Admin Group Changes |
In solution Microsoft Entra ID:
In solution Microsoft Entra ID Protection:
| Analytic Rule | Selection Criteria |
|---|---|
| Correlate Unfamiliar sign-in properties & atypical travel alerts |
In solution Multi Cloud Attack Coverage Essentials - Resource Abuse:
| Analytic Rule | Selection Criteria |
|---|---|
| Successful AWS Console Login from IP Address Observed Conducting Password Spray | |
| Suspicious AWS console logins by credential access alerts |
In solution eDCRule:
| Analytic Rule | Selection Criteria |
|---|---|
| [Entra ID] Authentication Method Changed for Privileged Account |
Standalone Content:
GitHub Only:
| Analytic Rule | Selection Criteria |
|---|---|
| Suspicious VM Instance Creation Activity Detected |
In solution Business Email Compromise - Financial Fraud:
In solution Cloud Identity Threat Protection Essentials:
| Hunting Query | Selection Criteria |
|---|---|
| Detect Disabled Account Sign-in Attempts by Account Name | |
| Sign-ins From VPS Providers | |
| Sign-ins from Nord VPN Providers | |
| Suspicious Sign-ins to Privileged Account |
In solution Hybrid Attack - Cloud & Identity:
In solution Microsoft Business Applications:
| Hunting Query | Selection Criteria |
|---|---|
| Dataverse - Identity management activity outside of privileged directory role membership |
In solution Microsoft Defender XDR:
| Hunting Query | Selection Criteria |
|---|---|
| Local Admin Group Changes |
In solution UEBA Essentials: BlastRadius == "High"
| Hunting Query |
|---|
| Anomalous connection from highly privileged user |
Standalone Content:
GitHub Only:
In solution AzureSecurityBenchmark:
| Workbook | Selection Criteria |
|---|---|
| AzureSecurityBenchmark |
In solution ContinuousDiagnostics&Mitigation:
| Workbook | Selection Criteria |
|---|---|
| ContinuousDiagnostics&Mitigation |
In solution CybersecurityMaturityModelCertification(CMMC)2.0:
| Workbook | Selection Criteria |
|---|---|
| CybersecurityMaturityModelCertification_CMMCV2 |
In solution Hybrid Attack - Cloud & Identity:
| Workbook | Selection Criteria |
|---|---|
| HybridAttack-Cloud&Identity |
In solution MaturityModelForEventLogManagementM2131: AssignedRoles contains "Admin"AssignedRoles contains "admin"AssignedRoles contains "contributor"AssignedRoles contains "owner"
| Workbook |
|---|
| MaturityModelForEventLogManagement_M2131 |
In solution MicrosoftPurviewInsiderRiskManagement: BlastRadius == "High"
| Workbook |
|---|
| InsiderRiskManagement |
In solution NISTSP80053:
| Workbook | Selection Criteria |
|---|---|
| NISTSP80053 |
In solution SOC Handbook:
| Workbook | Selection Criteria |
|---|---|
| InvestigationInsights |
In solution ZeroTrust(TIC3.0):
| Workbook | Selection Criteria |
|---|---|
| ZeroTrustTIC3 |
GitHub Only:
References by type: 0 connectors, 3 content items, 0 ASIM parsers, 0 other parsers.
| Selection Criteria | Connectors | Content Items | ASIM Parsers | Other Parsers | Total |
|---|---|---|---|---|---|
BlastRadius == "High" |
- | 2 | - | - | 2 |
AssignedRoles contains "Admin"AssignedRoles contains "admin"AssignedRoles contains "contributor"AssignedRoles contains "owner" |
- | 1 | - | - | 1 |
| Total | 0 | 3 | 0 | 0 | 3 |
| Value | Connectors | Content Items | ASIM Parsers | Other Parsers | Total |
|---|---|---|---|---|---|
contains Admin |
- | 1 | - | - | 1 |
contains admin |
- | 1 | - | - | 1 |
contains contributor |
- | 1 | - | - | 1 |
contains owner |
- | 1 | - | - | 1 |
| Value | Connectors | Content Items | ASIM Parsers | Other Parsers | Total |
|---|---|---|---|---|---|
High |
- | 2 | - | - | 2 |
Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊