SigninLogs
Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊
↑ Back to Tables Index
Reference for SigninLogs table in Azure Monitor Logs.
| Attribute |
Value |
| Category |
Azure Resources, Security |
| Basic Logs Eligible |
✓ Yes (source) |
| Supports Transformations |
✓ Yes (source) |
| Ingestion API Supported |
✗ No |
| Lake-Only Ingestion |
✓ Yes (source) |
| Azure Monitor Tables Reference |
View Documentation |
Contents
Schema (97 columns)
Source: Azure Monitor documentation
| Column Name |
Type |
Description |
| _BilledSize |
real |
The record size in bytes |
| _IsBillable |
string |
Specifies whether ingesting the data is billable. When _IsBillable isfalseingestion isn't billed to your Azure account |
| AADTenantId |
string |
|
| Agent |
dynamic |
The agentic property for sign in logs. Includes the agentType and the parentAppId when the type is AgenticInstance. |
| AlternateSignInName |
string |
The identification that the user provided to sign in. It may be the userPrincipalName but it's also populated when a user signs in using other identifiers. |
| AppDisplayName |
string |
The application name displayed in the Azure Portal. |
| AppId |
string |
The application identifier in Microsoft Entra ID. |
| AppliedConditionalAccessPolicies |
string |
|
| AppliedEventListeners |
dynamic |
Detailed information about the listeners, such as Azure Logic Apps and Azure Functions, that were triggered by the corresponding events in the sign-in event. |
| AppOwnerTenantId |
string |
The tenant identifier of the owenr of the application in Microsoft Entra ID. |
| AuthenticationAppDeviceDetails |
string |
Details of the app and device state used during the most recent authentication step using an authentication app. |
| AuthenticationAppPolicyEvaluationDetails |
string |
The details of the policies applied and enforced related to the authentication app during the latest signIn step. |
| AuthenticationContextClassReferences |
string |
Contains a collection of values that represent the conditional access authentication contexts applied to the sign-in. |
| AuthenticationDetails |
string |
The result of the authentication attempt and additional details on the authentication method. |
| AuthenticationMethodsUsed |
string |
The authentication methods used. Possible values: SMS, Authenticator App, App Verification code, Password, FIDO, PTA, or PHS. |
| AuthenticationProcessingDetails |
string |
Additional authentication processing details, such as the agent name in case of PTA/PHS or Server/farm name in case of federated authentication. |
| AuthenticationProtocol |
string |
Lists the protocol type or grant type used in the authentication. The possible values are: none, oAuth2, ropc, wsFederation, saml20, deviceCode. For authentications that use protocols other than the possible values listed, the protocol type is listed as none. |
| AuthenticationRequirement |
string |
This holds the highest level of authentication needed through all the sign-in steps, for sign-in to succeed. |
| AuthenticationRequirementPolicies |
string |
Sources of authentication requirement, such as conditional access, per-user MFA, identity protection, and security defaults. |
| AuthenticatorAppLocation |
string |
The location of the authenticator app. |
| AutonomousSystemNumber |
string |
The Autonomous System Number (ASN) of the network used by the actor. |
| Category |
string |
|
| ClientAppUsed |
string |
The legacy client used for sign-in activity. For example: Browser, Exchange ActiveSync, Modern clients, IMAP, MAPI, SMTP, or POP. |
| ClientCredentialType |
string |
The type of client credential used. Examples include client assertion, client secret, etc. |
| ClientSessionId |
string |
ID of the client session associated with the signIn. |
| ConditionalAccessAudiences |
string |
The audiences targeted by the conditional access policy. |
| ConditionalAccessPolicies |
dynamic |
A list of conditional access policies that are triggered by the corresponding sign-in activity. |
| ConditionalAccessStatus |
string |
The status of the conditional access policy triggered. Possible values: success, failure, or notApplied. |
| CorrelationId |
string |
The identifier that's sent from the client when sign-in is initiated. This is used for troubleshooting the corresponding sign-in activity when calling for support. |
| CreatedDateTime |
datetime |
The date and time the sign-in was initiated. The Timestamp type is always in UTC time. For example, midnight UTC on Jan 1, 2014 is 2014-01-01T00:00:00Z. |
| CrossTenantAccessType |
string |
Describes the type of cross-tenant access used by the actor to access the resource. |
| DeviceDetail |
dynamic |
The device information from where the sign-in occurred. Includes information such as deviceId, OS, and browser. |
| DurationMs |
long |
|
| FederatedCredentialId |
string |
Federated Credential Id. |
| FlaggedForReview |
bool |
During a failed sign in, a user may click a button in the Azure portal to mark the failed event for tenant admins. If a user clicked the button to flag the failed sign in, this value is true. |
| GlobalSecureAccessIpAddress |
string |
Global secure IP address that user signed in from. |
| HomeTenantId |
string |
The tenant identifier of the user initiating the sign in. Not applicable in Managed Identity or service principal sign ins. |
| HomeTenantName |
string |
The tenant name of the external tenant who homes the entitity taking action in the customer's tenant. |
| Id |
string |
The identifier representing the sign-in activity. |
| Identity |
string |
The display name of the actor identified in the signin. |
| IncomingTokenType |
string |
The type of token utilized to signIn (examples: primary refresh token, saml assertion). |
| IPAddress |
string |
The IP address of the client from where the sign-in occurred. |
| IPAddressFromResourceProvider |
string |
The IP address a user used to reach a resource provider, used to determine Conditional Access compliance for some policies. For example, when a user interacts with Exchange Online, the IP address Exchange receives from the user may be recorded here. This value is often null. |
| IsInteractive |
bool |
Indicates whether a user sign in is interactive. In interactive sign in, the user provides an authentication factor to Azure AD. These factors include passwords, responses to MFA challenges, biometric factors, or QR codes that a user provides to Azure AD or an associated app. In non-interactive sign in, the user doesn't provide an authentication factor. Instead, the client app uses a token or code to authenticate or access a resource on behalf of a user. Non-interactive sign ins are commonly used for a client to sign in on a user's behalf in a process transparent to the user. |
| IsRisky |
bool |
|
| IsTenantRestricted |
bool |
Indicates if a signIn is under a tenant restrictions policy or not. |
| IsThroughGlobalSecureAccess |
bool |
Displays whether or not a user came through Global Secure Access service or not. |
| Level |
string |
|
| Location |
string |
The 2 letter country code from where the sign-in occurred. Depending on IP address provided, this value may not always resolve to a city or region level of detail. |
| LocationDetails |
dynamic |
Provides the city, state, country/region and latitude and longitude from where the sign-in happened. |
| MfaDetail |
dynamic |
This property is deprecated. |
| NetworkLocationDetails |
string |
The network location details including the type of network used and its names. |
| OperationName |
string |
|
| OperationVersion |
string |
|
| OriginalRequestId |
string |
The request identifier of the first request in the authentication sequence. |
| OriginalTransferMethod |
string |
Transfer method used to initiate a session throughout all subsequent requests. |
| ProcessingTimeInMilliseconds |
string |
|
| Resource |
string |
|
| ResourceDisplayName |
string |
The name of the resource that the user signed in to. |
| ResourceGroup |
string |
|
| ResourceId |
string |
The identifier of the resource that the user signed in to. |
| ResourceIdentity |
string |
The resource that the user signed in to. |
| ResourceOwnerTenantId |
string |
The tenant identifier of the owner of the resource referenced in the sign in. |
| ResourceProvider |
string |
|
| ResourceServicePrincipalId |
string |
The identifier of the service principal representing the target resource in the sign-in event. |
| ResourceTenantId |
string |
The tenant identifier of the resource referenced in the sign in. |
| ResultDescription |
string |
Provides the error message or the reason for failure for the corresponding sign-in activity. |
| ResultSignature |
string |
|
| ResultType |
string |
Provides the 5-6 digit error code that's generated during a sign-in event. 0 indicates success; other values are failures. You can find more information using the Azure AD Error Codes documentation orhttps://login.microsoftonline.com/error. |
| RiskDetail |
string |
The reason behind a specific state of a risky user, sign-in, or a risk event. Possible values: none, adminGeneratedTemporaryPassword, userPerformedSecuredPasswordChange, userPerformedSecuredPasswordReset, adminConfirmedSigninSafe, aiConfirmedSigninSafe, userPassedMFADrivenByRiskBasedPolicy, adminDismissedAllRiskForUser, or adminConfirmedSigninCompromised. The value none means that no action has been performed on the user or sign-in so far. Note: Details for this property are only available for Azure AD Premium P2 customers. All other customers are returned hidden. |
| RiskEventTypes |
string |
This property is deprecated. |
| RiskEventTypes_V2 |
string |
The list of risk event types associated with the sign-in. Possible values: unlikelyTravel, anonymizedIPAddress, maliciousIPAddress, unfamiliarFeatures, malwareInfectedIPAddress, suspiciousIPAddress, leakedCredentials, investigationsThreatIntelligence, or generic. |
| RiskLevel |
string |
|
| RiskLevelAggregated |
string |
The aggregated risk level. Possible values: none, low, medium, high, or hidden. The value hidden means the user or sign-in was not enabled for Azure AD Identity Protection. Note: Details for this property are only available for Azure AD Premium P2 customers. All other customers are returned hidden. |
| RiskLevelDuringSignIn |
string |
The risk level during sign-in. Possible values: none, low, medium, high, or hidden. The value hidden means the user or sign-in was not enabled for Azure AD Identity Protection. Note: Details for this property are only available for Azure AD Premium P2 customers. All other customers are returned hidden. |
| RiskState |
string |
The risk state of a risky user, sign-in, or a risk event. Possible values: none, confirmedSafe, remediated, dismissed, atRisk, or confirmedCompromised. |
| RootActorID |
string |
The root actor virtual ID associated with the sign-in. |
| ServicePrincipalId |
string |
The application identifier used for sign-in. This field is populated when you are signing in using an application. |
| ServicePrincipalName |
string |
The application name used for sign-in. This field is populated when you are signing in using an application. |
| SessionId |
string |
Id of the session that was generated during the signIn. |
| SessionLifetimePolicies |
string |
Any conditional access session management policies that were applied during the sign-in event. |
| SignInIdentifier |
string |
The identification that the user provided to sign in. It may be the userPrincipalName but it's also populated when a user signs in using other identifiers. |
| SignInIdentifierType |
string |
The type of sign in identifier. Possible values are: userPrincipalName, phoneNumber, proxyAddress, qrCode, onPremisesUserPrincipalName. |
| SourceAppClientId |
string |
The Source App's Client ID for Target Identities. |
| SourceSystem |
string |
The type of agent the event was collected by. For example,OpsManagerfor Windows agent, either direct connect or Operations Manager,Linuxfor all Linux agents, orAzurefor Azure Diagnostics |
| Status |
dynamic |
The sign-in status. Includes the error code and description of the error (in case of a sign-in failure). |
| TimeGenerated |
datetime |
|
| TokenIssuerName |
string |
The name of the identity provider. For example, sts.microsoft.com. |
| TokenIssuerType |
string |
The type of identity provider. The possible values are: AzureAD, or ADFederationServices, AzureADBackupAuth, ADFederationServicesMFAAdapter, NPSExtension. |
| TokenProtectionStatusDetails |
dynamic |
Token protection creates a cryptographically secure tie between the token and the device it's issued to. This field indicates whether the signin token was bound to the device or not. |
| Type |
string |
The name of the table |
| UniqueTokenIdentifier |
string |
A unique base64 encoded request identifier used to track tokens issued by Azure AD as they are redeemed at resource providers. |
| UserAgent |
string |
The user agent information related to sign-in. |
| UserDisplayName |
string |
The display name of the user. |
| UserId |
string |
The identifier of the user. |
| UserPrincipalName |
string |
The UPN of the user. |
| UserType |
string |
Identifies whether the user is a member or guest in the tenant. Possible values are: member and guest. |
Schema References
Official Microsoft Learn documentation for field/column information:
Solutions (39)
This table is used by the following solutions:
Connectors (1)
This table is ingested by the following connectors:
Content Items Using This Table (173)
Analytic Rules (47)
In solution Apache Log4j Vulnerability Detection:
In solution FalconFriday:
In solution GitLab: ResultType == "0"
In solution HoneyLabs:
In solution Lastpass Enterprise Activity Monitoring:
In solution Lumen Defender Threat Feed:
In solution Microsoft Business Applications:
In solution Microsoft Defender XDR:
In solution Microsoft Entra ID:
In solution MicrosoftPurviewInsiderRiskManagement: RiskState == "atRisk"
In solution Multi Cloud Attack Coverage Essentials - Resource Abuse:
In solution SecurityThreatEssentialSolution:
In solution StratoSecure:
In solution Threat Intelligence:
In solution Threat Intelligence (NEW):
In solution eDCRule:
Standalone Content:
Hunting Queries (80)
In solution Business Email Compromise - Financial Fraud:
In solution Cloud Identity Threat Protection Essentials:
In solution Hybrid Attack - Cloud & Identity:
In solution Lastpass Enterprise Activity Monitoring:
In solution Microsoft 365:
In solution Microsoft Business Applications:
In solution Microsoft Defender XDR:
In solution MicrosoftPurviewInsiderRiskManagement:
In solution SecurityThreatEssentialSolution: ResultType == "0"
In solution UEBA Essentials:
In solution Windows Server DNS:
Standalone Content:
GitHub Only:
Workbooks (46)
In solution 1Password:
In solution Apache Log4j Vulnerability Detection:
In solution AzureSecurityBenchmark: OperationName in "Add member to role,Add user,AzureFirewallIDSLog,NetworkSecurityGroupEvents,Reset user password,Update user"
OperationName contains "PIM"
OperationName contains "create"
OperationName contains "delete"
OperationName contains "lockbox"
OperationName contains "remove"
OperationName contains "update"
In solution ContinuousDiagnostics&Mitigation: OperationName contains "PIM"
In solution CybersecurityMaturityModelCertification(CMMC)2.0: AuthenticationRequirement == "multiFactorAuthentication"
OperationName in "Add member to role,Add user,NetworkSecurityGroupEvents,Reset user password,Update user"
OperationName contains "Add"
OperationName contains "Audit"
OperationName contains "Change"
OperationName contains "Create"
OperationName contains "Delete"
OperationName contains "Log"
OperationName contains "Monitor"
OperationName contains "PIM"
OperationName contains "Remove"
OperationName contains "Update"
OperationName contains "Write"
OperationName contains "reset"
In solution DPDP Compliance: OperationName in "Add member to role,Add user,Consent to application,Reset user password,Update user"
OperationName == "Sign-in activity"
OperationName != "Consent to application"
In solution GDPR Compliance & Data Security: OperationName in "Add member to role,Add user,Consent to application,Reset user password,Update user"
OperationName == "Sign-in activity"
OperationName != "Consent to application"
In solution Global Secure Access:
In solution HIPAA Compliance: AuthenticationRequirement == "multiFactorAuthentication"
In solution Hybrid Attack - Cloud & Identity: OperationName in "Add app role assignment to service principal,Add delegated permission grant,Add service principal credentials,Admin deleted security info,Admin registered security info,Admin updated security info,Consent to application,GetBlob,ListBlobs,ListBlobsHierarchySegment,ListContainersSegment,Set domain authentication,Set federation settings on domain,User changed default security info,User deleted security info,User registered security info,User updated security info"
OperationName has_any "clusterrolebindings,rolebindings"
OperationName has_any "cronjobs,daemonsets"
OperationName has_any "cronjobs/create,daemonsets/create"
In solution Lastpass Enterprise Activity Monitoring:
In solution Lumen Defender Threat Feed:
In solution MaturityModelForEventLogManagementM2131: AppDisplayName in "Azure Active Directory PowerShell,Microsoft Azure CLI"
AppDisplayName contains "ACOM"
AppDisplayName contains "CLI"
AppDisplayName contains "PowerShell"
AppDisplayName contains "command"
AppDisplayName contains "graph"
OperationName in "Add member to role,Add user,ApplicationGatewayFirewall,AzureFirewallIDSLog,Reset user password,Update user"
OperationName !contains "external"
OperationName !contains "invite"
OperationName !contains "licnense"
OperationName contains "group"
OperationName contains "member"
OperationName contains "principal"
OperationName contains "role"
OperationName contains "user"
In solution Microsoft Entra ID:
| Workbook |
Selection Criteria |
| AzureActiveDirectorySignins |
|
| ConditionalAccessSISM |
OperationName in "Add conditional access policy,Add member to group,Add member to restricted management administrative unit,Delete conditional access policy,Remove member from group,Remove member from restricted management administrative unit,Update conditional access policy,Update group" |
In solution MicrosoftPurviewInsiderRiskManagement: AppDisplayName contains "Portal"
OperationName in "Add member to role,Add user,Consent to application,Create Deployment,Create or Update Virtual Machine,Create role assignment,List Storage Account Keys,Reset user password,Update user"
OperationName in "Set domain authentication,Set federation settings on domain,Sign-in activity"
OperationName != "Consent to application"
OperationName contains "Create"
OperationName contains "Delete"
OperationName contains "Update"
OperationName contains "delet"
OperationName contains "delete"
OperationName contains "remove"
OperationName has "Create"
OperationName has_any "Create,Update"
OperationName has_any "Ip,Security Rule"
In solution NISTSP80053: OperationName contains "Delete"
OperationName contains "PIM"
OperationName contains "Remove"
In solution SOC Handbook: AppDisplayName == "Windows Sign In"
OperationName == "Consent to application"
OperationName == "Disable Strong Authentication"
OperationName contains "password"
In solution SOX IT Compliance:
In solution Teams: AppDisplayName startswith "Microsoft Teams"
ResultType == "0"
ResultType !in "0,50140"
In solution ThreatAnalysis&Response:
In solution Windows Firewall: ResultType == "0"
ResultType != "0"
In solution ZeroTrust(TIC3.0): AppDisplayName has_any "teams"
OperationName in "Add member to role,Add user,ApplicationGatewayFirewall,AzureFirewallIDSLog,AzureFirewallThreatIntelLog,NetworkSecurityGroupEvents,Reset user password,Update user"
OperationName contains "PIM"
GitHub Only:
| Workbook |
Selection Criteria |
| 1Password |
|
| AdvancedWorkbookConcepts |
|
| AzureActiveDirectorySignins |
|
| AzureAuditActivityAndSignin |
|
| AzureLogCoverage |
|
| ConditionalAccessTrendsandChanges |
|
| CopilotforSecurityMonitoring |
|
| DSTIMWorkbook |
|
| DoDZeroTrustWorkbook |
AuthenticationRequirement in "multiFactorAuthentication,singleFactorAuthentication"
ConditionalAccessStatus == "notApplied"
NetworkLocationDetails == "[]"
OperationName in "Add app role assignment grant to user,Add application,Add group,Add member to role,Add member to role completed (PIM activation),Add user,Create access package,Reset user password,Update conditional access policy,Update user,User requests access package assignment"
OperationName contains "PIM"
OperationName contains "create access package"
OperationName contains "permanent"
OperationName has "User requests access package assignment"
OperationName has "application" |
| InsecureProtocols |
ClientAppUsed !in "Browser,Mobile Apps
Desktop clients"
ResultType == "0" |
| InvestigationInsights |
AppDisplayName == "Windows Sign In"
OperationName == "Consent to application"
OperationName == "Disable Strong Authentication"
OperationName contains "password" |
| Log4jPostCompromiseHunting |
|
| MicrosoftSecurityLicenseUtilization |
|
| MicrosoftSentinelDeploymentandMigrationTracker |
|
| MicrosoftTeams |
AppDisplayName startswith "Microsoft Teams"
ResultType == "0"
ResultType !in "0,50140" |
| SentinelWorkspaceReconTools |
|
| SolarWindsPostCompromiseHunting |
TokenIssuerType == "AzureAD" |
| UserMap |
|
| User_Analytics_Workbook |
|
| WindowsFirewall |
ResultType == "0"
ResultType != "0" |
| WindowsFirewallViaAMA |
ResultType == "0"
ResultType != "0" |
| WorkspaceUsage |
AuthenticationRequirement in "multiFactorAuthentication,singleFactorAuthentication"
AuthenticationRequirement != "multiFactorAuthentication"
OperationName in "Add member to role completed (PIM activation),Invite external user,Redeem external user invite,User changed default security info,User deleted security info,User registered all required security info,User registered security info"
OperationName !in "Microsoft.SecurityInsights/Incidents/investigations/write,Microsoft.SecurityInsights/dataConnectorsCheckRequirements/action" |
| ZeroTrustStrategyWorkbook |
AuthenticationRequirement in "multiFactorAuthentication,singleFactorAuthentication"
ConditionalAccessStatus == "notApplied"
NetworkLocationDetails == "[]"
OperationName in "Add app role assignment grant to user,Add application,Add group,Add member to role,Add member to role completed (PIM activation),Add user,Create access package,Reset user password,Update conditional access policy,Update user,User requests access package assignment"
OperationName contains "PIM"
OperationName contains "create access package"
OperationName contains "permanent"
OperationName has "User requests access package assignment"
OperationName has "application" |
Parsers Using This Table (1)
ASIM Parsers (1)
Resource Types
This table collects data from the following Azure resource types:
Selection Criteria Summary (46 criteria, 62 total references)
References by type: 0 connectors, 62 content items, 0 ASIM parsers, 0 other parsers.
| Selection Criteria |
Connectors |
Content Items |
ASIM Parsers |
Other Parsers |
Total |
ResultType == "0" |
- |
10 |
- |
- |
10 |
AuthenticationRequirement == "multiFactorAuthentication" |
- |
3 |
- |
- |
3 |
ResultType in "0,50057" |
- |
2 |
- |
- |
2 |
ResultType == "50057" |
- |
2 |
- |
- |
2 |
ResultType == "0"
RiskLevelAggregated != "none" |
- |
2 |
- |
- |
2 |
ResultType == "50053" |
- |
2 |
- |
- |
2 |
OperationName in "Add member to role,Add user,Consent to application,Reset user password,Update user"
OperationName == "Sign-in activity"
OperationName != "Consent to application" |
- |
2 |
- |
- |
2 |
ResourceIdentity == "00000007-0000-0000-c000-000000000000" |
- |
1 |
- |
- |
1 |
NetworkLocationDetails !has "trustedNamedLocation"
ResultType == "0" |
- |
1 |
- |
- |
1 |
AppDisplayName == "Windows Sign In" |
- |
1 |
- |
- |
1 |
ResultType == "500121" |
- |
1 |
- |
- |
1 |
RiskState == "atRisk" |
- |
1 |
- |
- |
1 |
AppDisplayName in "ADFS Trust,Azure Portal,Microsoft Azure PowerShell"
RiskLevelAggregated == "high"
RiskLevelDuringSignIn == "high" |
- |
1 |
- |
- |
1 |
ResultType in "0,50125,50140" |
- |
1 |
- |
- |
1 |
ResultType == "0"
RiskState == "atRisk" |
- |
1 |
- |
- |
1 |
AuthenticationRequirement == "singleFactorAuthentication"
ResultType == "0" |
- |
1 |
- |
- |
1 |
ResultType != "0" |
- |
1 |
- |
- |
1 |
OperationName == "Update user" |
- |
1 |
- |
- |
1 |
AppDisplayName == "Office 365 Exchange Online"
ConditionalAccessStatus == "success" |
- |
1 |
- |
- |
1 |
ResultType in "50125,50140,70043,70044" |
- |
1 |
- |
- |
1 |
ResourceIdentity == "00000007-0000-0000-c000-000000000000"
ResultType == "0" |
- |
1 |
- |
- |
1 |
AuthenticationRequirement == "singleFactorAuthentication"
ResourceIdentity == "00000007-0000-0000-c000-000000000000"
ResultType == "0" |
- |
1 |
- |
- |
1 |
RiskDetail != "none" |
- |
1 |
- |
- |
1 |
OperationName in "PutBlob,PutRange" |
- |
1 |
- |
- |
1 |
OperationName == "Add member to role." |
- |
1 |
- |
- |
1 |
AuthenticationDetails has "deviceCode"
ResultType == "0" |
- |
1 |
- |
- |
1 |
NetworkLocationDetails == "[]"
RiskLevelDuringSignIn == "high" |
- |
1 |
- |
- |
1 |
ConditionalAccessStatus == "success" |
- |
1 |
- |
- |
1 |
AppDisplayName !in "Office 365 Exchange Online,Skype for Business Online,Office 365 SharePoint Online" |
- |
1 |
- |
- |
1 |
AppDisplayName == "Azure Portal"
OperationName has_any "Add member to role" |
- |
1 |
- |
- |
1 |
OperationName == "Sign-in activity" |
- |
1 |
- |
- |
1 |
OperationName == "Add user" |
- |
1 |
- |
- |
1 |
ResultType in "0,50057,50074,50126,51004" |
- |
1 |
- |
- |
1 |
AppDisplayName contains "Azure Portal"
ResultType in "50020,50126" |
- |
1 |
- |
- |
1 |
OperationName in "Add member to role,Add user,AzureFirewallIDSLog,NetworkSecurityGroupEvents,Reset user password,Update user"
OperationName contains "PIM"
OperationName contains "create"
OperationName contains "delete"
OperationName contains "lockbox"
OperationName contains "remove"
OperationName contains "update" |
- |
1 |
- |
- |
1 |
OperationName contains "PIM" |
- |
1 |
- |
- |
1 |
AuthenticationRequirement == "multiFactorAuthentication"
OperationName in "Add member to role,Add user,NetworkSecurityGroupEvents,Reset user password,Update user"
OperationName contains "Add"
OperationName contains "Audit"
OperationName contains "Change"
OperationName contains "Create"
OperationName contains "Delete"
OperationName contains "Log"
OperationName contains "Monitor"
OperationName contains "PIM"
OperationName contains "Remove"
OperationName contains "Update"
OperationName contains "Write"
OperationName contains "reset" |
- |
1 |
- |
- |
1 |
OperationName in "Add app role assignment to service principal,Add delegated permission grant,Add service principal credentials,Admin deleted security info,Admin registered security info,Admin updated security info,Consent to application,GetBlob,ListBlobs,ListBlobsHierarchySegment,ListContainersSegment,Set domain authentication,Set federation settings on domain,User changed default security info,User deleted security info,User registered security info,User updated security info"
OperationName has_any "clusterrolebindings,rolebindings"
OperationName has_any "cronjobs,daemonsets"
OperationName has_any "cronjobs/create,daemonsets/create" |
- |
1 |
- |
- |
1 |
AppDisplayName in "Azure Active Directory PowerShell,Microsoft Azure CLI"
AppDisplayName contains "ACOM"
AppDisplayName contains "CLI"
AppDisplayName contains "PowerShell"
AppDisplayName contains "command"
AppDisplayName contains "graph"
OperationName in "Add member to role,Add user,ApplicationGatewayFirewall,AzureFirewallIDSLog,Reset user password,Update user"
OperationName !contains "external"
OperationName !contains "invite"
OperationName !contains "licnense"
OperationName contains "group"
OperationName contains "member"
OperationName contains "principal"
OperationName contains "role"
OperationName contains "user" |
- |
1 |
- |
- |
1 |
OperationName in "Add conditional access policy,Add member to group,Add member to restricted management administrative unit,Delete conditional access policy,Remove member from group,Remove member from restricted management administrative unit,Update conditional access policy,Update group" |
- |
1 |
- |
- |
1 |
AppDisplayName contains "Portal"
OperationName in "Add member to role,Add user,Consent to application,Create Deployment,Create or Update Virtual Machine,Create role assignment,List Storage Account Keys,Reset user password,Update user"
OperationName in "Set domain authentication,Set federation settings on domain,Sign-in activity"
OperationName != "Consent to application"
OperationName contains "Create"
OperationName contains "Delete"
OperationName contains "Update"
OperationName contains "delet"
OperationName contains "delete"
OperationName contains "remove"
OperationName has "Create"
OperationName has_any "Create,Update"
OperationName has_any "Ip,Security Rule" |
- |
1 |
- |
- |
1 |
OperationName contains "Delete"
OperationName contains "PIM"
OperationName contains "Remove" |
- |
1 |
- |
- |
1 |
AppDisplayName == "Windows Sign In"
OperationName == "Consent to application"
OperationName == "Disable Strong Authentication"
OperationName contains "password" |
- |
1 |
- |
- |
1 |
AppDisplayName startswith "Microsoft Teams"
ResultType == "0"
ResultType !in "0,50140" |
- |
1 |
- |
- |
1 |
ResultType == "0"
ResultType != "0" |
- |
1 |
- |
- |
1 |
AppDisplayName has_any "teams"
OperationName in "Add member to role,Add user,ApplicationGatewayFirewall,AzureFirewallIDSLog,AzureFirewallThreatIntelLog,NetworkSecurityGroupEvents,Reset user password,Update user"
OperationName contains "PIM" |
- |
1 |
- |
- |
1 |
| Total |
0 |
62 |
0 |
0 |
62 |
AppDisplayName
| Value |
Connectors |
Content Items |
ASIM Parsers |
Other Parsers |
Total |
Windows Sign In |
- |
2 |
- |
- |
2 |
Azure Portal |
- |
2 |
- |
- |
2 |
ADFS Trust |
- |
1 |
- |
- |
1 |
Microsoft Azure PowerShell |
- |
1 |
- |
- |
1 |
Office 365 Exchange Online |
- |
1 |
- |
- |
1 |
!= Office 365 Exchange Online |
- |
1 |
- |
- |
1 |
!= Skype for Business Online |
- |
1 |
- |
- |
1 |
!= Office 365 SharePoint Online |
- |
1 |
- |
- |
1 |
contains Azure Portal |
- |
1 |
- |
- |
1 |
Azure Active Directory PowerShell |
- |
1 |
- |
- |
1 |
Microsoft Azure CLI |
- |
1 |
- |
- |
1 |
contains ACOM |
- |
1 |
- |
- |
1 |
contains CLI |
- |
1 |
- |
- |
1 |
contains PowerShell |
- |
1 |
- |
- |
1 |
contains command |
- |
1 |
- |
- |
1 |
contains graph |
- |
1 |
- |
- |
1 |
contains Portal |
- |
1 |
- |
- |
1 |
startswith Microsoft Teams |
- |
1 |
- |
- |
1 |
has_any teams |
- |
1 |
- |
- |
1 |
AuthenticationDetails
| Value |
Connectors |
Content Items |
ASIM Parsers |
Other Parsers |
Total |
has deviceCode |
- |
1 |
- |
- |
1 |
AuthenticationRequirement
| Value |
Connectors |
Content Items |
ASIM Parsers |
Other Parsers |
Total |
multiFactorAuthentication |
- |
4 |
- |
- |
4 |
singleFactorAuthentication |
- |
2 |
- |
- |
2 |
ConditionalAccessStatus
| Value |
Connectors |
Content Items |
ASIM Parsers |
Other Parsers |
Total |
success |
- |
2 |
- |
- |
2 |
NetworkLocationDetails
| Value |
Connectors |
Content Items |
ASIM Parsers |
Other Parsers |
Total |
!has trustedNamedLocation |
- |
1 |
- |
- |
1 |
[] |
- |
1 |
- |
- |
1 |
OperationName
| Value |
Connectors |
Content Items |
ASIM Parsers |
Other Parsers |
Total |
Update user |
- |
8 |
- |
- |
8 |
Add user |
- |
8 |
- |
- |
8 |
Add member to role |
- |
7 |
- |
- |
7 |
Reset user password |
- |
7 |
- |
- |
7 |
contains PIM |
- |
5 |
- |
- |
5 |
Consent to application |
- |
5 |
- |
- |
5 |
Sign-in activity |
- |
4 |
- |
- |
4 |
AzureFirewallIDSLog |
- |
3 |
- |
- |
3 |
NetworkSecurityGroupEvents |
- |
3 |
- |
- |
3 |
contains Delete |
- |
3 |
- |
- |
3 |
!= Consent to application |
- |
3 |
- |
- |
3 |
contains delete |
- |
2 |
- |
- |
2 |
contains remove |
- |
2 |
- |
- |
2 |
contains Create |
- |
2 |
- |
- |
2 |
contains Remove |
- |
2 |
- |
- |
2 |
contains Update |
- |
2 |
- |
- |
2 |
Set domain authentication |
- |
2 |
- |
- |
2 |
Set federation settings on domain |
- |
2 |
- |
- |
2 |
ApplicationGatewayFirewall |
- |
2 |
- |
- |
2 |
PutBlob |
- |
1 |
- |
- |
1 |
PutRange |
- |
1 |
- |
- |
1 |
Add member to role. |
- |
1 |
- |
- |
1 |
has_any Add member to role |
- |
1 |
- |
- |
1 |
contains create |
- |
1 |
- |
- |
1 |
contains lockbox |
- |
1 |
- |
- |
1 |
contains update |
- |
1 |
- |
- |
1 |
contains Add |
- |
1 |
- |
- |
1 |
contains Audit |
- |
1 |
- |
- |
1 |
contains Change |
- |
1 |
- |
- |
1 |
contains Log |
- |
1 |
- |
- |
1 |
contains Monitor |
- |
1 |
- |
- |
1 |
contains Write |
- |
1 |
- |
- |
1 |
contains reset |
- |
1 |
- |
- |
1 |
Add app role assignment to service principal |
- |
1 |
- |
- |
1 |
Add delegated permission grant |
- |
1 |
- |
- |
1 |
Add service principal credentials |
- |
1 |
- |
- |
1 |
Admin deleted security info |
- |
1 |
- |
- |
1 |
Admin registered security info |
- |
1 |
- |
- |
1 |
Admin updated security info |
- |
1 |
- |
- |
1 |
GetBlob |
- |
1 |
- |
- |
1 |
ListBlobs |
- |
1 |
- |
- |
1 |
ListBlobsHierarchySegment |
- |
1 |
- |
- |
1 |
ListContainersSegment |
- |
1 |
- |
- |
1 |
User changed default security info |
- |
1 |
- |
- |
1 |
User deleted security info |
- |
1 |
- |
- |
1 |
User registered security info |
- |
1 |
- |
- |
1 |
User updated security info |
- |
1 |
- |
- |
1 |
has_any clusterrolebindings |
- |
1 |
- |
- |
1 |
has_any rolebindings |
- |
1 |
- |
- |
1 |
has_any cronjobs |
- |
1 |
- |
- |
1 |
has_any daemonsets |
- |
1 |
- |
- |
1 |
has_any cronjobs/create |
- |
1 |
- |
- |
1 |
has_any daemonsets/create |
- |
1 |
- |
- |
1 |
!contains external |
- |
1 |
- |
- |
1 |
!contains invite |
- |
1 |
- |
- |
1 |
!contains licnense |
- |
1 |
- |
- |
1 |
contains group |
- |
1 |
- |
- |
1 |
contains member |
- |
1 |
- |
- |
1 |
contains principal |
- |
1 |
- |
- |
1 |
contains role |
- |
1 |
- |
- |
1 |
contains user |
- |
1 |
- |
- |
1 |
Add conditional access policy |
- |
1 |
- |
- |
1 |
Add member to group |
- |
1 |
- |
- |
1 |
Add member to restricted management administrative unit |
- |
1 |
- |
- |
1 |
Delete conditional access policy |
- |
1 |
- |
- |
1 |
Remove member from group |
- |
1 |
- |
- |
1 |
Remove member from restricted management administrative unit |
- |
1 |
- |
- |
1 |
Update conditional access policy |
- |
1 |
- |
- |
1 |
Update group |
- |
1 |
- |
- |
1 |
Create Deployment |
- |
1 |
- |
- |
1 |
Create or Update Virtual Machine |
- |
1 |
- |
- |
1 |
Create role assignment |
- |
1 |
- |
- |
1 |
List Storage Account Keys |
- |
1 |
- |
- |
1 |
contains delet |
- |
1 |
- |
- |
1 |
has Create |
- |
1 |
- |
- |
1 |
has_any Create |
- |
1 |
- |
- |
1 |
has_any Update |
- |
1 |
- |
- |
1 |
has_any Ip |
- |
1 |
- |
- |
1 |
has_any Security Rule |
- |
1 |
- |
- |
1 |
Disable Strong Authentication |
- |
1 |
- |
- |
1 |
contains password |
- |
1 |
- |
- |
1 |
AzureFirewallThreatIntelLog |
- |
1 |
- |
- |
1 |
ResourceIdentity
| Value |
Connectors |
Content Items |
ASIM Parsers |
Other Parsers |
Total |
00000007-0000-0000-c000-000000000000 |
- |
3 |
- |
- |
3 |
ResultType
| Value |
Connectors |
Content Items |
ASIM Parsers |
Other Parsers |
Total |
0 |
- |
24 |
- |
- |
24 |
50057 |
- |
5 |
- |
- |
5 |
!= 0 |
- |
3 |
- |
- |
3 |
50125 |
- |
2 |
- |
- |
2 |
50140 |
- |
2 |
- |
- |
2 |
50053 |
- |
2 |
- |
- |
2 |
50126 |
- |
2 |
- |
- |
2 |
500121 |
- |
1 |
- |
- |
1 |
70043 |
- |
1 |
- |
- |
1 |
70044 |
- |
1 |
- |
- |
1 |
50074 |
- |
1 |
- |
- |
1 |
51004 |
- |
1 |
- |
- |
1 |
50020 |
- |
1 |
- |
- |
1 |
!= 50140 |
- |
1 |
- |
- |
1 |
RiskDetail
| Value |
Connectors |
Content Items |
ASIM Parsers |
Other Parsers |
Total |
!= none |
- |
1 |
- |
- |
1 |
RiskLevelAggregated
| Value |
Connectors |
Content Items |
ASIM Parsers |
Other Parsers |
Total |
!= none |
- |
2 |
- |
- |
2 |
high |
- |
1 |
- |
- |
1 |
RiskLevelDuringSignIn
| Value |
Connectors |
Content Items |
ASIM Parsers |
Other Parsers |
Total |
high |
- |
2 |
- |
- |
2 |
RiskState
| Value |
Connectors |
Content Items |
ASIM Parsers |
Other Parsers |
Total |
atRisk |
- |
2 |
- |
- |
2 |
Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊
↑ Back to Tables Index