SpyCloud Conditional Access Playbook

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

↑ Back to Content Index


Spycloud Conditional access playbook

Attribute Value
Type Playbook
Solution SpyCloud Enterprise Protection CCF
Source View on GitHub

Logic App Connectors

This playbook uses 3 Logic App connectors / built-in actions:

Connector / Action Type Connections Actions
azuresentinel Managed 1 4
office365 Managed 1 1
http Built-in 0 7
Action parameters (URLs, paths, function IDs)

azuresentinel (Managed)

Action Method Endpoint Other
Entities_-_Get_Accounts post /entities/account —
Add_comment_to_incident post /Incidents/Comment —
Add_comment_to_incident_-_Password_Latest post /Incidents/Comment —
Add_comment_to_incident_-_user_disable post /Incidents/Comment —

office365 (Managed)

Action Method Endpoint Other
Send_an_email_-to_manager post /v2/Mail —

http (Built-in)

Action Method Endpoint Other
Get_User_Details GET https://graph.microsoft.com/v1.0/users/@{variables('user_email')}?$select=id,displayName,accountEnabled,lastPasswordChangeDateTime,userPrincipalName —
Add_user_to_Conditional_Access_Group POST https://graph.microsoft.com/v1.0/groups/@{parameters('Azure_CA_Group_Object_ID')}/members/$ref —
HTTP_-_Disable_User PATCH https://graph.microsoft.com/v1.0/users/@{variables('user_email')} —
HTTP_-_Revoke_User_Sessions POST https://graph.microsoft.com/v1.0/users/@{variables('user_email')}/revokeSignInSessions —
Force_Password_Reset PATCH https://graph.microsoft.com/v1.0/users/@{variables('user_email')} —
GetAccessToken POST @concat(variables('loginUrl'), parameters('TenantID'), '/oauth2/v2.0/token') —
Log_ingestion POST @variables('log_ingestion_api') —

Additional Documentation

📄 Source: SpyCloud_Conditional_Access_Playbook/readme.md

This playbook automates Azure AD / Entra ID identity response actions when SpyCloud breach data identifies compromised user credentials.

Capabilities

Prerequisites

Deployment

  1. In the Azure Portal, navigate to Deploy a custom template
  2. Select this template (azuredeploy.json)
  3. Confirm Subscription, Resource Group, and Region
  4. Enter a value for PlaybookName (this is the only ARM deployment-time parameter)
  5. Click Review + Create, then Create
  6. Authorize the office365 and azuresentinel API connections created by the deployment

Post-deployment configuration

All other settings are workflow parameters, baked into the Logic App with default values. After the playbook is deployed, update them with your own values:

  1. Navigate to the Microsoft Sentinel workspace, open Automation, and select the SpyCloud_Conditional_Access_Playbook playbook — or go directly to the Logic App resource in the Azure Portal
  2. Open the Logic App and click Edit to open the workflow designer
  3. Open the Parameters section (in the designer toolbar, or under Development Tools → Workflow parameters)
  4. For each parameter listed below, enter the appropriate value for your environment
  5. Click Save to apply the changes to the playbook
Parameter Type Default Description
Notify_Users_Emails String (empty) Email address(es) for notifications, semicolon-separated
Force_Password_Reset_On_Next_SignIn Bool false Forces password reset at next sign-in for affected users
Disable_User Bool false Disables affected Azure AD user accounts
Add_User_To_Azure_CA_Group Bool false Adds affected users to the Conditional Access enforcement group
Azure_CA_Group_Object_ID String (empty) Object ID of the Azure AD Conditional Access group
Revoke_User_Sessions Bool false Revokes all active sign-in sessions for affected users
ClientID String (empty) App Registration Client ID
TenantID String (empty) Azure Tenant ID
ClientSecret String (empty) App Registration Client Secret
DCE_Endpoint String (empty) DCE Logs Ingestion Endpoint URL for CA logs
DCE_Immutable_ID String (empty) DCR Immutable ID for SpyCloud_ConditionalAccessLogsV2_CL
Custom_Table_Name String SpyCloud_ConditionalAccessLogsV2_CL Custom Log Analytics table for playbook logs

After saving workflow parameters, confirm SpyCloud_Conditional_Access_Playbook shows status Enabled and check Run History for immediate failures.


Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

↑ Back to Playbooks · Back to SpyCloud Enterprise Protection CCF