Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊
Spycloud Conditional access playbook
| Attribute | Value |
|---|---|
| Type | Playbook |
| Solution | SpyCloud Enterprise Protection CCF |
| Source | View on GitHub |
This playbook uses 3 Logic App connectors / built-in actions:
| Connector / Action | Type | Connections | Actions |
|---|---|---|---|
azuresentinel |
Managed | 1 | 4 |
office365 |
Managed | 1 | 1 |
http |
Built-in | 0 | 7 |
azuresentinel (Managed)| Action | Method | Endpoint | Other |
|---|---|---|---|
| Entities_-_Get_Accounts | post | /entities/account |
— |
| Add_comment_to_incident | post | /Incidents/Comment |
— |
| Add_comment_to_incident_-_Password_Latest | post | /Incidents/Comment |
— |
| Add_comment_to_incident_-_user_disable | post | /Incidents/Comment |
— |
office365 (Managed)| Action | Method | Endpoint | Other |
|---|---|---|---|
| Send_an_email_-to_manager | post | /v2/Mail |
— |
http (Built-in)| Action | Method | Endpoint | Other |
|---|---|---|---|
| Get_User_Details | GET | https://graph.microsoft.com/v1.0/users/@{variables('user_email')}?$select=id,displayName,accountEnabled,lastPasswordChangeDateTime,userPrincipalName |
— |
| Add_user_to_Conditional_Access_Group | POST | https://graph.microsoft.com/v1.0/groups/@{parameters('Azure_CA_Group_Object_ID')}/members/$ref |
— |
| HTTP_-_Disable_User | PATCH | https://graph.microsoft.com/v1.0/users/@{variables('user_email')} |
— |
| HTTP_-_Revoke_User_Sessions | POST | https://graph.microsoft.com/v1.0/users/@{variables('user_email')}/revokeSignInSessions |
— |
| Force_Password_Reset | PATCH | https://graph.microsoft.com/v1.0/users/@{variables('user_email')} |
— |
| GetAccessToken | POST | @concat(variables('loginUrl'), parameters('TenantID'), '/oauth2/v2.0/token') |
— |
| Log_ingestion | POST | @variables('log_ingestion_api') |
— |
This playbook automates Azure AD / Entra ID identity response actions when SpyCloud breach data identifies compromised user credentials.
Capabilities
SpyCloud_ConditionalAccessLogsV2_CLSpyCloud_ConditionalAccessLogsV2_CL (Section 2.2)azuredeploy.json)office365 and azuresentinel API connections created by the deploymentAll other settings are workflow parameters, baked into the Logic App with default values. After the playbook is deployed, update them with your own values:
SpyCloud_Conditional_Access_Playbook playbook — or go directly to the Logic App resource in the Azure Portal| Parameter | Type | Default | Description |
|---|---|---|---|
| Notify_Users_Emails | String | (empty) | Email address(es) for notifications, semicolon-separated |
| Force_Password_Reset_On_Next_SignIn | Bool | false | Forces password reset at next sign-in for affected users |
| Disable_User | Bool | false | Disables affected Azure AD user accounts |
| Add_User_To_Azure_CA_Group | Bool | false | Adds affected users to the Conditional Access enforcement group |
| Azure_CA_Group_Object_ID | String | (empty) | Object ID of the Azure AD Conditional Access group |
| Revoke_User_Sessions | Bool | false | Revokes all active sign-in sessions for affected users |
| ClientID | String | (empty) | App Registration Client ID |
| TenantID | String | (empty) | Azure Tenant ID |
| ClientSecret | String | (empty) | App Registration Client Secret |
| DCE_Endpoint | String | (empty) | DCE Logs Ingestion Endpoint URL for CA logs |
| DCE_Immutable_ID | String | (empty) | DCR Immutable ID for SpyCloud_ConditionalAccessLogsV2_CL |
| Custom_Table_Name | String | SpyCloud_ConditionalAccessLogsV2_CL | Custom Log Analytics table for playbook logs |
After saving workflow parameters, confirm SpyCloud_Conditional_Access_Playbook shows status Enabled and check Run History for immediate failures.
Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊
↑ Back to Playbooks · Back to SpyCloud Enterprise Protection CCF