Signin Logs with expanded Conditional Access Policies

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

Back to Content Index


Example query for SigninLogs showing how to break out packed fields. In this case extending conditional access Policies

Attribute Value
Type Hunting Query
Solution Standalone Content
ID 4eb6d052-9873-4092-b989-66eae780e203
Tactics Impact
Required Connectors AzureActiveDirectory
Source [View on GitHub](https://github.com/Azure/Azure-Sentinel/blob/master/Hunting Queries/SigninLogs/SignInLogsWithExpandedPolicies.yaml)

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

Back to Hunting Queries