Solution: Uniqkey
Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊
| Attribute | Value |
|---|---|
| Publisher | Uniqkey |
| Support Tier | Partner |
| Support Link | https://uniqkey.eu/ |
| Categories | Identity,Security - Others |
| Version | 3.0.0 |
| Author | Uniqkey - support@uniqkey.eu |
| First Published | 2026-08-25 |
| Last Updated | 2026-09-01 |
| Solution Folder | Uniqkey |
| Marketplace | Azure Marketplace · Popularity: 🟢 High (84%) |
The Uniqkey solution for Microsoft Sentinel enables ingestion of security and audit events from the Uniqkey business password management platform. Events cover authentication, credential access, credential management, sharing, policy management, threat detection and other administrative activity, giving security teams visibility into password and access hygiene across the organization.
Underlying Microsoft Technologies used:
This solution takes a dependency on the following technologies, and some of these dependencies either may be in Preview state or might result in additional ingestion or operational costs:
a. Microsoft Sentinel Codeless Connector Framework
This solution provides 1 data connector(s):
This solution uses 1 table(s):
| Table | Used By Connectors | Used By Content |
|---|---|---|
UniqkeyEvents_CL |
Uniqkey Security Events | Analytics, Workbooks |
This solution includes 10 content item(s):
| Content Type | Count |
|---|---|
| Analytic Rules | 9 |
| Workbooks | 1 |
| Name | Severity | Tactics | Tables Used |
|---|---|---|---|
| Uniqkey - Credential export from newly created account | Medium | CredentialAccess, Persistence | UniqkeyEvents_CL |
| Uniqkey - Data export activity | Medium | CredentialAccess, Exfiltration | UniqkeyEvents_CL |
| Uniqkey - Departing employee credential export | High | CredentialAccess, Exfiltration | UniqkeyEvents_CL |
| Uniqkey - Event ingestion stopped | Medium | DefenseEvasion | UniqkeyEvents_CL |
| Uniqkey - Excessive credential access | Medium | CredentialAccess | UniqkeyEvents_CL |
| Uniqkey - Platform threat detection | High | InitialAccess, CredentialAccess | UniqkeyEvents_CL |
| Uniqkey - Security policy change | Medium | DefenseEvasion, Persistence | UniqkeyEvents_CL |
| Uniqkey - Self-granted privilege or access change | Medium | PrivilegeEscalation, Persistence | UniqkeyEvents_CL |
| Uniqkey - Sign-in from unfamiliar IP address | Low | InitialAccess | UniqkeyEvents_CL |
| Name | Tables Used |
|---|---|
| Uniqkey | UniqkeyEvents_CL |
📄 Source: Uniqkey/README.md
This solution ingests security and audit events from the Uniqkey business password management platform into Microsoft Sentinel using the Codeless Connector Framework (CCF).
| Component | Path | Purpose |
|---|---|---|
| Connector definition | Data Connectors/UniqkeyAuditLogs_ccf/Uniqkey_ConnectorDefinition.json |
Connector page UI in the Sentinel portal |
| Poller config | Data Connectors/UniqkeyAuditLogs_ccf/Uniqkey_PollerConfig.json |
REST API polling (bearer auth, cursor paging, time windows) |
| Data collection rule | Data Connectors/UniqkeyAuditLogs_ccf/Uniqkey_DCR.json |
Raw event to UniqkeyEvents_CL schema transformation |
| Table schema | Data Connectors/UniqkeyAuditLogs_ccf/Uniqkey_Table.json |
Custom table UniqkeyEvents_CL |
| Packaging manifest | Data/Solution_Uniqkey.json |
Input for the V3 packaging tool |
| Analytic rules | Analytic Rules/*.yaml |
9 scheduled detections (anomalous sign-in, export/exfiltration patterns, insider privilege escalation, policy changes, platform threat detections, ingestion health) |
| Workbook | Workbooks/Uniqkey.json |
Uniqkey Security Events dashboard (volume, sign-in map, client systems, top users, exports, threat detections) |
https://siem-integration.production.uniqkey.eu.Logos/Uniqkey.svg added and embedded in the connector definition.publisherId: "uniqkey" matches the Commercial Marketplace publisher ID registered in Partner Center. Support email confirmed as support@uniqkey.eu.ASimAuthentication parser under Parsers/.Workbooks/Images/Preview/UniqkeyEvents{Black,White}.png at the repository root are generated placeholders. Replace them with real screenshots (dark and light theme) of the deployed workbook.Outcome.pwsh .script/local-validation/build-and-validate.ps1 -SolutionName "Uniqkey"
| Version | Date Modified (DD-MM-YYYY) | Change History |
|---|---|---|
| 3.0.0 | 25-08-2026 | Initial release of the Uniqkey solution with a CCF data connector for Uniqkey security events |
Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊