AADServicePrincipalSignInLogs

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

Back to Tables Index


Reference for AADServicePrincipalSignInLogs table in Azure Monitor Logs.

Attribute Value
Category Entra
Basic Logs Eligible ✓ Yes (source)
Supports Transformations ✓ Yes (source)
Ingestion API Supported ✗ No
Lake-Only Ingestion ✓ Yes (source)
Azure Monitor Tables Reference View Documentation

Contents

Schema (46 columns)

Source: Azure Monitor documentation

Column Name Type Description
_BilledSize real The record size in bytes
_IsBillable string Specifies whether ingesting the data is billable. When _IsBillable is false ingestion isn't billed to your Azure account
AADTenantId string ID of the AAD tenant.
Agent string Details of agentic sign-in.
AppId string Unique GUID representing the app ID in the Azure Active Directory
AppOwnerTenantId string The tenant identifier of the owenr of the application in Azure Active Directory
AuthenticationContextClassReferences string The authentication contexts of the sign-in
AuthenticationProcessingDetails string Provides the details associated with authentication processor
AutonomousSystemNumber string Autonomous System Number for the network.
Category string Category of the sign-in event
ClientCredentialType string The type of client credential used. Examples include client assertion, client secret, etc.
ConditionalAccessAudiences string Details of the conditional access audiences being applied for the sign-in.
ConditionalAccessPolicies string Details of the conditional access policies being applied for the sign-in
ConditionalAccessStatus string Status of all the conditionalAccess policies related to the sign-in
CorrelationId string ID to provide sign-in trail
CreatedDateTime datetime Datetime of the sign-in activity.
DurationMs long The duration of the operation in milliseconds
FederatedCredentialId string Th identifier of an application's federated identity credential if a federated identity credential was used to sign in.
Id string Unique ID representing the sign-in activity
Identity string The identity from the token that was presented when you made the request. It can be a user account, system account, or service principal
IPAddress string IP address of the client used to sign in
Level string The severity level of the event
Location string The region of the resource emitting the event
LocationDetails string Details of the sign-in location
NetworkLocationDetails string Provides the details associated with Authentication processor.
OperationName string For sign-ins, this value is always Sign-in activity
OperationVersion string The REST API version that's requested by the client
ResourceDisplayName string Name of the resource that the service principal signed into
ResourceGroup string Resource group for the logs
ResourceIdentity string ID of the resource that the service principal signed into
ResourceOwnerTenantId string The tenant identifier of the owner of the resource referenced in the sign in
ResourceServicePrincipalId string Service Principal Id of the resource
ResultDescription string Provides the error description for the sign-in operation
ResultSignature string Contains the error code, if any, for the sign-in operation
ResultType string The result of the sign-in operation can be Success or Failure
ServicePrincipalCredentialKeyId string Key id of the service principal that initiated the sign-in
ServicePrincipalCredentialThumbprint string Thumbprint of the service principal that initiated the sign-in
ServicePrincipalId string ID of the service principal who initiated the sign-in
ServicePrincipalName string Service Principal Name of the service principal who initiated the sign-in
SessionId string Id of the session that was generated during the signIn.
SourceSystem string The type of agent the event was collected by. For example, OpsManager for Windows agent, either direct connect or Operations Manager, Linux for all Linux agents, or Azure for Azure Diagnostics
TenantId string The Log Analytics workspace ID
TimeGenerated datetime The date and time of the event in UTC
Type string The name of the table
UniqueTokenIdentifier string Unique token identifier for the request
UserAgent string User Agent for the sign-in

Schema References

Official Microsoft Learn documentation for field/column information:

Solutions (6)

This table is used by the following solutions:

Connectors (1)

This table is ingested by the following connectors:

Connector Selection Criteria
Microsoft Entra ID

Content Items Using This Table (14)

Analytic Rules (2)

In solution Lumen Defender Threat Feed:

Analytic Rule Selection Criteria
Lumen TI IPAddress in IdentityLogonEvents

In solution Microsoft Entra ID: OperationName == "Remove service principal"
OperationName has_all "Update application"

Analytic Rule
Suspicious Service Principal creation activity

Hunting Queries (7)

In solution Hybrid Attack - Cloud & Identity:

Hunting Query Selection Criteria
Key Vault harvest to SPN sign-in then out-of-scope resource access
Key Vault secret harvest followed by novel SPN sign-in from non-1P IP
Novel SPN sign-in followed by Azure RBAC write
Novel identity then Key Vault secret burst
Secret Added to Dormant Service Principal
Service principal Conditional Access anomaly ConditionalAccessStatus in "failure,notApplied"
ResultType in "0,Success"
Service principal credential change followed by novel SP sign-in

Workbooks (5)

In solution AzureSecurityBenchmark:

Workbook Selection Criteria
AzureSecurityBenchmark

In solution CybersecurityMaturityModelCertification(CMMC)2.0:

Workbook Selection Criteria
CybersecurityMaturityModelCertification_CMMCV2

In solution Hybrid Attack - Cloud & Identity: OperationName in "Add app role assignment to service principal,Add delegated permission grant,Add service principal credentials,Admin deleted security info,Admin registered security info,Admin updated security info,Consent to application,GetBlob,ListBlobs,ListBlobsHierarchySegment,ListContainersSegment,Set domain authentication,Set federation settings on domain,User changed default security info,User deleted security info,User registered security info,User updated security info"
OperationName has_any "clusterrolebindings,rolebindings"
OperationName has_any "cronjobs,daemonsets"
OperationName has_any "cronjobs/create,daemonsets/create"

Workbook
HybridAttack-Cloud&Identity

In solution MaturityModelForEventLogManagementM2131:

Workbook Selection Criteria
MaturityModelForEventLogManagement_M2131

In solution Microsoft Entra ID: OperationName in "Add conditional access policy,Add member to group,Add member to restricted management administrative unit,Delete conditional access policy,Remove member from group,Remove member from restricted management administrative unit,Update conditional access policy,Update group"

Workbook
ConditionalAccessSISM

Parsers Using This Table (1)

ASIM Parsers (1)

Parser Schema Product Selection Criteria
ASimAuthenticationAADServicePrincipalSignInLogs Authentication Microsoft Entra ID

Selection Criteria Summary (4 criteria, 4 total references)

References by type: 0 connectors, 4 content items, 0 ASIM parsers, 0 other parsers.

Selection Criteria Connectors Content Items ASIM Parsers Other Parsers Total
OperationName == "Remove service principal"
OperationName has_all "Update application"
- 1 - - 1
ConditionalAccessStatus in "failure,notApplied"
ResultType in "0,Success"
- 1 - - 1
OperationName in "Add app role assignment to service principal,Add delegated permission grant,Add service principal credentials,Admin deleted security info,Admin registered security info,Admin updated security info,Consent to application,GetBlob,ListBlobs,ListBlobsHierarchySegment,ListContainersSegment,Set domain authentication,Set federation settings on domain,User changed default security info,User deleted security info,User registered security info,User updated security info"
OperationName has_any "clusterrolebindings,rolebindings"
OperationName has_any "cronjobs,daemonsets"
OperationName has_any "cronjobs/create,daemonsets/create"
- 1 - - 1
OperationName in "Add conditional access policy,Add member to group,Add member to restricted management administrative unit,Delete conditional access policy,Remove member from group,Remove member from restricted management administrative unit,Update conditional access policy,Update group" - 1 - - 1
Total 0 4 0 0 4

ConditionalAccessStatus

Value Connectors Content Items ASIM Parsers Other Parsers Total
failure - 1 - - 1
notApplied - 1 - - 1

OperationName

Value Connectors Content Items ASIM Parsers Other Parsers Total
Remove service principal - 1 - - 1
has_all Update application - 1 - - 1
Add app role assignment to service principal - 1 - - 1
Add delegated permission grant - 1 - - 1
Add service principal credentials - 1 - - 1
Admin deleted security info - 1 - - 1
Admin registered security info - 1 - - 1
Admin updated security info - 1 - - 1
Consent to application - 1 - - 1
GetBlob - 1 - - 1
ListBlobs - 1 - - 1
ListBlobsHierarchySegment - 1 - - 1
ListContainersSegment - 1 - - 1
Set domain authentication - 1 - - 1
Set federation settings on domain - 1 - - 1
User changed default security info - 1 - - 1
User deleted security info - 1 - - 1
User registered security info - 1 - - 1
User updated security info - 1 - - 1
has_any clusterrolebindings - 1 - - 1
has_any rolebindings - 1 - - 1
has_any cronjobs - 1 - - 1
has_any daemonsets - 1 - - 1
has_any cronjobs/create - 1 - - 1
has_any daemonsets/create - 1 - - 1
Add conditional access policy - 1 - - 1
Add member to group - 1 - - 1
Add member to restricted management administrative unit - 1 - - 1
Delete conditional access policy - 1 - - 1
Remove member from group - 1 - - 1
Remove member from restricted management administrative unit - 1 - - 1
Update conditional access policy - 1 - - 1
Update group - 1 - - 1

ResultType

Value Connectors Content Items ASIM Parsers Other Parsers Total
0 - 1 - - 1
Success - 1 - - 1

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

Back to Tables Index