IdentityInfo

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

Back to Tables Index


Reference for IdentityInfo table in Azure Monitor Logs.

Attribute Value
Category Internal
Basic Logs Eligible ✗ No (source)
Supports Transformations ✓ Yes (source)
Ingestion API Supported ✗ No
Azure Monitor Tables Reference View Documentation

Contents

Schema (57 columns)

Source: Azure Monitor documentation

Column Name Type Description
_BilledSize real The record size in bytes
_IsBillable string Specifies whether ingesting the data is billable. When _IsBillable is false ingestion isn't billed to your Azure account
AccountCloudSID string The Azure AD security identifier of the account
AccountCreationTime datetime The date the user account was created (UTC)
AccountDisplayName string The user account display name
AccountDomain string Domain name of the user account
AccountName string User name of the account
AccountObjectId string The Azure Active Directory object ID for the account
AccountSID string The on premises security identifier of the account
AccountTenantId string The Azure Active Directory Tenant ID of the account
AccountUPN string User principal name of the account
AdditionalMailAddresses dynamic Additional email addresses of the user
Applications string All known applications this user account accessed
AssignedRoles dynamic AAD roles the user account is assigned to
BlastRadius string The potential impact of the user account in the org (low/medium/high)
ChangeSource string The source of the latest change of the entity
City string The city of the user account as defined in AAD
CompanyName string The name for the company in which the user works.
Country string The country of the user account as defined in AAD
DeletedDateTime datetime The date and time the user was deleted
Department string The user account department as defined in AAD
EmployeeId string The employee identifier assigned to the user by the organization
EntityRiskScore dynamic The risk score of the entity as part of the UEBA scoring process
ExtensionProperty dynamic ExtensionProperty fields from Azure AD
GivenName string The user account given name
GroupMembership dynamic Azure AD Groups the user account is a member
InvestigationPriority int The Investigation Priority score of the account
InvestigationPriorityPercentile int The account score compared to the organization
IsAccountEnabled bool Indication if the account is enabled in AAD or not
IsMFARegistered bool Indication if MFA is registered for this user account or not
IsServiceAccount bool The account is a service account.
JobTitle string The user account job title as defined in AAD
LastSeenDate datetime Date of the last activity observed in this account
MailAddress string The user account primary email address
Manager string The user accounts manager alias
OnPremisesDistinguishedName string Active Directory distinguished name (DN). A DN is a sequence of relative distinguished names (RDN) connected by commas.
OnPremisesExtensionAttributes string OnPremisesExtensionAttributes field from Azure AD
Phone string The phone number of the user account as defined in AAD
RelatedAccounts dynamic Various accounts that correlate to a certain user
RiskLevel string The AAD risk level (Low/Medium/High) of the user account
RiskLevelDetails string Details regarding the AAD risk level
RiskState string Indication if the account is at risk now or if the risk was remediated
SAMAccountName string The SAM account name of the account.
ServicePrincipals dynamic Azure AD service principals that are owned by the user
SourceSystem string The type of agent the event was collected by. For example, OpsManager for Windows agent, either direct connect or Operations Manager, Linux for all Linux agents, or Azure for Azure Diagnostics
State string The geographical state of the user account as defined in AAD
StreetAddress string The office street address of the user account as defined in AAD
Surname string The user account surname
Tags string Relevant information on the user account which is important for investigation: Sensitive\ VIP\ Administrator
TenantId string The Log Analytics workspace ID
TimeGenerated datetime Time when the event was generated (UTC)
Type string The name of the table
UACFlags string User Access control flags from AD & AAD
UserAccountControl dynamic Security attributes of the user account in the AD domain
UserState string The current state in AAD of the account (Active/Disabled/Dormant/Lockout)
UserStateChangedOn datetime Date of the last time the account state was changed (UTC)
UserType string The user type as appears in Azure AD

Schema References

Official Microsoft Learn documentation for field/column information:

Solutions (19)

This table is used by the following solutions:


Content Items Using This Table (52)

Analytic Rules (13)

In solution Azure Activity:

Analytic Rule Selection Criteria
Suspicious granting of permissions to an account

In solution Business Email Compromise - Financial Fraud:

Analytic Rule Selection Criteria
Authentication Method Changed for Privileged Account
Privileged Account Permissions Changed

In solution Microsoft Defender XDR:

Analytic Rule Selection Criteria
Local Admin Group Changes

In solution Microsoft Entra ID:

Analytic Rule Selection Criteria
Authentication Methods Changed for Privileged Account
MFA Rejected by User
Privileged Accounts - Sign in Failure Spikes
Successful logon from IP and failure from a different IP
User Accounts - Sign in Failure due to CA Spikes

In solution Microsoft Entra ID Protection:

Analytic Rule Selection Criteria
Correlate Unfamiliar sign-in properties & atypical travel alerts

In solution Multi Cloud Attack Coverage Essentials - Resource Abuse:

Analytic Rule Selection Criteria
Successful AWS Console Login from IP Address Observed Conducting Password Spray
Suspicious AWS console logins by credential access alerts

In solution eDCRule:

Analytic Rule Selection Criteria
[Entra ID] Authentication Method Changed for Privileged Account

Hunting Queries (30)

In solution Business Email Compromise - Financial Fraud:

Hunting Query Selection Criteria
Login attempts using Legacy Auth
Microsoft Entra ID signins from new locations
Risky Sign-in with new MFA method
Successful Signin From Non-Compliant Device
User Accounts - Unusual authentications occurring when countries do not conduct normal business operations.
User Login IP Address Teleportation

In solution Cloud Identity Threat Protection Essentials:

Hunting Query Selection Criteria
Detect Disabled Account Sign-in Attempts by Account Name
Sign-ins From VPS Providers
Sign-ins from Nord VPN Providers
Suspicious Sign-ins to Privileged Account

In solution Hybrid Attack - Cloud & Identity:

Hunting Query Selection Criteria
AAD Connect host remote admin followed by Entra privilege operation
Entra hybrid user sign-in followed by on-prem lateral movement
Kerberoast burst followed by cloud sign-in
RDP to hybrid joined device followed by Entra access
WMI or remote admin execution on hybrid device followed by cloud sign-in

In solution Microsoft Business Applications:

Hunting Query Selection Criteria
Dataverse - Identity management activity outside of privileged directory role membership

In solution Microsoft Defender XDR:

Hunting Query Selection Criteria
Local Admin Group Changes

In solution UEBA Essentials: BlastRadius == "High"

Hunting Query
Anomalous connection from highly privileged user

GitHub Only:

Hunting Query Selection Criteria
AI Agents - Hard-coded credentials in Tools or Configuration
AI Agents - Instructions changed on previously published agent
AI Agents - MCP Tool Configured
AI Agents - Missing Tools in Instructions
AI Agents - Newly observed MCP server on existing agent
AI Agents - Organization-wide Shared
AI Agents - Orphaned Agents with Disabled Owners
AI Agents - Owner added to MCP-enabled agent
AI Agents - Published Agents with Short Instructions
AI Agents - Published Agents without Instructions
AI Agents - Sharing expanded to organization-wide
User not covered under display name impersonation

Workbooks (9)

In solution AzureSecurityBenchmark:

Workbook Selection Criteria
AzureSecurityBenchmark

In solution ContinuousDiagnostics&Mitigation:

Workbook Selection Criteria
ContinuousDiagnostics&Mitigation

In solution CybersecurityMaturityModelCertification(CMMC)2.0:

Workbook Selection Criteria
CybersecurityMaturityModelCertification_CMMCV2

In solution Hybrid Attack - Cloud & Identity:

Workbook Selection Criteria
HybridAttack-Cloud&Identity

In solution MaturityModelForEventLogManagementM2131: AssignedRoles contains "Admin"
AssignedRoles contains "admin"
AssignedRoles contains "contributor"
AssignedRoles contains "owner"

Workbook
MaturityModelForEventLogManagement_M2131

In solution MicrosoftPurviewInsiderRiskManagement: BlastRadius == "High"

Workbook
InsiderRiskManagement

In solution NISTSP80053:

Workbook Selection Criteria
NISTSP80053

In solution SOC Handbook:

Workbook Selection Criteria
InvestigationInsights

In solution ZeroTrust(TIC3.0):

Workbook Selection Criteria
ZeroTrustTIC3

Selection Criteria Summary (2 criteria, 3 total references)

References by type: 0 connectors, 3 content items, 0 ASIM parsers, 0 other parsers.

Selection Criteria Connectors Content Items ASIM Parsers Other Parsers Total
BlastRadius == "High" - 2 - - 2
AssignedRoles contains "Admin"
AssignedRoles contains "admin"
AssignedRoles contains "contributor"
AssignedRoles contains "owner"
- 1 - - 1
Total 0 3 0 0 3

AssignedRoles

Value Connectors Content Items ASIM Parsers Other Parsers Total
contains Admin - 1 - - 1
contains admin - 1 - - 1
contains contributor - 1 - - 1
contains owner - 1 - - 1

BlastRadius

Value Connectors Content Items ASIM Parsers Other Parsers Total
High - 2 - - 2

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

Back to Tables Index