SigninLogs

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

↑ Back to Tables Index


Reference for SigninLogs table in Azure Monitor Logs.

Attribute Value
Category Azure Resources, Security
Basic Logs Eligible ✓ Yes (source)
Supports Transformations ✓ Yes (source)
Ingestion API Supported ✗ No
Lake-Only Ingestion ✓ Yes (source)
Azure Monitor Tables Reference View Documentation

Contents

Schema (97 columns)

Source: Azure Monitor documentation

Column Name Type Description
_BilledSize real The record size in bytes
_IsBillable string Specifies whether ingesting the data is billable. When _IsBillable isfalseingestion isn't billed to your Azure account
AADTenantId string
Agent dynamic The agentic property for sign in logs. Includes the agentType and the parentAppId when the type is AgenticInstance.
AlternateSignInName string The identification that the user provided to sign in. It may be the userPrincipalName but it's also populated when a user signs in using other identifiers.
AppDisplayName string The application name displayed in the Azure Portal.
AppId string The application identifier in Microsoft Entra ID.
AppliedConditionalAccessPolicies string
AppliedEventListeners dynamic Detailed information about the listeners, such as Azure Logic Apps and Azure Functions, that were triggered by the corresponding events in the sign-in event.
AppOwnerTenantId string The tenant identifier of the owenr of the application in Microsoft Entra ID.
AuthenticationAppDeviceDetails string Details of the app and device state used during the most recent authentication step using an authentication app.
AuthenticationAppPolicyEvaluationDetails string The details of the policies applied and enforced related to the authentication app during the latest signIn step.
AuthenticationContextClassReferences string Contains a collection of values that represent the conditional access authentication contexts applied to the sign-in.
AuthenticationDetails string The result of the authentication attempt and additional details on the authentication method.
AuthenticationMethodsUsed string The authentication methods used. Possible values: SMS, Authenticator App, App Verification code, Password, FIDO, PTA, or PHS.
AuthenticationProcessingDetails string Additional authentication processing details, such as the agent name in case of PTA/PHS or Server/farm name in case of federated authentication.
AuthenticationProtocol string Lists the protocol type or grant type used in the authentication. The possible values are: none, oAuth2, ropc, wsFederation, saml20, deviceCode. For authentications that use protocols other than the possible values listed, the protocol type is listed as none.
AuthenticationRequirement string This holds the highest level of authentication needed through all the sign-in steps, for sign-in to succeed.
AuthenticationRequirementPolicies string Sources of authentication requirement, such as conditional access, per-user MFA, identity protection, and security defaults.
AuthenticatorAppLocation string The location of the authenticator app.
AutonomousSystemNumber string The Autonomous System Number (ASN) of the network used by the actor.
Category string
ClientAppUsed string The legacy client used for sign-in activity. For example: Browser, Exchange ActiveSync, Modern clients, IMAP, MAPI, SMTP, or POP.
ClientCredentialType string The type of client credential used. Examples include client assertion, client secret, etc.
ClientSessionId string ID of the client session associated with the signIn.
ConditionalAccessAudiences string The audiences targeted by the conditional access policy.
ConditionalAccessPolicies dynamic A list of conditional access policies that are triggered by the corresponding sign-in activity.
ConditionalAccessStatus string The status of the conditional access policy triggered. Possible values: success, failure, or notApplied.
CorrelationId string The identifier that's sent from the client when sign-in is initiated. This is used for troubleshooting the corresponding sign-in activity when calling for support.
CreatedDateTime datetime The date and time the sign-in was initiated. The Timestamp type is always in UTC time. For example, midnight UTC on Jan 1, 2014 is 2014-01-01T00:00:00Z.
CrossTenantAccessType string Describes the type of cross-tenant access used by the actor to access the resource.
DeviceDetail dynamic The device information from where the sign-in occurred. Includes information such as deviceId, OS, and browser.
DurationMs long
FederatedCredentialId string Federated Credential Id.
FlaggedForReview bool During a failed sign in, a user may click a button in the Azure portal to mark the failed event for tenant admins. If a user clicked the button to flag the failed sign in, this value is true.
GlobalSecureAccessIpAddress string Global secure IP address that user signed in from.
HomeTenantId string The tenant identifier of the user initiating the sign in. Not applicable in Managed Identity or service principal sign ins.
HomeTenantName string The tenant name of the external tenant who homes the entitity taking action in the customer's tenant.
Id string The identifier representing the sign-in activity.
Identity string The display name of the actor identified in the signin.
IncomingTokenType string The type of token utilized to signIn (examples: primary refresh token, saml assertion).
IPAddress string The IP address of the client from where the sign-in occurred.
IPAddressFromResourceProvider string The IP address a user used to reach a resource provider, used to determine Conditional Access compliance for some policies. For example, when a user interacts with Exchange Online, the IP address Exchange receives from the user may be recorded here. This value is often null.
IsInteractive bool Indicates whether a user sign in is interactive. In interactive sign in, the user provides an authentication factor to Azure AD. These factors include passwords, responses to MFA challenges, biometric factors, or QR codes that a user provides to Azure AD or an associated app. In non-interactive sign in, the user doesn't provide an authentication factor. Instead, the client app uses a token or code to authenticate or access a resource on behalf of a user. Non-interactive sign ins are commonly used for a client to sign in on a user's behalf in a process transparent to the user.
IsRisky bool
IsTenantRestricted bool Indicates if a signIn is under a tenant restrictions policy or not.
IsThroughGlobalSecureAccess bool Displays whether or not a user came through Global Secure Access service or not.
Level string
Location string The 2 letter country code from where the sign-in occurred. Depending on IP address provided, this value may not always resolve to a city or region level of detail.
LocationDetails dynamic Provides the city, state, country/region and latitude and longitude from where the sign-in happened.
MfaDetail dynamic This property is deprecated.
NetworkLocationDetails string The network location details including the type of network used and its names.
OperationName string
OperationVersion string
OriginalRequestId string The request identifier of the first request in the authentication sequence.
OriginalTransferMethod string Transfer method used to initiate a session throughout all subsequent requests.
ProcessingTimeInMilliseconds string
Resource string
ResourceDisplayName string The name of the resource that the user signed in to.
ResourceGroup string
ResourceId string The identifier of the resource that the user signed in to.
ResourceIdentity string The resource that the user signed in to.
ResourceOwnerTenantId string The tenant identifier of the owner of the resource referenced in the sign in.
ResourceProvider string
ResourceServicePrincipalId string The identifier of the service principal representing the target resource in the sign-in event.
ResourceTenantId string The tenant identifier of the resource referenced in the sign in.
ResultDescription string Provides the error message or the reason for failure for the corresponding sign-in activity.
ResultSignature string
ResultType string Provides the 5-6 digit error code that's generated during a sign-in event. 0 indicates success; other values are failures. You can find more information using the Azure AD Error Codes documentation orhttps://login.microsoftonline.com/error.
RiskDetail string The reason behind a specific state of a risky user, sign-in, or a risk event. Possible values: none, adminGeneratedTemporaryPassword, userPerformedSecuredPasswordChange, userPerformedSecuredPasswordReset, adminConfirmedSigninSafe, aiConfirmedSigninSafe, userPassedMFADrivenByRiskBasedPolicy, adminDismissedAllRiskForUser, or adminConfirmedSigninCompromised. The value none means that no action has been performed on the user or sign-in so far. Note: Details for this property are only available for Azure AD Premium P2 customers. All other customers are returned hidden.
RiskEventTypes string This property is deprecated.
RiskEventTypes_V2 string The list of risk event types associated with the sign-in. Possible values: unlikelyTravel, anonymizedIPAddress, maliciousIPAddress, unfamiliarFeatures, malwareInfectedIPAddress, suspiciousIPAddress, leakedCredentials, investigationsThreatIntelligence, or generic.
RiskLevel string
RiskLevelAggregated string The aggregated risk level. Possible values: none, low, medium, high, or hidden. The value hidden means the user or sign-in was not enabled for Azure AD Identity Protection. Note: Details for this property are only available for Azure AD Premium P2 customers. All other customers are returned hidden.
RiskLevelDuringSignIn string The risk level during sign-in. Possible values: none, low, medium, high, or hidden. The value hidden means the user or sign-in was not enabled for Azure AD Identity Protection. Note: Details for this property are only available for Azure AD Premium P2 customers. All other customers are returned hidden.
RiskState string The risk state of a risky user, sign-in, or a risk event. Possible values: none, confirmedSafe, remediated, dismissed, atRisk, or confirmedCompromised.
RootActorID string The root actor virtual ID associated with the sign-in.
ServicePrincipalId string The application identifier used for sign-in. This field is populated when you are signing in using an application.
ServicePrincipalName string The application name used for sign-in. This field is populated when you are signing in using an application.
SessionId string Id of the session that was generated during the signIn.
SessionLifetimePolicies string Any conditional access session management policies that were applied during the sign-in event.
SignInIdentifier string The identification that the user provided to sign in. It may be the userPrincipalName but it's also populated when a user signs in using other identifiers.
SignInIdentifierType string The type of sign in identifier. Possible values are: userPrincipalName, phoneNumber, proxyAddress, qrCode, onPremisesUserPrincipalName.
SourceAppClientId string The Source App's Client ID for Target Identities.
SourceSystem string The type of agent the event was collected by. For example,OpsManagerfor Windows agent, either direct connect or Operations Manager,Linuxfor all Linux agents, orAzurefor Azure Diagnostics
Status dynamic The sign-in status. Includes the error code and description of the error (in case of a sign-in failure).
TimeGenerated datetime
TokenIssuerName string The name of the identity provider. For example, sts.microsoft.com.
TokenIssuerType string The type of identity provider. The possible values are: AzureAD, or ADFederationServices, AzureADBackupAuth, ADFederationServicesMFAAdapter, NPSExtension.
TokenProtectionStatusDetails dynamic Token protection creates a cryptographically secure tie between the token and the device it's issued to. This field indicates whether the signin token was bound to the device or not.
Type string The name of the table
UniqueTokenIdentifier string A unique base64 encoded request identifier used to track tokens issued by Azure AD as they are redeemed at resource providers.
UserAgent string The user agent information related to sign-in.
UserDisplayName string The display name of the user.
UserId string The identifier of the user.
UserPrincipalName string The UPN of the user.
UserType string Identifies whether the user is a member or guest in the tenant. Possible values are: member and guest.

Schema References

Official Microsoft Learn documentation for field/column information:

Solutions (39)

This table is used by the following solutions:

Connectors (1)

This table is ingested by the following connectors:

Connector Selection Criteria
Microsoft Entra ID

Content Items Using This Table (173)

Analytic Rules (47)

In solution Apache Log4j Vulnerability Detection:

Analytic Rule Selection Criteria
Log4j vulnerability exploit aka Log4Shell IP IOC
User agent search for log4j exploitation attempt

In solution FalconFriday:

Analytic Rule Selection Criteria
Expired access credentials being used in Azure
Microsoft Entra ID Rare UserAgent App Sign-in
Microsoft Entra ID UserAgent OS Missmatch

In solution GitLab: ResultType == "0"

Analytic Rule
GitLab - SSO - Sign-Ins Burst

In solution HoneyLabs:

Analytic Rule Selection Criteria
HoneyLabs TI Map IP Entity to SigninLogs

In solution Lastpass Enterprise Activity Monitoring:

Analytic Rule Selection Criteria
Failed sign-ins into LastPass due to MFA

In solution Lumen Defender Threat Feed:

Analytic Rule Selection Criteria
Lumen TI IPAddress in SigninLogs

In solution Microsoft Business Applications:

Analytic Rule Selection Criteria
Dataverse - Suspicious use of Web API ResourceIdentity == "00000007-0000-0000-c000-000000000000"
F&O - Unusual sign-in activity using single factor authentication NetworkLocationDetails !has "trustedNamedLocation"
ResultType == "0"
Power Apps - App activity from unauthorized geo
Power Platform - Possibly compromised user accesses Power Platform services

In solution Microsoft Defender XDR:

Analytic Rule Selection Criteria
Unusual Volume of file deletion by users

In solution Microsoft Entra ID:

Analytic Rule Selection Criteria
Anomalous sign-in location by user account and authenticating application
Brute force attack against an Entra-authenticated Windows device AppDisplayName == "Windows Sign In"
External guest invitation followed by Microsoft Entra ID PowerShell signin
MFA Rejected by User ResultType == "500121"
MFA Spamming followed by Successful login AuthenticationRequirement == "multiFactorAuthentication"
Password spray attack against Microsoft Entra ID Seamless SSO
Possible SignIn from Azure Backdoor

In solution MicrosoftPurviewInsiderRiskManagement: RiskState == "atRisk"

Analytic Rule
Insider Risk_Risky User Access By Application

In solution Multi Cloud Attack Coverage Essentials - Resource Abuse:

Analytic Rule Selection Criteria
Cross-Cloud Password Spray detection
Cross-Cloud Unauthorized Credential Access Detection From AWS RDS Login
High-Risk Cross-Cloud User Impersonation AppDisplayName in "ADFS Trust,Azure Portal,Microsoft Azure PowerShell"
RiskLevelAggregated == "high"
RiskLevelDuringSignIn == "high"
Unauthorized user access across AWS and Azure

In solution SecurityThreatEssentialSolution:

Analytic Rule Selection Criteria
Possible AiTM Phishing Attempt Against Microsoft Entra ID

In solution StratoSecure:

Analytic Rule Selection Criteria
SAST Auth Finding Correlated with Brute Force

In solution Threat Intelligence:

Analytic Rule Selection Criteria
TI Map IP Entity to SigninLogs
TI map Email entity to SigninLogs

In solution Threat Intelligence (NEW):

Analytic Rule Selection Criteria
TI Map Email entity to SigninLogs
TI Map IP Entity to SigninLogs

In solution eDCRule:

Analytic Rule Selection Criteria
[Entra ID] Suspicious Continuous OAuth Token Usage

Standalone Content:

Analytic Rule Selection Criteria
Account created from non-approved sources
Anomalous Single Factor Signin AuthenticationRequirement == "singleFactorAuthentication"
ResultType == "0"
Anomaly Sign In Event from an IP
Authentication Attempt from New Country
Authentications of Privileged Accounts Outside of Expected Controls ResultType == "0"
Failed AWS Console logons but success logon to AzureAD ResultType in "0,50125,50140"
High risk Office operation conducted by IP Address that recently attempted to log into a disabled account ResultType in "0,50057"
M365D Alerts Correlation to non-Microsoft Network device network activity involved in successful sign-in Activity
Malformed user agent
New country signIn with correct password ResultType != "0"
Privileged User Logon from new ASN ResultType == "0"
Risky user signin observed in non-Microsoft network device ResultType == "0"
RiskState == "atRisk"
Suspicious Login from deleted guest account
URL Added to Application from Unknown Domain

Hunting Queries (80)

In solution Business Email Compromise - Financial Fraud:

Hunting Query Selection Criteria
Login attempts using Legacy Auth
Microsoft Entra ID signins from new locations
Risky Sign-in with new MFA method OperationName == "Update user"
Successful Signin From Non-Compliant Device ResultType == "0"
User Accounts - Unusual authentications occurring when countries do not conduct normal business operations.
User Login IP Address Teleportation AppDisplayName == "Office 365 Exchange Online"
ConditionalAccessStatus == "success"

In solution Cloud Identity Threat Protection Essentials:

Hunting Query Selection Criteria
Detect Disabled Account Sign-in Attempts by Account Name ResultType == "50057"
Detect Disabled Account Sign-in Attempts by IP Address ResultType == "50057"
Sign-ins From VPS Providers ResultType == "0"
Sign-ins from Nord VPN Providers ResultType == "0"
Suspicious Sign-ins to Privileged Account

In solution Hybrid Attack - Cloud & Identity:

Hunting Query Selection Criteria
Federated Identity Provider Added to Tenant
MFA Method Added on Risky Account
Novel identity then Key Vault secret burst
Novel sign-in context followed by IAM reconnaissance burst
Risky Successful Sign-in to VPN or Network Access Application
Suspicious sign-in followed by auth method or role change
Suspicious sign-in followed by cloud network exposure writes
VPN Credential Stuffing and Password Spray

In solution Lastpass Enterprise Activity Monitoring:

Hunting Query Selection Criteria
Failed sign-ins into LastPass due to MFA.
Login into LastPass from a previously unknown IP.

In solution Microsoft 365:

Hunting Query Selection Criteria
SharePointFileOperation via devices with previously unseen user agents
SharePointFileOperation via previously unseen IPs

In solution Microsoft Business Applications:

Hunting Query Selection Criteria
Dataverse - Activity after failed logons ResultType in "50125,50140,70043,70044"
Dataverse - Generic client app used to access production environments ResourceIdentity == "00000007-0000-0000-c000-000000000000"
ResultType == "0"
Dataverse - Identity management changes without MFA AuthenticationRequirement == "singleFactorAuthentication"
ResourceIdentity == "00000007-0000-0000-c000-000000000000"
ResultType == "0"

In solution Microsoft Defender XDR:

Hunting Query Selection Criteria
Unusual Volume of file deletion by users

In solution MicrosoftPurviewInsiderRiskManagement:

Hunting Query Selection Criteria
Insider Risk_Sign In Risk Followed By Sensitive Data Access

In solution SecurityThreatEssentialSolution: ResultType == "0"

Hunting Query
Threat Essentials - Signins From VPS Providers
Threat Essentials - Signins from Nord VPN Providers

In solution UEBA Essentials:

Hunting Query Selection Criteria
Anomalous Failed Logon
Anomalous Sign-in by New or Dormant Account RiskDetail != "none"

In solution Windows Server DNS:

Hunting Query Selection Criteria
Solorigate Encoded Domain in URL

Standalone Content:

Hunting Query Selection Criteria
Anomalous Microsoft Entra ID apps based on authentication location OperationName == "Sign-in activity"
Anomalous non-interactive token issuance after interactive sign-in (AiTM pattern)
Anomalous sign-in location by user account and authenticating application
Anomalous sign-in location by user account and authenticating application - with sign-in details
Break-glass account sign-in detected
Bulk role assignments performed by the same actor in a short window OperationName == "Add member to role."
Device code authentication from unseen autonomous system AuthenticationDetails has "deviceCode"
ResultType == "0"
Disabled accounts using Squid proxy
Dormant privileged identities with no recent sign-ins ResultType == "0"
Failed Login Attempt by Expired account
Failed attempt to access Azure Portal AppDisplayName contains "Azure Portal"
ResultType in "50020,50126"
Failed service logon attempt by user account with available AuditData
Guest account initiating privileged Entra ID operation
Inactive or new account signins OperationName == "Add user"
Login attempt by Blocked MFA user
Login spike with increase failure rate ResultType in "0,50057,50074,50126,51004"
MFA Spamming AuthenticationRequirement == "multiFactorAuthentication"
MFA method registered from an IP address not seen in user sign-in history
Microsoft Entra ID sign-in burst from multiple locations
Privileged Entra ID account sign-in via legacy authentication protocol
Rare domains seen in Cloud Logs
Same User - Successful logon for a given App and failure on another App within 1m and low distribution
Short-window IP failure burst followed by successful sign-in
Short-window sign-in mismatch between interactive and non-interactive activity
Sign-in from new country followed by sensitive operation within one hour
Sign-in from unseen IP within 60 minutes of MFA disabled for account
Signin Logs with expanded Conditional Access Policies
Tracking Password Changes
Tracking Privileged Account Rare Activity

GitHub Only:

Hunting Query Selection Criteria
Administrators Authenticating to Another Microsoft Entra ID Tenant ResultType == "0"
RiskLevelAggregated != "none"
Anomolous Sign Ins Based on Time
Dormant Service Principal Update Creds and Logs In
Dormant User Update MFA and Logs In
Dormant User Update MFA and Logs In - UEBA
High Risk Sign In Around Authentication Method Added or Device Registration NetworkLocationDetails == "[]"
RiskLevelDuringSignIn == "high"
Low & slow password attempts with volatile IP addresses ResultType == "0"
New Location Sign in with Mail forwarding activity
Privileged Accounts Locked Out ResultType == "50053"
Risky Sign-in with Device Registration
Sign-ins from IPs that attempt sign-ins to disabled accounts ResultType in "0,50057"
Smart Lockouts ResultType == "50053"
Spike in failed sign-in events
Storage Account Key Enumeration AppDisplayName !in "Office 365 Exchange Online,Skype for Business Online,Office 365 SharePoint Online"
Successful Sign-In From Non-Compliant Device with bulk download activity ConditionalAccessStatus == "success"
Unfamiliar Signin Correlation with AzurePortal Signin Attempts and AuditLogs AppDisplayName == "Azure Portal"
OperationName has_any "Add member to role"
User Account Linked to Storage Account File Upload OperationName in "PutBlob,PutRange"
Users Authenticating to Other Microsoft Entra ID Tenants ResultType == "0"
RiskLevelAggregated != "none"

Workbooks (46)

In solution 1Password:

Workbook Selection Criteria
1Password

In solution Apache Log4j Vulnerability Detection:

Workbook Selection Criteria
Log4jPostCompromiseHunting

In solution AzureSecurityBenchmark: OperationName in "Add member to role,Add user,AzureFirewallIDSLog,NetworkSecurityGroupEvents,Reset user password,Update user"
OperationName contains "PIM"
OperationName contains "create"
OperationName contains "delete"
OperationName contains "lockbox"
OperationName contains "remove"
OperationName contains "update"

Workbook
AzureSecurityBenchmark

In solution ContinuousDiagnostics&Mitigation: OperationName contains "PIM"

Workbook
ContinuousDiagnostics&Mitigation

In solution CybersecurityMaturityModelCertification(CMMC)2.0: AuthenticationRequirement == "multiFactorAuthentication"
OperationName in "Add member to role,Add user,NetworkSecurityGroupEvents,Reset user password,Update user"
OperationName contains "Add"
OperationName contains "Audit"
OperationName contains "Change"
OperationName contains "Create"
OperationName contains "Delete"
OperationName contains "Log"
OperationName contains "Monitor"
OperationName contains "PIM"
OperationName contains "Remove"
OperationName contains "Update"
OperationName contains "Write"
OperationName contains "reset"

Workbook
CybersecurityMaturityModelCertification_CMMCV2

In solution DPDP Compliance: OperationName in "Add member to role,Add user,Consent to application,Reset user password,Update user"
OperationName == "Sign-in activity"
OperationName != "Consent to application"

Workbook
DPDPCompliance

In solution GDPR Compliance & Data Security: OperationName in "Add member to role,Add user,Consent to application,Reset user password,Update user"
OperationName == "Sign-in activity"
OperationName != "Consent to application"

Workbook
GDPRComplianceAndDataSecurity

In solution Global Secure Access:

Workbook Selection Criteria
GSANetworkTraffic

In solution HIPAA Compliance: AuthenticationRequirement == "multiFactorAuthentication"

Workbook
HIPAACompliance

In solution Hybrid Attack - Cloud & Identity: OperationName in "Add app role assignment to service principal,Add delegated permission grant,Add service principal credentials,Admin deleted security info,Admin registered security info,Admin updated security info,Consent to application,GetBlob,ListBlobs,ListBlobsHierarchySegment,ListContainersSegment,Set domain authentication,Set federation settings on domain,User changed default security info,User deleted security info,User registered security info,User updated security info"
OperationName has_any "clusterrolebindings,rolebindings"
OperationName has_any "cronjobs,daemonsets"
OperationName has_any "cronjobs/create,daemonsets/create"

Workbook
HybridAttack-Cloud&Identity

In solution Lastpass Enterprise Activity Monitoring:

Workbook Selection Criteria
LastPassWorkbook

In solution Lumen Defender Threat Feed:

Workbook Selection Criteria
Lumen-Threat-Feed-Overview

In solution MaturityModelForEventLogManagementM2131: AppDisplayName in "Azure Active Directory PowerShell,Microsoft Azure CLI"
AppDisplayName contains "ACOM"
AppDisplayName contains "CLI"
AppDisplayName contains "PowerShell"
AppDisplayName contains "command"
AppDisplayName contains "graph"
OperationName in "Add member to role,Add user,ApplicationGatewayFirewall,AzureFirewallIDSLog,Reset user password,Update user"
OperationName !contains "external"
OperationName !contains "invite"
OperationName !contains "licnense"
OperationName contains "group"
OperationName contains "member"
OperationName contains "principal"
OperationName contains "role"
OperationName contains "user"

Workbook
MaturityModelForEventLogManagement_M2131

In solution Microsoft Entra ID:

Workbook Selection Criteria
AzureActiveDirectorySignins
ConditionalAccessSISM OperationName in "Add conditional access policy,Add member to group,Add member to restricted management administrative unit,Delete conditional access policy,Remove member from group,Remove member from restricted management administrative unit,Update conditional access policy,Update group"

In solution MicrosoftPurviewInsiderRiskManagement: AppDisplayName contains "Portal"
OperationName in "Add member to role,Add user,Consent to application,Create Deployment,Create or Update Virtual Machine,Create role assignment,List Storage Account Keys,Reset user password,Update user"
OperationName in "Set domain authentication,Set federation settings on domain,Sign-in activity"
OperationName != "Consent to application"
OperationName contains "Create"
OperationName contains "Delete"
OperationName contains "Update"
OperationName contains "delet"
OperationName contains "delete"
OperationName contains "remove"
OperationName has "Create"
OperationName has_any "Create,Update"
OperationName has_any "Ip,Security Rule"

Workbook
InsiderRiskManagement

In solution NISTSP80053: OperationName contains "Delete"
OperationName contains "PIM"
OperationName contains "Remove"

Workbook
NISTSP80053

In solution SOC Handbook: AppDisplayName == "Windows Sign In"
OperationName == "Consent to application"
OperationName == "Disable Strong Authentication"
OperationName contains "password"

Workbook
InvestigationInsights

In solution SOX IT Compliance:

Workbook Selection Criteria
SOXITCompliance

In solution Teams: AppDisplayName startswith "Microsoft Teams"
ResultType == "0"
ResultType !in "0,50140"

Workbook
MicrosoftTeams

In solution ThreatAnalysis&Response:

Workbook Selection Criteria
DynamicThreatModeling&Response

In solution Windows Firewall: ResultType == "0"
ResultType != "0"

Workbook
WindowsFirewall

In solution ZeroTrust(TIC3.0): AppDisplayName has_any "teams"
OperationName in "Add member to role,Add user,ApplicationGatewayFirewall,AzureFirewallIDSLog,AzureFirewallThreatIntelLog,NetworkSecurityGroupEvents,Reset user password,Update user"
OperationName contains "PIM"

Workbook
ZeroTrustTIC3

GitHub Only:

Workbook Selection Criteria
1Password
AdvancedWorkbookConcepts
AzureActiveDirectorySignins
AzureAuditActivityAndSignin
AzureLogCoverage
ConditionalAccessTrendsandChanges
CopilotforSecurityMonitoring
DSTIMWorkbook
DoDZeroTrustWorkbook AuthenticationRequirement in "multiFactorAuthentication,singleFactorAuthentication"
ConditionalAccessStatus == "notApplied"
NetworkLocationDetails == "[]"
OperationName in "Add app role assignment grant to user,Add application,Add group,Add member to role,Add member to role completed (PIM activation),Add user,Create access package,Reset user password,Update conditional access policy,Update user,User requests access package assignment"
OperationName contains "PIM"
OperationName contains "create access package"
OperationName contains "permanent"
OperationName has "User requests access package assignment"
OperationName has "application"
InsecureProtocols ClientAppUsed !in "Browser,Mobile Apps
Desktop clients"
ResultType == "0"
InvestigationInsights AppDisplayName == "Windows Sign In"
OperationName == "Consent to application"
OperationName == "Disable Strong Authentication"
OperationName contains "password"
Log4jPostCompromiseHunting
MicrosoftSecurityLicenseUtilization
MicrosoftSentinelDeploymentandMigrationTracker
MicrosoftTeams AppDisplayName startswith "Microsoft Teams"
ResultType == "0"
ResultType !in "0,50140"
SentinelWorkspaceReconTools
SolarWindsPostCompromiseHunting TokenIssuerType == "AzureAD"
UserMap
User_Analytics_Workbook
WindowsFirewall ResultType == "0"
ResultType != "0"
WindowsFirewallViaAMA ResultType == "0"
ResultType != "0"
WorkspaceUsage AuthenticationRequirement in "multiFactorAuthentication,singleFactorAuthentication"
AuthenticationRequirement != "multiFactorAuthentication"
OperationName in "Add member to role completed (PIM activation),Invite external user,Redeem external user invite,User changed default security info,User deleted security info,User registered all required security info,User registered security info"
OperationName !in "Microsoft.SecurityInsights/Incidents/investigations/write,Microsoft.SecurityInsights/dataConnectorsCheckRequirements/action"
ZeroTrustStrategyWorkbook AuthenticationRequirement in "multiFactorAuthentication,singleFactorAuthentication"
ConditionalAccessStatus == "notApplied"
NetworkLocationDetails == "[]"
OperationName in "Add app role assignment grant to user,Add application,Add group,Add member to role,Add member to role completed (PIM activation),Add user,Create access package,Reset user password,Update conditional access policy,Update user,User requests access package assignment"
OperationName contains "PIM"
OperationName contains "create access package"
OperationName contains "permanent"
OperationName has "User requests access package assignment"
OperationName has "application"

Parsers Using This Table (1)

ASIM Parsers (1)

Parser Schema Product Selection Criteria
ASimAuthenticationSigninLogs Authentication Microsoft Entra ID

Resource Types

This table collects data from the following Azure resource types:

Selection Criteria Summary (46 criteria, 62 total references)

References by type: 0 connectors, 62 content items, 0 ASIM parsers, 0 other parsers.

Selection Criteria Connectors Content Items ASIM Parsers Other Parsers Total
ResultType == "0" - 10 - - 10
AuthenticationRequirement == "multiFactorAuthentication" - 3 - - 3
ResultType in "0,50057" - 2 - - 2
ResultType == "50057" - 2 - - 2
ResultType == "0"
RiskLevelAggregated != "none"
- 2 - - 2
ResultType == "50053" - 2 - - 2
OperationName in "Add member to role,Add user,Consent to application,Reset user password,Update user"
OperationName == "Sign-in activity"
OperationName != "Consent to application"
- 2 - - 2
ResourceIdentity == "00000007-0000-0000-c000-000000000000" - 1 - - 1
NetworkLocationDetails !has "trustedNamedLocation"
ResultType == "0"
- 1 - - 1
AppDisplayName == "Windows Sign In" - 1 - - 1
ResultType == "500121" - 1 - - 1
RiskState == "atRisk" - 1 - - 1
AppDisplayName in "ADFS Trust,Azure Portal,Microsoft Azure PowerShell"
RiskLevelAggregated == "high"
RiskLevelDuringSignIn == "high"
- 1 - - 1
ResultType in "0,50125,50140" - 1 - - 1
ResultType == "0"
RiskState == "atRisk"
- 1 - - 1
AuthenticationRequirement == "singleFactorAuthentication"
ResultType == "0"
- 1 - - 1
ResultType != "0" - 1 - - 1
OperationName == "Update user" - 1 - - 1
AppDisplayName == "Office 365 Exchange Online"
ConditionalAccessStatus == "success"
- 1 - - 1
ResultType in "50125,50140,70043,70044" - 1 - - 1
ResourceIdentity == "00000007-0000-0000-c000-000000000000"
ResultType == "0"
- 1 - - 1
AuthenticationRequirement == "singleFactorAuthentication"
ResourceIdentity == "00000007-0000-0000-c000-000000000000"
ResultType == "0"
- 1 - - 1
RiskDetail != "none" - 1 - - 1
OperationName in "PutBlob,PutRange" - 1 - - 1
OperationName == "Add member to role." - 1 - - 1
AuthenticationDetails has "deviceCode"
ResultType == "0"
- 1 - - 1
NetworkLocationDetails == "[]"
RiskLevelDuringSignIn == "high"
- 1 - - 1
ConditionalAccessStatus == "success" - 1 - - 1
AppDisplayName !in "Office 365 Exchange Online,Skype for Business Online,Office 365 SharePoint Online" - 1 - - 1
AppDisplayName == "Azure Portal"
OperationName has_any "Add member to role"
- 1 - - 1
OperationName == "Sign-in activity" - 1 - - 1
OperationName == "Add user" - 1 - - 1
ResultType in "0,50057,50074,50126,51004" - 1 - - 1
AppDisplayName contains "Azure Portal"
ResultType in "50020,50126"
- 1 - - 1
OperationName in "Add member to role,Add user,AzureFirewallIDSLog,NetworkSecurityGroupEvents,Reset user password,Update user"
OperationName contains "PIM"
OperationName contains "create"
OperationName contains "delete"
OperationName contains "lockbox"
OperationName contains "remove"
OperationName contains "update"
- 1 - - 1
OperationName contains "PIM" - 1 - - 1
AuthenticationRequirement == "multiFactorAuthentication"
OperationName in "Add member to role,Add user,NetworkSecurityGroupEvents,Reset user password,Update user"
OperationName contains "Add"
OperationName contains "Audit"
OperationName contains "Change"
OperationName contains "Create"
OperationName contains "Delete"
OperationName contains "Log"
OperationName contains "Monitor"
OperationName contains "PIM"
OperationName contains "Remove"
OperationName contains "Update"
OperationName contains "Write"
OperationName contains "reset"
- 1 - - 1
OperationName in "Add app role assignment to service principal,Add delegated permission grant,Add service principal credentials,Admin deleted security info,Admin registered security info,Admin updated security info,Consent to application,GetBlob,ListBlobs,ListBlobsHierarchySegment,ListContainersSegment,Set domain authentication,Set federation settings on domain,User changed default security info,User deleted security info,User registered security info,User updated security info"
OperationName has_any "clusterrolebindings,rolebindings"
OperationName has_any "cronjobs,daemonsets"
OperationName has_any "cronjobs/create,daemonsets/create"
- 1 - - 1
AppDisplayName in "Azure Active Directory PowerShell,Microsoft Azure CLI"
AppDisplayName contains "ACOM"
AppDisplayName contains "CLI"
AppDisplayName contains "PowerShell"
AppDisplayName contains "command"
AppDisplayName contains "graph"
OperationName in "Add member to role,Add user,ApplicationGatewayFirewall,AzureFirewallIDSLog,Reset user password,Update user"
OperationName !contains "external"
OperationName !contains "invite"
OperationName !contains "licnense"
OperationName contains "group"
OperationName contains "member"
OperationName contains "principal"
OperationName contains "role"
OperationName contains "user"
- 1 - - 1
OperationName in "Add conditional access policy,Add member to group,Add member to restricted management administrative unit,Delete conditional access policy,Remove member from group,Remove member from restricted management administrative unit,Update conditional access policy,Update group" - 1 - - 1
AppDisplayName contains "Portal"
OperationName in "Add member to role,Add user,Consent to application,Create Deployment,Create or Update Virtual Machine,Create role assignment,List Storage Account Keys,Reset user password,Update user"
OperationName in "Set domain authentication,Set federation settings on domain,Sign-in activity"
OperationName != "Consent to application"
OperationName contains "Create"
OperationName contains "Delete"
OperationName contains "Update"
OperationName contains "delet"
OperationName contains "delete"
OperationName contains "remove"
OperationName has "Create"
OperationName has_any "Create,Update"
OperationName has_any "Ip,Security Rule"
- 1 - - 1
OperationName contains "Delete"
OperationName contains "PIM"
OperationName contains "Remove"
- 1 - - 1
AppDisplayName == "Windows Sign In"
OperationName == "Consent to application"
OperationName == "Disable Strong Authentication"
OperationName contains "password"
- 1 - - 1
AppDisplayName startswith "Microsoft Teams"
ResultType == "0"
ResultType !in "0,50140"
- 1 - - 1
ResultType == "0"
ResultType != "0"
- 1 - - 1
AppDisplayName has_any "teams"
OperationName in "Add member to role,Add user,ApplicationGatewayFirewall,AzureFirewallIDSLog,AzureFirewallThreatIntelLog,NetworkSecurityGroupEvents,Reset user password,Update user"
OperationName contains "PIM"
- 1 - - 1
Total 0 62 0 0 62

AppDisplayName

Value Connectors Content Items ASIM Parsers Other Parsers Total
Windows Sign In - 2 - - 2
Azure Portal - 2 - - 2
ADFS Trust - 1 - - 1
Microsoft Azure PowerShell - 1 - - 1
Office 365 Exchange Online - 1 - - 1
!= Office 365 Exchange Online - 1 - - 1
!= Skype for Business Online - 1 - - 1
!= Office 365 SharePoint Online - 1 - - 1
contains Azure Portal - 1 - - 1
Azure Active Directory PowerShell - 1 - - 1
Microsoft Azure CLI - 1 - - 1
contains ACOM - 1 - - 1
contains CLI - 1 - - 1
contains PowerShell - 1 - - 1
contains command - 1 - - 1
contains graph - 1 - - 1
contains Portal - 1 - - 1
startswith Microsoft Teams - 1 - - 1
has_any teams - 1 - - 1

AuthenticationDetails

Value Connectors Content Items ASIM Parsers Other Parsers Total
has deviceCode - 1 - - 1

AuthenticationRequirement

Value Connectors Content Items ASIM Parsers Other Parsers Total
multiFactorAuthentication - 4 - - 4
singleFactorAuthentication - 2 - - 2

ConditionalAccessStatus

Value Connectors Content Items ASIM Parsers Other Parsers Total
success - 2 - - 2

NetworkLocationDetails

Value Connectors Content Items ASIM Parsers Other Parsers Total
!has trustedNamedLocation - 1 - - 1
[] - 1 - - 1

OperationName

Value Connectors Content Items ASIM Parsers Other Parsers Total
Update user - 8 - - 8
Add user - 8 - - 8
Add member to role - 7 - - 7
Reset user password - 7 - - 7
contains PIM - 5 - - 5
Consent to application - 5 - - 5
Sign-in activity - 4 - - 4
AzureFirewallIDSLog - 3 - - 3
NetworkSecurityGroupEvents - 3 - - 3
contains Delete - 3 - - 3
!= Consent to application - 3 - - 3
contains delete - 2 - - 2
contains remove - 2 - - 2
contains Create - 2 - - 2
contains Remove - 2 - - 2
contains Update - 2 - - 2
Set domain authentication - 2 - - 2
Set federation settings on domain - 2 - - 2
ApplicationGatewayFirewall - 2 - - 2
PutBlob - 1 - - 1
PutRange - 1 - - 1
Add member to role. - 1 - - 1
has_any Add member to role - 1 - - 1
contains create - 1 - - 1
contains lockbox - 1 - - 1
contains update - 1 - - 1
contains Add - 1 - - 1
contains Audit - 1 - - 1
contains Change - 1 - - 1
contains Log - 1 - - 1
contains Monitor - 1 - - 1
contains Write - 1 - - 1
contains reset - 1 - - 1
Add app role assignment to service principal - 1 - - 1
Add delegated permission grant - 1 - - 1
Add service principal credentials - 1 - - 1
Admin deleted security info - 1 - - 1
Admin registered security info - 1 - - 1
Admin updated security info - 1 - - 1
GetBlob - 1 - - 1
ListBlobs - 1 - - 1
ListBlobsHierarchySegment - 1 - - 1
ListContainersSegment - 1 - - 1
User changed default security info - 1 - - 1
User deleted security info - 1 - - 1
User registered security info - 1 - - 1
User updated security info - 1 - - 1
has_any clusterrolebindings - 1 - - 1
has_any rolebindings - 1 - - 1
has_any cronjobs - 1 - - 1
has_any daemonsets - 1 - - 1
has_any cronjobs/create - 1 - - 1
has_any daemonsets/create - 1 - - 1
!contains external - 1 - - 1
!contains invite - 1 - - 1
!contains licnense - 1 - - 1
contains group - 1 - - 1
contains member - 1 - - 1
contains principal - 1 - - 1
contains role - 1 - - 1
contains user - 1 - - 1
Add conditional access policy - 1 - - 1
Add member to group - 1 - - 1
Add member to restricted management administrative unit - 1 - - 1
Delete conditional access policy - 1 - - 1
Remove member from group - 1 - - 1
Remove member from restricted management administrative unit - 1 - - 1
Update conditional access policy - 1 - - 1
Update group - 1 - - 1
Create Deployment - 1 - - 1
Create or Update Virtual Machine - 1 - - 1
Create role assignment - 1 - - 1
List Storage Account Keys - 1 - - 1
contains delet - 1 - - 1
has Create - 1 - - 1
has_any Create - 1 - - 1
has_any Update - 1 - - 1
has_any Ip - 1 - - 1
has_any Security Rule - 1 - - 1
Disable Strong Authentication - 1 - - 1
contains password - 1 - - 1
AzureFirewallThreatIntelLog - 1 - - 1

ResourceIdentity

Value Connectors Content Items ASIM Parsers Other Parsers Total
00000007-0000-0000-c000-000000000000 - 3 - - 3

ResultType

Value Connectors Content Items ASIM Parsers Other Parsers Total
0 - 24 - - 24
50057 - 5 - - 5
!= 0 - 3 - - 3
50125 - 2 - - 2
50140 - 2 - - 2
50053 - 2 - - 2
50126 - 2 - - 2
500121 - 1 - - 1
70043 - 1 - - 1
70044 - 1 - - 1
50074 - 1 - - 1
51004 - 1 - - 1
50020 - 1 - - 1
!= 50140 - 1 - - 1

RiskDetail

Value Connectors Content Items ASIM Parsers Other Parsers Total
!= none - 1 - - 1

RiskLevelAggregated

Value Connectors Content Items ASIM Parsers Other Parsers Total
!= none - 2 - - 2
high - 1 - - 1

RiskLevelDuringSignIn

Value Connectors Content Items ASIM Parsers Other Parsers Total
high - 2 - - 2

RiskState

Value Connectors Content Items ASIM Parsers Other Parsers Total
atRisk - 2 - - 2

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

↑ Back to Tables Index