Skip to content

Commit

Permalink
Merge pull request #9653 from Azure/v-sudkharat/Repackaging-Microsoft…
Browse files Browse the repository at this point in the history
…-Entra-ID

Repackaging-MicrosoftEntraID
  • Loading branch information
v-atulyadav authored Dec 29, 2023
2 parents ec65f47 + 92e8491 commit 93da382
Show file tree
Hide file tree
Showing 7 changed files with 307 additions and 266 deletions.
2 changes: 1 addition & 1 deletion Solutions/Microsoft Entra ID/Data/Solution_AAD.json
Original file line number Diff line number Diff line change
Expand Up @@ -88,7 +88,7 @@
"Solutions/Microsoft Entra ID/Playbooks/Revoke-AADSignInSessions/entity-trigger/azuredeploy.json"
],
"BasePath": "C:\\GitHub\\Azure-Sentinel",
"Version": "3.0.9",
"Version": "3.0.10",
"Metadata": "SolutionMetadata.json",
"TemplateSpec": true,
"Is1PConnector": true
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -4,7 +4,7 @@
"Logo": "<img src=\"https://raw.githubusercontent.com/Azure/Azure-Sentinel/master/Workbooks/Images/Logos/MicrosoftEntraID_logo.svg\"width=\"75px\" height=\"75px\">",
"Description": "The [Microsoft Entra ID](https://docs.microsoft.com/azure/active-directory/fundamentals/active-directory-whatis) solution for Microsoft Sentinel enables you to ingest Microsoft Entra ID [Audit](https://docs.microsoft.com/azure/active-directory/reports-monitoring/concept-audit-logs), [Sign-in](https://docs.microsoft.com/azure/active-directory/reports-monitoring/concept-sign-ins), [Provisioning](https://docs.microsoft.com/azure/active-directory/reports-monitoring/concept-provisioning-logs), [Risk Events and Risky User/Service Principal](https://docs.microsoft.com/azure/active-directory/identity-protection/howto-identity-protection-investigate-risk#risky-users) logs using Diagnostic Settings into Microsoft Sentinel.",
"BasePath": "C:\\GitHub\\Azure-Sentinel",
"Version": "3.0.7",
"Version": "3.0.10",
"Metadata": "SolutionMetadata.json",
"TemplateSpec": true,
"Is1PConnector": true,
Expand Down
Binary file added Solutions/Microsoft Entra ID/Package/3.0.10.zip
Binary file not shown.
Original file line number Diff line number Diff line change
Expand Up @@ -880,7 +880,7 @@
"name": "analytic52-text",
"type": "Microsoft.Common.TextBlock",
"options": {
"text": "Identifies evidence of password spray activity against Microsoft Entra ID applications by looking for failures from multiple accounts from the same\nIP address within a time window. If the number of accounts breaches the threshold just once, all failures from the IP address within the time range\nare bought into the result. Details on whether there were successful authentications by the IP address within the time window are also included.\nThis can be an indicator that an attack was successful.\nThe default failure acccount threshold is 5, Default time window for failures is 20m and default look back window is 1 days\nNote: Due to the number of possible accounts involved in a password spray it is not possible to map identities to a custom entity.\nReferences: https://docs.microsoft.com/azure/active-directory/reports-monitoring/reference-sign-ins-error-codes."
"text": "Identifies evidence of password spray activity against Microsoft Entra ID applications by looking for failures from multiple accounts from the same\nIP address within a time window. If the number of accounts breaches the threshold just once, all failures from the IP address within the time range\nare bought into the result. Details on whether there were successful authentications by the IP address within the time window are also included.\nThis can be an indicator that an attack was successful.\nThe default failure acccount threshold is 5, Default time window for failures is 20m and default look back window is 1 day\nNote: Due to the number of possible accounts involved in a password spray it is not possible to map identities to a custom entity.\nReferences: https://docs.microsoft.com/azure/active-directory/reports-monitoring/reference-sign-ins-error-codes."
}
}
]
Expand Down
Loading

0 comments on commit 93da382

Please sign in to comment.