Skip to content

Conversation

@Cyberlorians
Copy link
Contributor

Required items, please complete

Change(s):

  • Added ConditionalAccessSISM.json workbook to Solutions/Microsoft Entra ID/Workbooks/
  • New comprehensive Conditional Access monitoring workbook for Microsoft Sentinel
  • Provides real-time insights into CA policies using AuditLogs and SigninLogs
  • Includes user monitoring, workload identity analysis, and emergency account tracking

Reason for Change(s):

  • Enhances Microsoft Entra ID solution set with specialized Conditional Access monitoring capabilities
  • Addresses gap in comprehensive CA policy analysis and monitoring tools
  • Provides administrators with actionable insights for Zero Trust implementation
  • Supports both user accounts and workload identities in CA policy evaluation

Version Updated:

  • N/A (New workbook submission, not updating existing detection/analytic rule)

Testing Completed:

  • Yes - Workbook has been tested in Microsoft Sentinel environment
  • Validated with AuditLogs and SigninLogs data sources
  • Confirmed compatibility with Log Analytics workspace queries
  • Tested across multiple CA policy scenarios and configurations
  • All KQL queries execute successfully without custom parsers or functions

Checked that the validations are passing and have addressed any issues that are present:

  • Yes - Workbook follows standard JSON structure for Microsoft Sentinel workbooks
  • All queries use standard Microsoft Entra ID log tables (AuditLogs, SigninLogs, AADServicePrincipalSignInLogs, AADRiskyServicePrincipals)
  • No custom parsers or functions required
  • Workbook structure aligns with existing Microsoft Entra ID workbooks in the repository

@Cyberlorians Cyberlorians requested review from a team as code owners November 11, 2025 14:53
@v-atulyadav v-atulyadav self-assigned this Nov 12, 2025
@v-atulyadav v-atulyadav added the Solution Solution specialty review needed label Nov 12, 2025
@Cyberlorians
Copy link
Contributor Author

Cyberlorians commented Nov 12, 2025

This CI failure appears to be a validation pipeline issue. According to the Microsoft Sentinel Solutions Packaging Tool documentation, workbooks are valid solution components that should not be validated against detection template schemas.

The validation pipeline is incorrectly requiring TTP fields (tactics, techniques, relevantTechniques) for workbook files. Per the official guidance, workbooks have separate validation requirements and should be excluded from detection-specific schema checks.

Could a maintainer please review the CI validation configuration to properly handle workbook files?

@v-atulyadav
Copy link
Collaborator

Hi @Cyberlorians,

Please remove the fallbackResourceIds, and also ensure that the fromTemplate value is something other than "sentinel-UserWorkbook", as indicated by the error. Thanks

image image

Copy link
Contributor Author

@Cyberlorians Cyberlorians left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

changes were made

@Cyberlorians
Copy link
Contributor Author

Hi. What's the new failure issue now?

@v-atulyadav
Copy link
Collaborator

Hi. What's the new failure issue now?

You can ignore this

@Cyberlorians
Copy link
Contributor Author

Great. Thanks. Is everything else ok? When can I expect it to be published?

@v-atulyadav
Copy link
Collaborator

v-atulyadav commented Nov 20, 2025

Hi @Cyberlorians,
Please add workbook metadata in below mentioned path and then kindly proceed with packaging this solution. Thanks
https://github.com/Azure/Azure-Sentinel/blob/master/Workbooks/WorkbooksMetadata.json
https://github.com/Azure/Azure-Sentinel/blob/master/Tools/Create-Azure-Sentinel-Solution/V3/README.md

@Cyberlorians
Copy link
Contributor Author

I updated the metadata.json. I do not know how to package this. Very confusing. The packaging solution does not lay this out for a non coder or for workbooks. If this cannot be published please contact me on TEAMS at [email protected]. Please and thank you.

@Cyberlorians
Copy link
Contributor Author

Evening, is there any possibility of you helping me? Please contact on msft teams channel. [email protected]

I do not know how to package and I need to get this workbook in place. Going forward I would be grateful if someone could show me

@v-atulyadav
Copy link
Collaborator

Hi @Cyberlorians,
Please update the workbook metadata as suggested above. We will take care of the packaging. Thanks

@Cyberlorians
Copy link
Contributor Author

Thank you and I did I believe last week. Would you verify it's updated?

@v-atulyadav
Copy link
Collaborator

Hi @Cyberlorians,
I haven't seen any metadata updates for this workbook. Please confirm on your end. Thanks
https://github.com/Azure/Azure-Sentinel/blob/master/Workbooks/WorkbooksMetadata.json

@v-atulyadav
Copy link
Collaborator

Hi @Cyberlorians,
Please proceed with the request mentioned above. Thanks

@v-atulyadav
Copy link
Collaborator

Hi @Cyberlorians,
We are awaiting your response on the request above. Thanks

@Cyberlorians
Copy link
Contributor Author

new pr Add Conditional Access Insights Workbook for Microsoft Entra ID #13313

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Solution Solution specialty review needed

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants