Skip to content

Commit 1350d16

Browse files
author
Markus Vilcinskas
committed
workbook01
1 parent 05cf3cc commit 1350d16

File tree

1 file changed

+36
-6
lines changed

1 file changed

+36
-6
lines changed

articles/active-directory/reports-monitoring/workbook-sesitive-operations-report.md

Lines changed: 36 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -21,6 +21,9 @@ ms.collection: M365-identity-device-management
2121

2222
# Sensitive operations report workbook
2323

24+
As an It administrator, you need to be able to identify comprmises in your environment to ensure that you can keep it in a healty state.
25+
26+
The sensitive operations report workbook is intended to help identify suspicious application and service principal activity that may indicate compromises in your environment.
2427

2528

2629
This article provides you with an overview of this workbook.
@@ -30,13 +33,10 @@ This article provides you with an overview of this workbook.
3033

3134
![Workbook category](./media/workbook-sesitive-operations-report/workbook-category.png)
3235

36+
This workbook identifies recent sensitive operations that have been performed in your tenant and which may service principal compromise.
3337

34-
This workbook is intended to help identify suspicious application and service principal activity that may indicate compromises in your environment.
35-
36-
37-
This workbook identifies recent sensitive operations that have been performed in your tenant and which may service principal compromise.
38+
If you organization is new to Azure monitor workbooks, you need to integrate your Azure AD sign-in and audit logs with Azure Monitor before accessing the workbook. This allows you to store, and query, and visualize your logs using workbooks for up to 2 years. Only sign-in and audit events created after Azure Monitor integration will be stored, so the workbook will not contain insights prior to that date. Learn more about the prerequisites to Azure Monitor workbooks for Azure Active Directory. If you have previously integrated your Azure AD sign-in and audit logs with Azure Monitor, you can use the workbook to assess past information.
3839

39-
4040

4141

4242
## Sections
@@ -104,7 +104,37 @@ This section includes the following data:
104104

105105
## Filters
106106

107-
This workbook doesn't have filters.
107+
This paragraph lists the supported filters for each section.
108+
109+
110+
### Modified Application and Service Principal Credentials/Authentication Methods
111+
112+
- Time range
113+
- Operation name
114+
- Credential
115+
- Actor
116+
- Exclude actor
117+
118+
119+
### New permissions granted to service principals
120+
121+
- Time range
122+
- Client app
123+
- Resource
124+
125+
### Directory role and group membership updates to service principals
126+
127+
- Time range
128+
- Operation
129+
- Initiating user or app
130+
131+
### Modified federation settings
132+
133+
- Time range
134+
- Operation
135+
- Initiating user or app
136+
137+
108138

109139

110140
## Best practice

0 commit comments

Comments
 (0)