You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
As an It administrator, you need to be able to identify comprmises in your environment to ensure that you can keep it in a healty state.
25
+
26
+
The sensitive operations report workbook is intended to help identify suspicious application and service principal activity that may indicate compromises in your environment.
24
27
25
28
26
29
This article provides you with an overview of this workbook.
@@ -30,13 +33,10 @@ This article provides you with an overview of this workbook.
This workbook identifies recent sensitive operations that have been performed in your tenant and which may service principal compromise.
33
37
34
-
This workbook is intended to help identify suspicious application and service principal activity that may indicate compromises in your environment.
35
-
36
-
37
-
This workbook identifies recent sensitive operations that have been performed in your tenant and which may service principal compromise.
38
+
If you organization is new to Azure monitor workbooks, you need to integrate your Azure AD sign-in and audit logs with Azure Monitor before accessing the workbook. This allows you to store, and query, and visualize your logs using workbooks for up to 2 years. Only sign-in and audit events created after Azure Monitor integration will be stored, so the workbook will not contain insights prior to that date. Learn more about the prerequisites to Azure Monitor workbooks for Azure Active Directory. If you have previously integrated your Azure AD sign-in and audit logs with Azure Monitor, you can use the workbook to assess past information.
38
39
39
-
40
40
41
41
42
42
## Sections
@@ -104,7 +104,37 @@ This section includes the following data:
104
104
105
105
## Filters
106
106
107
-
This workbook doesn't have filters.
107
+
This paragraph lists the supported filters for each section.
108
+
109
+
110
+
### Modified Application and Service Principal Credentials/Authentication Methods
111
+
112
+
- Time range
113
+
- Operation name
114
+
- Credential
115
+
- Actor
116
+
- Exclude actor
117
+
118
+
119
+
### New permissions granted to service principals
120
+
121
+
- Time range
122
+
- Client app
123
+
- Resource
124
+
125
+
### Directory role and group membership updates to service principals
0 commit comments