Skip to content

Commit 36d6daa

Browse files
author
Markus Vilcinskas
committed
workbook01
1 parent d8005d5 commit 36d6daa

File tree

1 file changed

+3
-3
lines changed

1 file changed

+3
-3
lines changed

articles/active-directory/reports-monitoring/workbook-sensitive-operations-report.md

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -21,7 +21,7 @@ ms.collection: M365-identity-device-management
2121

2222
# Sensitive operations report workbook
2323

24-
As an It administrator, you need to be able to identify comprmises in your environment to ensure that you can keep it in a healty state.
24+
As an It administrator, you need to be able to identify compromises in your environment to ensure that you can keep it in a healthy state.
2525

2626
The sensitive operations report workbook is intended to help identify suspicious application and service principal activity that may indicate compromises in your environment.
2727

@@ -35,7 +35,7 @@ This article provides you with an overview of this workbook.
3535

3636
This workbook identifies recent sensitive operations that have been performed in your tenant and which may service principal compromise.
3737

38-
If you organization is new to Azure monitor workbooks, you need to integrate your Azure AD sign-in and audit logs with Azure Monitor before accessing the workbook. This allows you to store, and query, and visualize your logs using workbooks for up to 2 years. Only sign-in and audit events created after Azure Monitor integration will be stored, so the workbook will not contain insights prior to that date. Learn more about the prerequisites to Azure Monitor workbooks for Azure Active Directory. If you have previously integrated your Azure AD sign-in and audit logs with Azure Monitor, you can use the workbook to assess past information.
38+
If your organization is new to Azure monitor workbooks, you need to integrate your Azure AD sign-in and audit logs with Azure Monitor before accessing the workbook. This allows you to store, and query, and visualize your logs using workbooks for up to two years. Only sign-in and audit events created after Azure Monitor integration will be stored, so the workbook will not contain insights prior to that date. Learn more about the prerequisites to Azure Monitor workbooks for Azure Active Directory. If you have previously integrated your Azure AD sign-in and audit logs with Azure Monitor, you can use the workbook to assess past information.
3939

4040

4141

@@ -147,7 +147,7 @@ This paragraph lists the supported filters for each section.
147147

148148
- **New permissions granted to service principals** to look out for broad or excessive permissions being added to service principals by actors that may be compromised.
149149

150-
- **Modified federation settings** section to confirm that the added or modified target domain/URL is a legitimate admin behavior. Any actions which modify or add domain federation trusts are rare and should be treated as high fidelity to be investigated as soon as possible.
150+
- **Modified federation settings** section to confirm that the added or modified target domain/URL is a legitimate admin behavior. Actions that modify or add domain federation trusts are rare and should be treated as high fidelity to be investigated as soon as possible.
151151

152152

153153

0 commit comments

Comments
 (0)