Skip to content

Commit 63c1f47

Browse files
authored
[Rule Tuning] Added OWA (outlook for web) new AppID (#4568)
* Added OWA (outlook for web) new AppID **Title:** Add new Outlook for Web AppID to abnormal Microsoft 365 ClientAppID rule **Description:** This pull request updates the `initial_access_microsoft_365_abnormal_clientappid` rule to include the newly introduced Outlook for Web AppID: - **New AppID**: `9199bf20-a13f-4107-85dc-02114787ef48` ### Context Outlook for Web (OWA) is migrating to a new authentication platform using MSAL and a Single Page Application (SPA) auth model. As part of this backend change, Microsoft is replacing the existing OWA AppID with a new one. This change is being rolled out during the first half of calendar year 2024, with full deployment expected by Q4 2024. - **Old OWA AppID**: `00000002-0000-0ff1-ce00-000000000000` - **New OWA AppID**: `9199bf20-a13f-4107-85dc-02114787ef48` Although no action is required for tenant administrators, this new AppID may show up in logs and should be accounted for in detections relying on known legitimate ClientAppIDs. ### Why this change? The rule `initial_access_microsoft_365_abnormal_clientappid` flags potentially suspicious or unauthorized client applications accessing Microsoft 365 services. To prevent false positives caused by this official change from Microsoft, this PR adds the new OWA AppID to the allowlist. ### References - Microsoft 365 Message Center notice (ref: MC715025) - [MSAL documentation](https://learn.microsoft.com/en-us/azure/active-directory/develop/msal-overview) * Update initial_access_microsoft_365_abnormal_clientappid.toml Updated updated_date
1 parent e8c5416 commit 63c1f47

File tree

1 file changed

+3
-2
lines changed

1 file changed

+3
-2
lines changed

rules/integrations/o365/initial_access_microsoft_365_abnormal_clientappid.toml

Lines changed: 3 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -2,7 +2,7 @@
22
creation_date = "2023/07/18"
33
integration = ["o365"]
44
maturity = "production"
5-
updated_date = "2025/01/15"
5+
updated_date = "2025/03/26"
66

77
[rule]
88
author = ["Elastic"]
@@ -94,7 +94,8 @@ not o365.audit.ClientAppId : ("13937bba-652e-4c46-b222-3003f4d1ff97" or "6326e36
9494
"d73f4b35-55c9-48c7-8b10-651f6f2acb2e" or "d9b8ec3a-1e4e-4e08-b3c2-5baf00c0fcb0" or "de8bc8b5-d9f9-48b1-a8ad-b748da725064" or
9595
"dfe74da8-9279-44ec-8fb2-2aed9e1c73d0" or "e1ef36fd-b883-4dbf-97f0-9ece4b576fc6" or "e64aa8bc-8eb4-40e2-898b-cf261a25954f" or
9696
"e9f49c6b-5ce5-44c8-925d-015017e9f7ad" or "ee272b19-4411-433f-8f28-5c13cb6fd407" or "f5eaa862-7f08-448c-9c4e-f4047d4d4521" or
97-
"fb78d390-0c51-40cd-8e17-fdbfab77341b" or "fc0f3af4-6835-4174-b806-f7db311fd2f3" or "fdf9885b-dd37-42bf-82e5-c3129ef5a302"
97+
"fb78d390-0c51-40cd-8e17-fdbfab77341b" or "fc0f3af4-6835-4174-b806-f7db311fd2f3" or "fdf9885b-dd37-42bf-82e5-c3129ef5a302" or
98+
"9199bf20-a13f-4107-85dc-02114787ef48"
9899
)
99100
'''
100101

0 commit comments

Comments
 (0)