Skip to content

Commit d944d8b

Browse files
[Rule Tuning] Entra ID OAuth user_impersonation Scope for Unusual User and Client
Fixes #5461
1 parent a16307e commit d944d8b

File tree

1 file changed

+13
-3
lines changed

1 file changed

+13
-3
lines changed

rules/integrations/azure/initial_access_entra_id_oauth_user_impersonation_scope.toml

Lines changed: 13 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -2,7 +2,7 @@
22
creation_date = "2025/07/03"
33
integration = ["azure"]
44
maturity = "production"
5-
updated_date = "2025/10/06"
5+
updated_date = "2025/12/15"
66

77
[rule]
88
author = ["Elastic"]
@@ -83,15 +83,25 @@ event.dataset: azure.signinlogs and
8383
azure.signinlogs.properties.token_protection_status_details.sign_in_session_status: "unbound" and
8484
azure.signinlogs.properties.user_type: "Member" and
8585
azure.signinlogs.properties.conditional_access_status: "notApplied" and
86-
not user_agent.original: Mozilla*PKeyAuth/1.0 and
86+
not user_agent.original: (Mozilla*PKeyAuth/1.0 or Microsoft*Authentication*iPhone*) and
8787
not azure.signinlogs.properties.device_detail.operating_system: (Ios* or Android*) and
8888
event.outcome: "success"
8989
and not azure.signinlogs.properties.app_id: (
9090
"a5f63c0-b750-4f38-a71c-4fc0d58b89e2" or
9191
"6bc3b958-689b-49f5-9006-36d165f30e00" or
9292
"66a88757-258c-4c72-893c-3e8bed4d6899" or
9393
"cc15fd57-2c6c-4117-a88c-83b1d56b4bbe" or
94-
"0000000c-0000-0000-c000-000000000000"
94+
"0000000c-0000-0000-c000-000000000000" or
95+
"0a5f63c0-b750-4f38-a71c-4fc0d58b89e2" or
96+
"48af08dc-f6d2-435f-b2a7-069abd99c086" or
97+
"ab9b8c07-8f02-4f72-87fa-80105867a763" or
98+
"fc0f3af4-6835-4174-b806-f7db311fd2f3" or
99+
"5e3ce6c0-2b1f-4285-8d4b-75ee78787346" or
100+
"e8be65d6-d430-4289-a665-51bf2a194bda" or
101+
"95de633a-083e-42f5-b444-a4295d8e9314" or
102+
"d52792f4-ba38-424d-8140-ada5b883f293" or
103+
"65d91a3d-ab74-42e6-8a2f-0add61688c74" or
104+
"8c59ead7-d703-4a27-9e55-c96a0054c8d2"
95105
)
96106
'''
97107

0 commit comments

Comments
 (0)