|
2 | 2 | creation_date = "2025/07/03" |
3 | 3 | integration = ["azure"] |
4 | 4 | maturity = "production" |
5 | | -updated_date = "2025/10/06" |
| 5 | +updated_date = "2025/12/15" |
6 | 6 |
|
7 | 7 | [rule] |
8 | 8 | author = ["Elastic"] |
@@ -83,15 +83,25 @@ event.dataset: azure.signinlogs and |
83 | 83 | azure.signinlogs.properties.token_protection_status_details.sign_in_session_status: "unbound" and |
84 | 84 | azure.signinlogs.properties.user_type: "Member" and |
85 | 85 | azure.signinlogs.properties.conditional_access_status: "notApplied" and |
86 | | - not user_agent.original: Mozilla*PKeyAuth/1.0 and |
| 86 | + not user_agent.original: (Mozilla*PKeyAuth/1.0 or Microsoft*Authentication*iPhone*) and |
87 | 87 | not azure.signinlogs.properties.device_detail.operating_system: (Ios* or Android*) and |
88 | 88 | event.outcome: "success" |
89 | 89 | and not azure.signinlogs.properties.app_id: ( |
90 | 90 | "a5f63c0-b750-4f38-a71c-4fc0d58b89e2" or |
91 | 91 | "6bc3b958-689b-49f5-9006-36d165f30e00" or |
92 | 92 | "66a88757-258c-4c72-893c-3e8bed4d6899" or |
93 | 93 | "cc15fd57-2c6c-4117-a88c-83b1d56b4bbe" or |
94 | | - "0000000c-0000-0000-c000-000000000000" |
| 94 | + "0000000c-0000-0000-c000-000000000000" or |
| 95 | + "0a5f63c0-b750-4f38-a71c-4fc0d58b89e2" or |
| 96 | + "48af08dc-f6d2-435f-b2a7-069abd99c086" or |
| 97 | + "ab9b8c07-8f02-4f72-87fa-80105867a763" or |
| 98 | + "fc0f3af4-6835-4174-b806-f7db311fd2f3" or |
| 99 | + "5e3ce6c0-2b1f-4285-8d4b-75ee78787346" or |
| 100 | + "e8be65d6-d430-4289-a665-51bf2a194bda" or |
| 101 | + "95de633a-083e-42f5-b444-a4295d8e9314" or |
| 102 | + "d52792f4-ba38-424d-8140-ada5b883f293" or |
| 103 | + "65d91a3d-ab74-42e6-8a2f-0add61688c74" or |
| 104 | + "8c59ead7-d703-4a27-9e55-c96a0054c8d2" |
95 | 105 | ) |
96 | 106 | ''' |
97 | 107 |
|
|
0 commit comments