Azure-Sentinel icon indicating copy to clipboard operation
Azure-Sentinel copied to clipboard

Entra id Conditional Access (prefix) analytic rules - NEW

Open Cyberlorians opened this issue 7 months ago • 14 comments

These are new, never seen before. These are CRUD lifecycle of conditional access and other metrics that cyber needs.

Reason for Change(s):

  • Sentinel Entra is lacking any type of AR around CA policies.

Version Updated:

  • Not applicable, not yet

Testing Completed:

  • yes, verified

Checked that the validations are passing and have addressed any issues that are present:

  • See guidance below

Cyberlorians avatar May 21 '25 19:05 Cyberlorians

I see no details on issue and needs to be fixed. Please let me know what needs to be addressed

Cyberlorians avatar Jun 04 '25 15:06 Cyberlorians

@Cyberlorians Required property 'requiredDataConnectors' not found in JSON. Please add in Analyatic Rules.

v-maheshbh avatar Jun 17 '25 10:06 v-maheshbh

@Cyberlorians relevantTechniques field is missing in multiple Analytic rules.

v-maheshbh avatar Jun 17 '25 10:06 v-maheshbh

Thanks! Where exactly does that get added? In the description or when I submit it in the notes? I ask because in the AR itself (in Sentinel) that is not an option

Thank you

Cyberlorians avatar Jun 17 '25 10:06 Cyberlorians

@Cyberlorians please refer any analytical rules https://github.com/Azure/Azure-Sentinel/tree/master/Solutions/Microsoft%20Entra%20ID/Analytic%20Rules

v-maheshbh avatar Jun 17 '25 10:06 v-maheshbh

Ok I see it now. I manually add this into the yaml?

Cyberlorians avatar Jun 17 '25 10:06 Cyberlorians

Cool. Thanks. I'm on leave. Not sure I can do from a phone.

After I update the files, do o have to make a whole new pull request or no? Sorry, this is the first time doing this.

Cyberlorians avatar Jun 17 '25 10:06 Cyberlorians

@Cyberlorians Please make this change in the same pull request (PR).

v-maheshbh avatar Jun 17 '25 11:06 v-maheshbh

Is it still azureactivedirectory? Those ARs you showed me are of the old. Because it's Microsoft entra id

What should I put?

Cyberlorians avatar Jun 17 '25 11:06 Cyberlorians

@Cyberlorians Yes, use azureactivedirectory

v-maheshbh avatar Jun 18 '25 09:06 v-maheshbh

updates have been made. please verify again

Cyberlorians avatar Jun 18 '25 13:06 Cyberlorians

Why is it failing now? I'm not following nor is this in any guidance. I'd appreciate an assist, greatly.

Cyberlorians avatar Jun 20 '25 11:06 Cyberlorians

@Cyberlorians "Invalid data model. No valid tactic corresponding to the technique T1489 was provided in the tactics field

v-maheshbh avatar Jun 23 '25 08:06 v-maheshbh

I updated the one yaml file which has an X to look like this. Is this proper? I.e., it means add a sub technique and NOT leave a parent. I am not so sure this is accurate as some ARs have just a parent and not sub.

tactics:

  • DefenseEvasion relevantTechniques:
    • T1562.007

Cyberlorians avatar Jun 23 '25 10:06 Cyberlorians