Azure-Sentinel icon indicating copy to clipboard operation
Azure-Sentinel copied to clipboard

Add Conditional Access Insights Workbook for Microsoft Entra ID

Open Cyberlorians opened this issue 4 months ago • 5 comments

Required items, please complete

Change(s):

Added ConditionalAccessSISM.json workbook to Solutions/Microsoft Entra ID/Workbooks/ New comprehensive Conditional Access monitoring workbook for Microsoft Sentinel Provides real-time insights into CA policies using AuditLogs and SigninLogs Includes user monitoring, workload identity analysis, and emergency account tracking Reason for Change(s):

Enhances Microsoft Entra ID solution set with specialized Conditional Access monitoring capabilities Addresses gap in comprehensive CA policy analysis and monitoring tools Provides administrators with actionable insights for Zero Trust implementation Supports both user accounts and workload identities in CA policy evaluation Version Updated:

N/A (New workbook submission, not updating existing detection/analytic rule) Testing Completed:

Yes - Workbook has been tested in Microsoft Sentinel environment Validated with AuditLogs and SigninLogs data sources Confirmed compatibility with Log Analytics workspace queries Tested across multiple CA policy scenarios and configurations All KQL queries execute successfully without custom parsers or functions Checked that the validations are passing and have addressed any issues that are present:

Yes - Workbook follows standard JSON structure for Microsoft Sentinel workbooks All queries use standard Microsoft Entra ID log tables (AuditLogs, SigninLogs, AADServicePrincipalSignInLogs, AADRiskyServicePrincipals) No custom parsers or functions required Workbook structure aligns with existing Microsoft Entra ID workbooks in the repository

Cyberlorians avatar Dec 12 '25 16:12 Cyberlorians

Hi, what is the conflict? It is not telling me.

Cyberlorians avatar Dec 15 '25 15:12 Cyberlorians

I saw the last error. I uploaded two images and updated the meta file. Please review.

Cyberlorians avatar Dec 16 '25 23:12 Cyberlorians

Hi @Cyberlorians Kindly review failing validation check.

Thanks!

v-maheshbh avatar Dec 17 '25 11:12 v-maheshbh

Hi. I cannot tell what the issue is. I uploaded the image files etc.

Cyberlorians avatar Dec 17 '25 11:12 Cyberlorians

@sreedharande I updated the meta file. It seemed the array was duplicate.

Cyberlorians avatar Dec 17 '25 13:12 Cyberlorians