logo

Azure AD Graph Activity Logs: Ingestion and threat detection to close the visibility gap

ID: def6a325-32ca-51f2-b8a6-e6b5f2f99fef

STIX ID: report--def6a325-32ca-51f2-b8a6-e6b5f2f99fef

Feed Name: Elastic Security Labs

Date Published: 2026-06-19

Date Updated: 2026-06-20

...
...

Elastic Security Labs describes the new availability of AzureADGraphActivityLogs for ingestion into Elastic, explains how legacy Azure AD Graph (graph.windows.net) has been abused by reconnaissance tools (ROADrecon, AADInternals), and provides field mappings, example hunts/detections (user-agent fingerprints, API-version misuse, FOCI client mismatches, 4xx surges), and prevention guidance (per-app blockAzureADGraphAccess, Conditional Access, disabling device-code where unnecessary). The report is operational: it shows how to enable the diagnostic stream, ingest it into Elastic, validate events, and tune detections to reduce the visibility gap that historically allowed bulk directory enumeration and token misuse.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.