Azure AD Graph Activity Logs: Ingestion and threat detection to close the visibility gap
ID: def6a325-32ca-51f2-b8a6-e6b5f2f99fef
STIX ID: report--def6a325-32ca-51f2-b8a6-e6b5f2f99fef
Feed Name: Elastic Security Labs
Elastic Security Labs describes the new availability of AzureADGraphActivityLogs for ingestion into Elastic, explains how legacy Azure AD Graph (graph.windows.net) has been abused by reconnaissance tools (ROADrecon, AADInternals), and provides field mappings, example hunts/detections (user-agent fingerprints, API-version misuse, FOCI client mismatches, 4xx surges), and prevention guidance (per-app blockAzureADGraphAccess, Conditional Access, disabling device-code where unnecessary). The report is operational: it shows how to enable the diagnostic stream, ingest it into Elastic, validate events, and tune detections to reduce the visibility gap that historically allowed bulk directory enumeration and token misuse.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
