Analyze Azure Active Directory Sign-in Location
Hi All,
Azure Active Directory Sign-in Logs is really helpful, when analyzing Sign-in Problems.
But it also can be very helpful, when analyzing the overall Sign-ins or looking out for strange behavior.
One of the Tips would be th Filter for Location and use the CountryCode and Status of Sucess
data:image/s3,"s3://crabby-images/2fad4/2fad4b87626f841df7991c29ee23d73994f237c8" alt=""
I have set up Azure Active Directory Diagnostics to save the Sign-In Logs to a LogAnalytics Workspace.
Here you can Query the Logs with KQL. Let's search for Logins that come from Outside Switzerland.
SigninLogs
| where TimeGenerated > ago(30d)
| where LocationDetails.countryOrRegion <> "CH"
//| where Status.errorCode <> "0" //Not Sucessful Logins
| project UserPrincipalName, Status.errorCode, Status.failureReason,AppDisplayName, ResourceDisplayName, LocationDetails.countryOrRegion
| where TimeGenerated > ago(30d)
| where LocationDetails.countryOrRegion <> "CH"
//| where Status.errorCode <> "0" //Not Sucessful Logins
| project UserPrincipalName, Status.errorCode, Status.failureReason,AppDisplayName, ResourceDisplayName, LocationDetails.countryOrRegion
data:image/s3,"s3://crabby-images/7b325/7b325f9b289b836863674f3d338140a88008700a" alt=""
It's worht mentioning that there are also some predefined Workbooks available
data:image/s3,"s3://crabby-images/6c562/6c562afa9b46eaac91a42485ed8f9bc05d614aae" alt=""
"Sign-ins" will give you an overview and also a Heatmap
data:image/s3,"s3://crabby-images/f7521/f752120d6b004a0671d2eadbcdb4c9b2dd1bd1b7" alt=""
"Sign-In Analysis (Preview AAD & AD FS)" will extend that to the Federation Services.
data:image/s3,"s3://crabby-images/7a8b8/7a8b80c6f1614ff00acada6d62d550a9f29c8a03" alt=""
If you want to go further, you can create Workbooks created by others. Here's one Example
How to use Azure Sentinel to follow a Users travel and map their location
Regards
Andres Bohren
data:image/s3,"s3://crabby-images/ce79f/ce79f9c98cd007f13e0ccefdf2d821bb659c891e" alt=""