Skip to main content
Skip table of contents

Azure Active Directory Messages

Vendor Documentation

Classification

Rule NameRule TypeCommon EventClassification
Azure Active Directory MessagesBase RuleGeneral Audit MessageOther Audit
Logon Using DA TokenSub RuleUser LogonAuthentication Success
Logon Failure Using DA TokenSub RuleUser Logon FailureAuthentication Failure
Logon Using Federated TokenSub RuleUser LogonAuthentication Success
Logon Failed Using Federated TokenSub RuleUser Logon FailureAuthentication Failure
Logon Using PasswordSub RuleUser LogonAuthentication Success
Logon Failed Using PasswordSub RuleUser Logon FailureAuthentication Failure
Add App Role Assignment Grant to UserSub RuleSuccessful ActivityOther Audit Success
Add App Role Assignment Grant to User FailSub RuleUnsuccessful ActivityOther Audit Failure
Add App Role Assignment to Service PrincipalSub RuleSuccessful ActivityOther Audit Success
Add App Role Assignment to Service Principal FailSub RuleSuccessful ActivityOther Audit Success
Add ApplicationSub RuleSoftware InstalledConfiguration
Add Application FailSub RuleUnsuccessful ActivityOther Audit Failure
Add OAuth2PermissionGrantSub RulePrivilege GrantedAccess Granted
Add OAuth2PermissionGrant FailedSub RuleUnsuccessful ActivityOther Audit Failure
Add Service PrincipalSub RuleSuccessful ActivityOther Audit Success
Add Service Principal FailedSub RuleUnsuccessful ActivityOther Audit Failure
Add UserSub RuleUser Account CreatedAccount Created
Add User FailedSub RuleUnsuccessful ActivityOther Audit Failure
Change User LicenseSub RuleUser Account Attribute ModifiedAccount Modified
Change User License FailedSub RuleUnsuccessful ActivityOther Audit Failure
Consent to ApplicationSub RuleSuccessful ActivityOther Audit Success
Consent to Application FailedSub RuleUnsuccessful ActivityOther Audit Failure
Delete GroupSub RuleGroup DeletedAccount Deleted
Delete Group FailedSub RuleUnsuccessful ActivityOther Audit Failure
Delete UserSub RuleUser Account DeletedAccount Deleted
Delete User FailedSub RuleUnsuccessful ActivityOther Audit Failure
Reset User PasswordSub RulePassword ModifiedAccount Modified
Reset User Password FailedSub RulePassword Change AttemptedOther Audit Failure
Update ApplicationSub RuleSoftware UpdatedConfiguration
Update Application FailedSub RuleUnsuccessful ActivityOther Audit Failure
Update GroupSub RuleGroup Attribute ModifiedAccount Modified
Update Group FailedSub RuleUnsuccessful ActivityOther Audit Failure
Update Service PrincipalSub RuleRole Attribute ModifiedAccount Modified
Update Service Principal FailedSub RuleUnsuccessful ActivityOther Audit Failure
Update UserSub RuleUser Account Attribute ModifiedAccount Modified
Update User FailedSub RuleUnsuccessful ActivityOther Audit Failure
Authentication SuccessSub RuleUser LogonAuthentication Success
Authentication FailureSub RuleUser Logon FailureAuthentication Failure
Add Member to RoleSub RuleAccount Added to GroupAccess Granted
Add Member to GroupSub RuleAccount Added to GroupAccess Granted
Add Member to RoleSub RuleSet Role SuccessOther Audit
Add Owner to GroupSub RuleOwnership GrantedAccess Granted
Add GroupSub RuleGroup CreatedAccount Created
Remove Member from RoleSub RuleAccount Removed from GroupAccess Revoked
User Account Not FoundSub RuleUser Not FoundError
Set Group LicenseSub RuleLicense AllocatedInformation
Add Member to Role FailedSub RuleGeneral Failed ActivityFailed Activity
Remove Member from RoleSub RuleGeneral Failed ActivityFailed Activity
FlowToken ExpiredSub RuleToken Not FoundError
Redirected User Login SuccessSub RuleUser LogonAuthentication Success
Redirected User Login FailureSub RuleUser Logon FailureAuthentication Failure
Fault Domain RedirectedSub RuleAuthentication Failure ActivityAuthentication Failure

Mapping with LogRhythm Schema  

Device Key in Log MessageLogRhythm SchemaData Type
TSN/AN/A
SESSID<session>Text/String
COMMAND<command>Text/String
USERTYPE<objecttype>Text/String
USERKEY<login>
<domainorigin>
Text/String
WORKLOAD

<process>


Text/String
RESULTCODE<result>
<tag1>
Text/String
OBJECT<account>Text/String
USER<subject>Text/String
SIP<sip>IP Address
EVENTTYPE<vmid>Text/String
EXTENDEDPROPERTIES "name":"targetName","value":"<group>Text/String
EXTENDEDPROPERTIES "Name":"Group.DisplayName","NewValue":"<group>Text/String
MODIFIEDPROPERTIES "name":"role.displayname","newvalue":"<group>Text/String
MODIFIEDPROPERTIES "name":"RequestType","value":"<policy>Text/String
APPLICATION<objectname>Text/String
USERAGENT

<useragent>

<object>

Text/String
LOGINSTATUS<tag5>
<status>
Text/String
USERDOMAINN/AN/A
ACTORN/AN/A
ACTORCONTEXTIDN/AN/A
ACTORIPN/AN/A
INTERSYSTEMSIDN/AN/A
INTRASYSTEMSIDN/AN/A
SUPPORTTICKETIDN/AN/A
TARGETN/AN/A
TARGETCONTEXTIDN/AN/A
JavaScript errors detected

Please note, these errors can depend on your browser setup.

If this problem persists, please contact our support.