↳ GitHub sourceConnector
PRODAFT USTA - Account Takeover Prevention (via Codeless Connector Framework)
Description
The PRODAFT USTA Account Takeover Prevention data connector ingests compromised-credential tickets from the PRODAFT USTA platform into Microsoft Sentinel. Sensitive values are redacted at ingestion: plaintext passwords are never stored — only password strength signals (score and length) are retained for triage.
- Declared status
- 1
- Declared author / publisher
- PRODAFT
Declared sources
Metadata from the source file. No dependencies inferred from KQL.
Data types
Declared permissions
Read and Write permissions are required.
Workspace
Workspace
PRODAFT USTA API key
A long-lived PRODAFT USTA API key with access to the Account Takeover Prevention endpoint is required.
Connector instructions
Content published in the repository. Refer to the original file for all parameters.
Connect PRODAFT USTA Account Takeover Prevention to Microsoft Sentinel
Enter your USTA base URL and a long-lived API key, then select Connect. The connector authenticates to USTA with the `Authorization: Bearer <api-key>` header and polls every minute. To load history from before the connection time, deploy the **PRODAFTUstaATP-Backfill** playbook shipped with this solution.
USTA Base URL
API Key
Related content
Links established from declared identifiers and solution manifests.
Source provenance
GitHubDisplayed values come from files in Azure/Azure-Sentinel. They describe the published template, not your workspace configuration.
- Commit
9800e51↗- Source identifier
PRODAFTUstaATPCCPDefinition
GSTEP / CATALOG TRACKING
Added to catalog : 16 Sept 2026 · 05:49 UTC
Last change observed : 16 Sept 2026 · 05:49 UTC