↳ Source GitHubRègle analytiqueHigh
Power Platform - Possibly compromised user accesses Power Platform services
Description
Identifies user accounts flagged at risk in Microsoft Entra Identity Protection and correlates these users with sign-in activity in Power Platform, including Power Apps, Power Automate and Power Platform Admin Center.
- Type de règle
- Scheduled
- Version
- 3.0.0
- Statut déclaré
- Available
- Fréquence
- 1h
- Période analysée
- 1d
- Déclenchement
- gt 0
Couverture MITRE déclarée
Sources déclarées
Métadonnées du fichier source. Aucune dépendance déduite du KQL.
Connecteurs
Types de données
Requête KQL
Requête originale, sans modification.
let power_automate_appid = "6204c1d1-4712-4c46-a7d9-3ed63d992682";
let power_apps_appid = "a8f7a65c-f5ba-4859-b2d6-df772c264e9d";
let ppac_appid = "065d9450-1e87-434e-ac2f-69af271549ed";
let query_frequency = 1h;
SigninLogs
| where ingestion_time() >= ago(query_frequency)
| where array_length(todynamic(RiskEventTypes)) != 0 or array_length(todynamic(RiskEventTypes_V2)) != 0
| where AppId in (power_automate_appid, power_apps_appid, ppac_appid)
| extend AffectedPlatform = case(
AppId == ppac_appid,
"Power Platform Admin Center",
AppId == power_apps_appid,
"Power Apps",
AppId == power_automate_appid,
"Power Automate",
"Unknown"
)
| extend
Severity = iif(AffectedPlatform in ("Power Apps", "Power Automate"), "Medium", "High"),
CloudAppId = case(AffectedPlatform == "Power Apps", int(27593), AffectedPlatform == "Power Automate", int(27592), 0),
AccountName = tostring(split(UserPrincipalName, '@')[0]),
UPNSuffix = tostring(split(UserPrincipalName, '@')[1])
| project
TimeGenerated,
UserId,
UniqueTokenIdentifier,
Identity,
RiskEventTypes,
RiskEventTypes_V2,
UserPrincipalName,
AppId,
AppDisplayName,
AffectedPlatform,
IPAddress,
Severity,
CloudAppId,
AccountName,
UPNSuffix
Entités déclarées
Contenus associés
Liens établis à partir des identifiants déclarés et des manifests des solutions.
Traçabilité de la source
GitHubLes valeurs affichées proviennent des fichiers du dépôt Azure/Azure-Sentinel. Elles décrivent le modèle publié, pas la configuration de votre workspace.
- Commit
7ca9800↗- Identifiant source
54d48840-1c64-4399-afee-ad39a069118d
GSTEP / SUIVI DU CATALOGUE
Ajouté au catalogue : 16 sept. 2026 · 05:49 UTC
Dernier changement observé : 16 sept. 2026 · 05:49 UTC