Data Source: Azure Active Directory Update authorization policy

Logs an event when an authorization policy is updated in Azure Active Directory.

Property Value
Source Azure AD
Sourcetype azure:monitor:aad
Separator operationName
+ Fields

            1
            _time
          
            3
            Level
          
            5
            callerIpAddress
          
            7
            category
          
            9
            correlationId
          
            11
            date_hour
          
            13
            date_mday
          
            15
            date_minute
          
            17
            date_month
          
            19
            date_second
          
            21
            date_wday
          
            23
            date_year
          
            25
            date_zone
          
            27
            durationMs
          
            29
            host
          
            31
            index
          
            33
            linecount
          
            35
            operationName
          
            37
            operationVersion
          
            39
            properties.activityDateTime
          
            41
            properties.activityDisplayName
          
            43
            properties.additionalDetails{}.key
          
            45
            properties.additionalDetails{}.value
          
            47
            properties.category
          
            49
            properties.correlationId
          
            51
            properties.id
          
            53
            properties.initiatedBy.user.displayName
          
            55
            properties.initiatedBy.user.id
          
            57
            properties.initiatedBy.user.ipAddress
          
            59
            properties.initiatedBy.user.userPrincipalName
          
            61
            properties.loggedByService
          
            63
            properties.operationType
          
            65
            properties.result
          
            67
            properties.resultReason
          
            69
            properties.targetResources{}.displayName
          
            71
            properties.targetResources{}.id
          
            73
            properties.targetResources{}.modifiedProperties{}.displayName
          
            75
            properties.targetResources{}.modifiedProperties{}.newValue
          
            77
            properties.targetResources{}.modifiedProperties{}.oldValue
          
            79
            properties.targetResources{}.type
          
            81
            properties.userAgent
          
            83
            punct
          
            85
            resourceId
          
            87
            resultSignature
          
            89
            source
          
            91
            sourcetype
          
            93
            splunk_server
          
            95
            tenantId
          
            97
            time
          
            99
            timeendpos
          
            101
            timestartpos
          
            103
            
          
...
not set
1{"time": "2023-10-26T19:22:20.2814027Z", "resourceId": "/tenants/5f210575-a69b-41a7-b623-3f6d79ccd432/providers/Microsoft.aadiam", "operationName": "Update authorization policy", "operationVersion": "1.0", "category": "AuditLogs", "tenantId": "5f210575-a69b-41a7-b623-3f6d79ccd432", "resultSignature": "None", "durationMs": 0, "callerIpAddress": "1.2.3.4", "correlationId": "cc46d719-4c0f-4b78-8795-b0d6ca5b2065", "Level": 4, "properties": {"id": "Directory_cc46d719-4c0f-4b78-8795-b0d6ca5b2065_6CH7M_196574953", "category": "AuthorizationPolicy", "correlationId": "cc46d719-4c0f-4b78-8795-b0d6ca5b2065", "result": "success", "resultReason": "", "activityDisplayName": "Update authorization policy", "activityDateTime": "2023-10-26T19:22:20.2814027+00:00", "loggedByService": "Core Directory", "operationType": "Update", "userAgent": null, "initiatedBy": {"user": {"id": "e4c722ac-3b83-478d-8f52-c388885dc30f", "displayName": null, "userPrincipalName": "attacker@splunkresearch.onmicrosoft.com", "ipAddress": "1.2.3.4", "roles": []}}, "targetResources": [{"id": "24484114-1daa-4700-aaf7-44ee5cbe5678", "displayName": "Authorization Policy", "type": "Other", "modifiedProperties": [{"displayName": "AllowUserConsentForRiskyApps", "oldValue": "[false]", "newValue": "[true]"}, {"displayName": "PermissionGrantPolicyIdsAssignedToDefaultUserRole", "oldValue": "[\"ManagePermissionGrantsForSelf.microsoft-user-default-legacy\"]", "newValue": "[\"microsoft-user-default-legacy\"]"}, {"displayName": "Included Updated Properties", "oldValue": null, "newValue": "\"AllowUserConsentForRiskyApps, PermissionGrantPolicyIdsAssignedToDefaultUserRole\""}], "administrativeUnits": []}], "additionalDetails": [{"key": "User-Agent", "value": "Swagger-Codegen/1.0.0.0/csharp/msal"}]}}

Source: GitHub | Version: 2