Microsoft Sentinel Analytic Rules
cloudbrothers.infoAzure Sentinel RepoToggle Dark/Light/Auto modeToggle Dark/Light/Auto modeToggle Dark/Light/Auto modeBack to homepage

Conditional Access - A Conditional Access policy was deleted

Back
Id2e96fa64-ac4d-4c92-b79e-e9c54b5d8230
RulenameConditional Access - A Conditional Access policy was deleted
DescriptionA Conditional Access policy was deleted from Entra ID.
SeverityLow
TacticsDefenseEvasion
TechniquesT1562.007
Required data connectorsAzureActiveDirectory
KindScheduled
Query frequency5m
Query period5m
Trigger threshold0
Trigger operatorgt
Source Urihttps://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Microsoft Entra ID/Analytic Rules/Conditional Access - A Conditional Access policy was deleted.yaml
Version1.0.1
Arm template2e96fa64-ac4d-4c92-b79e-e9c54b5d8230.json
Deploy To Azure
// A Conditional Access policy was deleted.
AuditLogs
| where OperationName in ("Delete conditional access policy")
| extend modifiedBy = tostring(InitiatedBy.user.userPrincipalName)
| extend accountName = tostring(split(modifiedBy, "@")[0])
| extend upnSuffix = tostring(split(modifiedBy, "@")[1])
| project
    TimeGenerated,
    OperationName,
    policy = TargetResources[0].displayName,
    modifiedBy,
    accountName,
    upnSuffix,
    result = Result,
    oldPolicy = TargetResources[0].modifiedProperties[0].oldValue
| order by TimeGenerated desc
id: 2e96fa64-ac4d-4c92-b79e-e9c54b5d8230
eventGroupingSettings:
  aggregationKind: AlertPerResult
triggerOperator: gt
OriginalUri: https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Microsoft Entra ID/Analytic Rules/Conditional Access - A Conditional Access policy was deleted.yaml
entityMappings:
- fieldMappings:
  - identifier: Name
    columnName: accountName
  - identifier: UPNSuffix
    columnName: upnSuffix
  entityType: Account
requiredDataConnectors:
- dataTypes:
  - AuditLogs
  connectorId: AzureActiveDirectory
queryFrequency: 5m
suppressionEnabled: false
queryPeriod: 5m
triggerThreshold: 0
incidentConfiguration:
  groupingConfiguration:
    lookbackDuration: PT1H
    groupByAlertDetails: []
    reopenClosedIncident: false
    matchingMethod: AllEntities
    groupByCustomDetails: []
    groupByEntities: []
    enabled: false
  createIncident: true
query: |
  // A Conditional Access policy was deleted.
  AuditLogs
  | where OperationName in ("Delete conditional access policy")
  | extend modifiedBy = tostring(InitiatedBy.user.userPrincipalName)
  | extend accountName = tostring(split(modifiedBy, "@")[0])
  | extend upnSuffix = tostring(split(modifiedBy, "@")[1])
  | project
      TimeGenerated,
      OperationName,
      policy = TargetResources[0].displayName,
      modifiedBy,
      accountName,
      upnSuffix,
      result = Result,
      oldPolicy = TargetResources[0].modifiedProperties[0].oldValue
  | order by TimeGenerated desc  
name: Conditional Access - A Conditional Access policy was deleted
kind: Scheduled
tactics:
- DefenseEvasion
severity: Low
relevantTechniques:
- T1562.007
suppressionDuration: 5h
version: 1.0.1
description: A Conditional Access policy was deleted from Entra ID.