let query_frequency = 1h;
let audit_properties = dynamic(['isauditenabled', 'isuseraccessauditenabled','isreadauditenabled']);
DataverseActivity
| where TimeGenerated >= ago(query_frequency)
| where Message in~ ("Update", "UpdateAuditSettings")
| where Fields has_any (audit_properties)
| mv-expand Fields
| extend AuditValue = Fields.Name, AuditEnabled = tobool(Fields.Value)
| where AuditValue in~ (audit_properties) and not (AuditEnabled)
| extend
CloudAppId = int(32780),
AccountName = tostring(split(UserId, '@')[0]),
UPNSuffix = tostring(split(UserId, '@')[1])
| project
TimeGenerated,
UserId,
ClientIp,
OriginalObjectId,
AuditValue,
AuditEnabled,
InstanceUrl,
CloudAppId,
AccountName,
UPNSuffix
queryFrequency: 1h
OriginalUri: https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Microsoft Business Applications/Analytic Rules/Dataverse - Audit logging disabled.yaml
triggerOperator: gt
status: Available
relevantTechniques:
- T1562
name: Dataverse - Audit logging disabled
eventGroupingSettings:
aggregationKind: SingleAlert
queryPeriod: 14d
query: |
let query_frequency = 1h;
let audit_properties = dynamic(['isauditenabled', 'isuseraccessauditenabled','isreadauditenabled']);
DataverseActivity
| where TimeGenerated >= ago(query_frequency)
| where Message in~ ("Update", "UpdateAuditSettings")
| where Fields has_any (audit_properties)
| mv-expand Fields
| extend AuditValue = Fields.Name, AuditEnabled = tobool(Fields.Value)
| where AuditValue in~ (audit_properties) and not (AuditEnabled)
| extend
CloudAppId = int(32780),
AccountName = tostring(split(UserId, '@')[0]),
UPNSuffix = tostring(split(UserId, '@')[1])
| project
TimeGenerated,
UserId,
ClientIp,
OriginalObjectId,
AuditValue,
AuditEnabled,
InstanceUrl,
CloudAppId,
AccountName,
UPNSuffix
version: 3.2.1
kind: Scheduled
tactics:
- DefenseEvasion
description: Identifies a change in system audit configuration whereby audit logging is turned off.
alertDetailsOverride:
alertDescriptionFormat: 'Audit settings changes were detected in {{InstanceUrl}}. {{AuditValue}} enabled: was set to {{AuditEnabled}}.'
alertDisplayNameFormat: 'Dataverse - Audit logging was disabled in {{InstanceUrl}} '
id: ea07523b-e6b8-469b-9e25-cdef1ae6fb45
entityMappings:
- fieldMappings:
- columnName: AccountName
identifier: Name
- columnName: UPNSuffix
identifier: UPNSuffix
entityType: Account
- fieldMappings:
- columnName: ClientIp
identifier: Address
entityType: IP
- fieldMappings:
- columnName: CloudAppId
identifier: AppId
- columnName: InstanceUrl
identifier: InstanceName
entityType: CloudApplication
triggerThreshold: 0
requiredDataConnectors:
- dataTypes:
- DataverseActivity
connectorId: Dataverse
severity: Low