<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Microsoft Entra ID on sentinelchangelog.net</title><link>http://sentinelchangelog.net/tags/microsoft-entra-id/</link><description>Recent content in Microsoft Entra ID on sentinelchangelog.net</description><generator>Hugo -- 0.157.0</generator><language>en</language><lastBuildDate>Wed, 03 Jun 2026 06:01:01 +0000</lastBuildDate><atom:link href="http://sentinelchangelog.net/tags/microsoft-entra-id/index.xml" rel="self" type="application/rss+xml"/><item><title>Microsoft Agent Identities Connector: New Entra Non-Human Identity Asset Visibility (Preview)</title><link>http://sentinelchangelog.net/posts/2026-06-03-pr-14326/</link><pubDate>Wed, 03 Jun 2026 06:01:01 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2026-06-03-pr-14326/</guid><description>Agent 365 solution adds new Microsoft Agent Identities connector for tracking agent blueprints and non-human identity assets across four data tables.</description></item><item><title>Entra ID Post-Credential Activity Detection: Service Principal Staging and Privileged Role Escalation</title><link>http://sentinelchangelog.net/posts/2026-05-29-pr-14299/</link><pubDate>Fri, 29 May 2026 10:56:48 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2026-05-29-pr-14299/</guid><description>Three new hunting queries target Midnight Blizzard-style persistence patterns — service principal credential staging, privileged role assignments to new accounts, and Temporary Access Pass abuse.</description></item><item><title>Entra ID Identity Boundary Expansion: Three New Hunting Queries for Stealthy Persistence</title><link>http://sentinelchangelog.net/posts/2026-05-28-pr-14307/</link><pubDate>Thu, 28 May 2026 11:14:14 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2026-05-28-pr-14307/</guid><description>Added three hunting queries targeting identity boundary expansion techniques in Entra ID that escalate privileges without creating new accounts.</description></item><item><title>Entra ID Authentication Anomalies: Advanced Hunting for Privilege Abuse and Defense Evasion</title><link>http://sentinelchangelog.net/posts/2026-05-27-pr-14339/</link><pubDate>Wed, 27 May 2026 13:42:33 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2026-05-27-pr-14339/</guid><description>Adds three-query pack detecting legacy auth bypass, guest account abuse, and post-reset privileged operations.</description></item><item><title>Entra ID Account Takeover: Three-Query Hunting Pack for Post-Compromise Detection</title><link>http://sentinelchangelog.net/posts/2026-05-27-pr-14335/</link><pubDate>Wed, 27 May 2026 13:41:06 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2026-05-27-pr-14335/</guid><description>Adds hunting pack targeting device code phishing, service principal persistence, and bulk password resets by privileged actors.</description></item><item><title>Microsoft Entra ID OAuth Consent Query: Fixing Zero-Result Bug in High-Risk Permission Detection</title><link>http://sentinelchangelog.net/posts/2026-05-27-pr-14334/</link><pubDate>Wed, 27 May 2026 13:38:30 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2026-05-27-pr-14334/</guid><description>Corrects broken hunting query that returned no results due to incorrect property name filter.</description></item><item><title>Entra ID Attack Chain Correlation: Three New Hunting Queries for Sequential Compromise Patterns</title><link>http://sentinelchangelog.net/posts/2026-05-26-pr-14311/</link><pubDate>Tue, 26 May 2026 08:14:04 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2026-05-26-pr-14311/</guid><description>Three hunting queries detect multi-event attack chains in Entra ID—privileged role grants followed by SP credential additions and MFA disabling followed by sign-ins from unknown IPs.</description></item><item><title>Entra ID Hunting Pack: Defense Weakening and Privilege Abuse Detection</title><link>http://sentinelchangelog.net/posts/2026-05-26-pr-14240/</link><pubDate>Tue, 26 May 2026 06:12:52 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2026-05-26-pr-14240/</guid><description>Three hunting queries targeting silent defense weakening techniques and off-hours privilege escalation in Entra ID environments.</description></item><item><title>Entra ID Workload Identity and Privileged Role Hunting Pack: Three New Detection Queries</title><link>http://sentinelchangelog.net/posts/2026-05-21-pr-14281/</link><pubDate>Thu, 21 May 2026 12:50:47 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2026-05-21-pr-14281/</guid><description>New hunting pack targeting workload identity abuse and privileged role assignment anomalies with coverage gaps for service principal credential theft and PIM bypass techniques.</description></item><item><title>Entra ID Cross-Source Hunting Pack: Post-Compromise Pattern Detection</title><link>http://sentinelchangelog.net/posts/2026-05-19-pr-14262/</link><pubDate>Tue, 19 May 2026 10:09:11 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2026-05-19-pr-14262/</guid><description>Three new hunting queries correlate AuditLogs and SigninLogs to surface post-compromise identity patterns using baseline-driven anomaly detection.</description></item><item><title>Microsoft Entra ID Table Rename: Hunting Queries Updated for Current Schema</title><link>http://sentinelchangelog.net/posts/2026-05-18-pr-14186/</link><pubDate>Mon, 18 May 2026 05:36:36 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2026-05-18-pr-14186/</guid><description>12 hunting queries updated to use EntraIdSignInEvents and EntraIdSpnSignInEvents tables, replacing deprecated AADSignInEventsBeta and AADSpnSignInEventsBeta references.</description></item><item><title>Entra ID Attack Chain Detection: 5 New Hunting Queries Target Application Layer Persistence</title><link>http://sentinelchangelog.net/posts/2026-05-13-pr-14239/</link><pubDate>Wed, 13 May 2026 10:29:56 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2026-05-13-pr-14239/</guid><description>Five hunting queries expose OAuth consent abuse, privileged escalation, and Conditional Access evasion used in Midnight Blizzard and Storm-0558 campaigns.</description></item><item><title>Microsoft Entra ID Protection: Enhanced Detection Logic Filters Out Admin Risk Events</title><link>http://sentinelchangelog.net/posts/2026-05-12-pr-14108/</link><pubDate>Tue, 12 May 2026 08:58:14 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2026-05-12-pr-14108/</guid><description>Updated CorrelateIPC_Unfamiliar-Atypical rule adds filtering to exclude admin-triggered atypical travel alerts, improving detection precision.</description></item><item><title>Microsoft Entra ID: Service Principal Credential Manipulation by Rare Actors</title><link>http://sentinelchangelog.net/posts/2026-05-07-pr-14213/</link><pubDate>Thu, 07 May 2026 10:51:04 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2026-05-07-pr-14213/</guid><description>Identifies service principal credential additions by actors not observed performing these operations in the previous 90 days, targeting persistence techniques.</description></item><item><title>Microsoft Entra ID: Hunting Query for Password Spraying Detection via IP Failure Bursts</title><link>http://sentinelchangelog.net/posts/2026-05-07-pr-14208/</link><pubDate>Thu, 07 May 2026 10:50:43 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2026-05-07-pr-14208/</guid><description>Correlates failed sign-ins across multiple identities followed by successful authentication from the same IP within 15 minutes, targeting password spraying patterns.</description></item><item><title>Microsoft Entra ID: New Hunting Query Detects Post-Compromise Token Abuse via ASN Mismatches</title><link>http://sentinelchangelog.net/posts/2026-05-07-pr-14207/</link><pubDate>Thu, 07 May 2026 10:50:16 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2026-05-07-pr-14207/</guid><description>Surfaces rapid ASN changes between interactive and non-interactive sign-ins within 10 minutes, indicating potential post-compromise token misuse.</description></item><item><title>Entra ID Brute Force Detection: Renamed for Broader Windows Device Coverage</title><link>http://sentinelchangelog.net/posts/2026-04-30-pr-14162/</link><pubDate>Thu, 30 Apr 2026 11:04:41 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2026-04-30-pr-14162/</guid><description>Analytic rule renamed from Cloud PC-specific to cover all Entra-authenticated Windows devices, clarifying detection scope without logic changes.</description></item><item><title>Microsoft Entra ID Conditional Access Bypass Detection: False Positive Reduction via Benign Status Code Watchlist</title><link>http://sentinelchangelog.net/posts/2026-04-14-pr-14016/</link><pubDate>Tue, 14 Apr 2026 10:34:59 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2026-04-14-pr-14016/</guid><description>New watchlist filters out 7 known-benign status codes from Conditional Access bypass detection to reduce false positives from legitimate MFA prompts and session expiration events.</description></item><item><title>Microsoft Entra ID: Account Creation/Deletion Detection Enhanced Against Timing Evasion</title><link>http://sentinelchangelog.net/posts/2026-04-13-pr-14049/</link><pubDate>Mon, 13 Apr 2026 10:07:13 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2026-04-13-pr-14049/</guid><description>Critical improvements to AccountCreatedandDeletedinShortTimeframe rule extend detection window to 7 days and use immutable UserID correlation to prevent timing-based evasion techniques.</description></item><item><title>Microsoft Entra ID Assets: Device and Organizational Contact Visibility Expansion</title><link>http://sentinelchangelog.net/posts/2026-03-11-pr-13766/</link><pubDate>Wed, 11 Mar 2026 05:07:17 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2026-03-11-pr-13766/</guid><description>Two new asset tables (EntraDevices, EntraOrgContacts) added to Microsoft Entra ID connector for BloodHound graph building and complete asset enumeration.</description></item><item><title>Documentation Fix: Broken Links Resolved in Microsoft Entra ID and Network Session Essentials</title><link>http://sentinelchangelog.net/posts/2026-02-06-pr-13510/</link><pubDate>Fri, 06 Feb 2026 09:21:39 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2026-02-06-pr-13510/</guid><description>Customer-reported broken links fixed in analytic rule descriptions with corrected MITRE technique references and restored documentation.</description></item><item><title>Microsoft Entra ID: New Conditional Access Security Insights and Monitoring Workbook</title><link>http://sentinelchangelog.net/posts/2025-12-19-pr-13313/</link><pubDate>Fri, 19 Dec 2025 20:29:56 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2025-12-19-pr-13313/</guid><description>New Conditional Access SISM workbook added to provide comprehensive CA policy monitoring and Zero Trust analytics.</description></item><item><title>SOX IT Compliance Solution Released: IT Change Monitoring for Financial Controls</title><link>http://sentinelchangelog.net/posts/2025-12-17-pr-13298/</link><pubDate>Wed, 17 Dec 2025 05:28:36 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2025-12-17-pr-13298/</guid><description>New compliance monitoring solution provides IT systems change tracking and segregation of duties controls for Sarbanes-Oxley compliance programs.</description></item><item><title>Microsoft Entra ID Playbooks: API Permission Updates for Session Revocation</title><link>http://sentinelchangelog.net/posts/2025-12-15-pr-13236/</link><pubDate>Mon, 15 Dec 2025 12:07:03 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2025-12-15-pr-13236/</guid><description>Updates Revoke-AADSignInSessions playbook documentation to use correct User.RevokeSessions.All permissions instead of broader User.ReadWrite.All.</description></item><item><title>Microsoft Entra ID Assets: Fixing Product Name Typo in Data Connector</title><link>http://sentinelchangelog.net/posts/2025-10-29-pr-12955/</link><pubDate>Wed, 29 Oct 2025 08:22:42 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2025-10-29-pr-12955/</guid><description>Fixed typo in Microsoft Entra ID Assets connector title and updated description to use correct Microsoft Sentinel branding.</description></item><item><title>GDPR Compliance Dashboard: New Workbook for Privacy Risk Monitoring</title><link>http://sentinelchangelog.net/posts/2025-10-09-pr-12933/</link><pubDate>Thu, 09 Oct 2025 12:04:16 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2025-10-09-pr-12933/</guid><description>New GDPR Compliance solution adds workbook consolidating privacy risk signals from Defender XDR, Microsoft Purview, Azure SQL, and Entra ID.</description></item><item><title>Microsoft Entra ID Assets Solution: New Data Risk Graph Foundation for Purview Integration</title><link>http://sentinelchangelog.net/posts/2025-09-25-pr-12810/</link><pubDate>Thu, 25 Sep 2025 05:53:40 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2025-09-25-pr-12810/</guid><description>New Microsoft Entra ID Assets connector provides supplemental asset data for enhanced activity insights and data risk graph capabilities in Microsoft Purview.</description></item><item><title>Microsoft Entra ID Connector: Preview Labels Removed from GA Data Types</title><link>http://sentinelchangelog.net/posts/2025-09-23-pr-12770/</link><pubDate>Tue, 23 Sep 2025 10:02:25 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2025-09-23-pr-12770/</guid><description>Entra ID connector updated to remove preview designations from data types that have reached general availability.</description></item><item><title>Microsoft Entra ID Conditional Access Rules: Incident Configuration Fix Resolves Rule Creation Failures</title><link>http://sentinelchangelog.net/posts/2025-08-29-pr-12717/</link><pubDate>Fri, 29 Aug 2025 08:18:56 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2025-08-29-pr-12717/</guid><description>Microsoft Entra ID Conditional Access detection rules updated to fix lookbackDuration format preventing rule deployment in Microsoft Sentinel workspaces.</description></item></channel></rss>