Elastic low stable kql
M365 Exchange Federated Domain Created or Modified
Identifies a new or modified federation domain, which can be used to create a trust between O365 and an external identity provider.
Detection Logic
data_stream.dataset:o365.audit and event.provider:Exchange and event.category:web and event.action:("Set-AcceptedDomain" or
"Set-MsolDomainFederationSettings" or "Add-FederatedDomain" or "New-AcceptedDomain" or "Remove-AcceptedDomain" or "Remove-FederatedDomain") and
event.outcome:success Field Validations
Loading…
Comments (0)
Loading comments...