Elastic low stable kql

M365 Exchange Federated Domain Created or Modified

Identifies a new or modified federation domain, which can be used to create a trust between O365 and an external identity provider.

View Source

Detection Logic

data_stream.dataset:o365.audit and event.provider:Exchange and event.category:web and event.action:("Set-AcceptedDomain" or
"Set-MsolDomainFederationSettings" or "Add-FederatedDomain" or "New-AcceptedDomain" or "Remove-AcceptedDomain" or "Remove-FederatedDomain") and
event.outcome:success

Field Validations

Loading…

Comments (0)

Loading comments...