Skip to content

[Feature] Entra Risks Module Include most common login locations #480

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Open
NobleWolf opened this issue Jan 3, 2025 · 2 comments
Open

[Feature] Entra Risks Module Include most common login locations #480

NobleWolf opened this issue Jan 3, 2025 · 2 comments
Labels
module/aadrisks AAD Risks Module pending-triage Submitted issue needing triage

Comments

@NobleWolf
Copy link

Is your feature request related to a problem? Please describe.
When investigating Impossible Travel type alerts the Entra ID Risks Module includes some useful information, but knowing where the account most commonly authenticates from would be most useful.
Currently that information is not there:
image

Describe the solution you'd like
The Defender portal entity page includes this information:
image

This information is supremely useful and always required by our Analysts for Impossible Travel (and similar) type alerts.

Describe alternatives you've considered
Accessing this information from Defender

Additional context
None

@NobleWolf NobleWolf added the pending-triage Submitted issue needing triage label Jan 3, 2025
@briandelmsft briandelmsft added the module/aadrisks AAD Risks Module label Jan 3, 2025
@piaudonn
Copy link
Collaborator

piaudonn commented Jan 5, 2025

Perhaps it is time to work on #210
What other insights shall we surface?

@NobleWolf
Copy link
Author

@piaudonn yes, that #210 sounds about right. Sorry for not searching the open issues 😨

As for other insights I'm not familiar with what's available in UEBA.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
module/aadrisks AAD Risks Module pending-triage Submitted issue needing triage
Projects
None yet
Development

No branches or pull requests

3 participants