Microsoft Azure Active Directory
The JSA DSM for Microsoft Azure Active Directory Audit logs collects events such as user creation, role assignment, and group assignment events. The Microsoft Azure Active Directory Sign-in logs collects user sign-in activity events.
To integrate Microsoft Azure Active Directory with JSA, complete the following steps:
If automatic updates are not enabled, download and install the most recent version of the following RPMs on your JSA console:
DSMCommon
Protocol Common RPM
Microsoft Azure Platform DSM RPM
Microsoft Azure Active Directory DSM RPM
Microsoft Azure Event Hubs Protocol RPM
Optional: Create a storage account.
Note:You must have a storage account to connect to an event hub.
Optional: Create an event hub.
Configure your Microsoft Azure Active Directory to forward events to an Azure Event Hub by streaming events through Diagnostic Logs.
Configure Microsoft Azure Event Hubs to communicate with JSA.
If JSA does not automatically detect the log source, add a Microsoft Azure Active Directory log source on the JSA Console by using the Microsoft Azure Event Hubs protocol.
Microsoft Azure Active Directory DSM Specifications
When you configure the Microsoft Azure Active Directory DSM, understanding the specifications for the Microsoft Azure Active Directory DSM can help ensure a successful integration. For example, knowing what protocol to use before you begin can help reduce frustration during the configuration process.
Specification |
Value |
---|---|
Manufacturer |
Microsoft |
DSM name |
Microsoft Azure Active Directory |
RPM file name |
DSM-MicrosoftAzureActiveDirectory-JSA-version-Build_number.noarch.rpm |
Protocol |
Microsoft Azure Event Hubs |
Event format |
JSON |
Recorded event types |
SignIn logs, Audit logs |
Automatically discovered? |
Yes |
Includes identity? |
No |
Includes custom properties? |
No |
More information |
Microsoft Azure Active Directory Log Source Parameters
When you add an Azure Active Directory log source on the JSAConsole by using the Microsoft Azure Event Hubs protocol, there are specific parameters you must use.
The following table describes the parameters that require specific values to retrieve Microsoft Azure Active Directory events from Microsoft Azure Active Directory:
Parameter |
Value |
---|---|
Log Source type |
Microsoft Azure Active Directory |
Protocol Configuration |
Microsoft Azure Event Hubs |
Log Source Identifier |
The Log Source Identifier can be any valid value, including the same value as the Log Source Name parameter, and doesn't need to reference a specific server. If you configured multiple Microsoft Azure Active Directory log sources, you might want to identify the first log source as AzureActiveDir-1, the second log source as AzureActiveDir-2, and the third log source as AzureActiveDir-3. |
Microsoft Azure Active Directory Sample Event Messages
Use these sample event messages as a way of verifying a successful integration with JSA.
The following table provides sample event messages for the Microsoft Azure Active Directory DSM:
Due to formatting, paste the message formats into a text editor and then remove any carriage return or line feed characters.
Event name |
Low level category |
Sample log message |
---|---|---|
Add member to group - success |
Group Member Added |
|
Sign-in activity fail |
User Login Failure |
|