Microsoft Graph

You can use the Wazuh module for Azure to collect Microsoft Graph activity logs from multiple Azure services (including Microsoft Entra ID) via the Microsoft Graph REST API.

In this section, you learn how to monitor your Microsoft Entra ID activity using the Microsoft Graph REST API. This section contains:

The following Microsoft Graph REST API endpoints support auditing and monitoring activities in Microsoft Entra ID.

Report type

Query

Directory audits

auditLogs/directoryAudits

Sign-ins

auditLogs/signIns

Provisioning

auditLogs/provisioning

These endpoints let administrators and developers monitor and audit Microsoft Entra ID activities for security, compliance, and operational purposes.

Wazuh can process Microsoft Entra ID activity reports using the above endpoints. Each requires a different query. Place these queries in the <query> field of the <request> block in your Wazuh module for Azure configuration.

Configuration

Create the application

This section explains how to create an application that uses the Microsoft Graph REST API. You can also configure an existing application. Skip this step if you already have an existing application.

  1. In the Microsoft Entra ID panel, select App registrations. Then, select New registration.

  2. Give the app a descriptive name, select the appropriate account type, and click Register.

    The app is now registered.

Grant permissions to the application

  1. Click on the application, go to the Overview section, and save the Application (client) ID for later authentication.

  2. Select the Add a permission option in the API permissions section.

  3. Search for "Microsoft Graph" and select the API.

  4. Select the permissions in Application permissions that align with your infrastructure. In this case, the AuditLog.Read.All permissions are granted. Then, click Add permissions.

  5. Use an admin user to Grant admin consent for the tenant.

Obtain the application key for authentication

To use the Microsoft Graph API to retrieve logs, we must generate an application key to authenticate. Follow the steps below to generate the application key.

  1. Select Certificates & secrets, then select New client secret to generate a key.

  2. Give an appropriate description, set a preferred duration for the key, and then click Add.

  3. Copy the key value. Use this for authentication in a later section.

    Note

    Copy the key before exiting this page, as it is displayed once. If you do not copy it before exiting the page, you must generate a new key.

Wazuh agent

We use the (client) ID and key of the application saved during the previous steps here. In this case, both fields were saved in a file for authentication. Check the authentication section for more information about configuring Azure credentials.

  1. Apply the following configuration to the local configuration file /var/ossec/etc/ossec.conf of the Wazuh agent:

    <wodle name="azure-logs">
       <disabled>no</disabled>
       <wday>Monday</wday>
       <time>2:00</time>
       <run_on_start>yes</run_on_start>
    
       <graph>
          <auth_path>/var/ossec/wodles/credentials/<GRAPH_CREDENTIALS></auth_path>
          <tenantdomain><YOUR_TENANT_DOMAIN></tenantdomain>
          <request>
             <tag>microsoft-entra_id</tag>
             <query>auditLogs/directoryAudits</query>
             <time_offset>1d</time_offset>
          </request>
       </graph>
    </wodle>
    

    Where:

    • <auth_path> is the full path of the file holding the application ID and application key. Replace <GRAPH_CREDENTIALS> with your authentication credentials file name.

    • <tenantdomain> is the tenant domain name. You can obtain this from the Overview section in Microsoft Entra ID. Replace the <YOUR_TENANT_DOMAIN> value with your tenant domain.

    • <wday> is the day of the week scheduled for the scan.

    • <query> is the Microsoft Graph endpoint to request.

    • <time> is the time scheduled for the scan.

    • <time_offset> set to 1d means that only the log data from the last day is parsed.

  2. Restart the Wazuh agent to apply the configuration changes:

    # systemctl restart wazuh-agent
    

Check the Wazuh module for Azure reference for more information about using the different available parameters. See the Wazuh Azure authentication file section for guidance on setting up credentials to monitor your Microsoft Entra ID.

Note

The field tenantdomain is mandatory. You can obtain it from the Overview section in Microsoft Entra ID.

Use case

Monitor Microsoft Entra ID

Microsoft Entra ID is the identity and directory management service that combines essential directory services, application access management, and identity protection in a single solution.

Wazuh can monitor the Microsoft Entra ID (ME-ID) service using the activity reports provided by the Microsoft Graph REST API. Microsoft Graph API can perform read operations on directory data and objects in Microsoft Entra ID applications.

Here is an example of Microsoft Entra ID activity monitoring using the above configuration.

Monitor a new user creation

Create a new user in Azure. A successful user creation activity produces a log entry. You can retrieve this log using the auditLogs/directoryAudits query.

  1. Navigate to Users > All users, select New user > Create new user.

  2. Fill in the required details and click Review + create. The user is now created.

    You can check the result of the successful user creation in the Audit logs section of Microsoft Entra ID.

    The results are available in the Threat Hunting tab of the Wazuh dashboard.