Microsoft Entra Risk Detection
You can integrate Microsoft Entra Risk Detection with Sophos XDR so that it sends data to Sophos for analysis.
This page gives you an overview of the integration.
Entra Risk Detection product overview
Microsoft Entra ID Protection is Microsoft's identity risk detection and remediation service within Microsoft Entra ID (formerly Azure Active Directory). It detects identity-based risks, such as leaked credentials, sign-ins from anonymous IP addresses, impossible travel, and sign-ins from unfamiliar locations or suspicious activity, and surfaces them as risk detections associated with risky sign-ins and risky users.
What we ingest
Sophos XDR collects Microsoft Entra ID Protection risk detections. These can be delivered through Azure Event Hubs (the preferred path) or collected by calling the Microsoft Graph REST APIs on a schedule. The following log categories are collected:
- Risk detections: Identity risk events raised by Entra ID Protection for risky sign-ins and risky users.
Event and data types
We ingest the following event and data types from Entra Risk Detection:
- Risk detections: Identity risk events such as leaked credentials, anonymous IP address, impossible travel, and unfamiliar sign-in properties, including the detection type, risk level, user, and sign-in context. Normalized to third-party security alert and cloud audit telemetry.
Data provided by this integration
Data provided by Entra Risk Detection gets normalized to the following schemas:
cloudauditthirdpartyalert
For more information about using schemas in Data Lake Search, see Schemas and logical types.