Comments (4)
Good point.
Microsoft's documentation makes a reference to this here: https://docs.microsoft.com/en-us/office/office-365-management-api/office-365-management-activity-api-schema#common-schema
See the point on ResultStatus.
I did some testing on this as well and I don't think using ExtendedProperties is reliable in determining whether the logon was successful or not. For example - I see some events where the ResultStatusDetail is "Success" but a LogonError property still exists with a value of KmsiInterrupt which is documented here: https://docs.microsoft.com/en-gb/azure/active-directory/develop/reference-aadsts-error-codes#aadsts-error-codes
I haven't seen any events where the LogonError property exists (except for when the value is "None") but the even't isn't an authentication failure so maybe that's the most reliable way.
from o365beat.
Actually it looks like LogonError is always "None" for Logout events but LogonError "None" also seems to exists for some successful login events (not sure why this is the case).
So you could filter for successfuly authentication events by searching for events where Operation = UserLoggedIn and LogonError doesn't exist or equals to "None" and ExtendedProerties doesn't contain "Logout"
from o365beat.
Thank you for this issue, and for the discussion! I'd love to consolidate these lessons and move them to the right location. I'll try to distill and capture this in a section in the README soon, with a link to this issue. I'll let you know when that happens, I don't want to close this until we have a good place to direct curious folks.
from o365beat.
Referenced in README in release v1.5.1, and we can keep this (closed) issue for reference and any additional discussion. Thanks again!
from o365beat.
Related Issues (20)
- Exiting: error loading config file: yaml: line 2: did not find expected node content HOT 5
- visualization not working HOT 5
- Client.Timeout for Exchange/General/Sharepoint HOT 6
- Docker Instructions HOT 3
- Parsing Extended Properties HOT 4
- Preventing Duplicate Events HOT 4
- Dashboard and visualizations not working - error with fields.keyword HOT 5
- Logstash connection errors HOT 7
- o365 audit.exchange not returning threat audit logs HOT 3
- WARN beater/o365beat.go:249 start XX must be <=YY hrs ago, resetting HOT 3
- Live Realoding Credentials HOT 2
- Proxy support for the API requests HOT 1
- Certificate signed by unknown authority message HOT 2
- AzureActiveDirectory Logs not pulled HOT 3
- Log content changed recently?
- GCC High no available content locations: HOT 1
- Tenant ID not found
- Does O365beat support multiple Office 365 tenants scenario
- Log file is not getting created
Recommend Projects
-
React
A declarative, efficient, and flexible JavaScript library for building user interfaces.
-
Vue.js
🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.
-
Typescript
TypeScript is a superset of JavaScript that compiles to clean JavaScript output.
-
TensorFlow
An Open Source Machine Learning Framework for Everyone
-
Django
The Web framework for perfectionists with deadlines.
-
Laravel
A PHP framework for web artisans
-
D3
Bring data to life with SVG, Canvas and HTML. 📊📈🎉
-
Recommend Topics
-
javascript
JavaScript (JS) is a lightweight interpreted programming language with first-class functions.
-
web
Some thing interesting about web. New door for the world.
-
server
A server is a program made to process requests and deliver data to clients.
-
Machine learning
Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.
-
Visualization
Some thing interesting about visualization, use data art
-
Game
Some thing interesting about game, make everyone happy.
Recommend Org
-
Facebook
We are working to build community through open source technology. NB: members must have two-factor auth.
-
Microsoft
Open source projects and samples from Microsoft.
-
Google
Google ❤️ Open Source for everyone.
-
Alibaba
Alibaba Open Source for everyone
-
D3
Data-Driven Documents codes.
-
Tencent
China tencent open source team.
from o365beat.