elastic / elastic/integrations

[Azure]: Bug - Sign-In Logs Reporting `none` Where Value Exists

Open
#12,833 0 comments 0 reactions 1 assignee Claimed by @terrancedejesus View on GitHub
Integration:azure needs:triage Team:Obs-InfraObs
Dominant language
Handlebars
Stars
333
Forks
647
Avg merge
2d 18h
Merged PRs (30d)
182

Description

### Integration Name

Azure Logs [azure]

### Dataset Name

azure.signinlogs

### Integration Version

1.22.0

### Agent Version

8.16.1

### Agent Output Type

elasticsearch

### Elasticsearch Version

latest

### OS Version and Architecture

Ubuntu 22.04 LTS

### Software/API Version

_No response_

### Error Message

Azure Sign-In Logs are not reporting the correct value for `azure.signinlogs.properties.original_transfer_method`.

This value is typically reported as `none`

### Event Original

```
{
"Level": 4,
"callerIpAddress": "x.x.x.x",
"category": "SignInLogs",
"correlationId": "fc7f84b3-e612-4334-afcc-28a9f56d1d1b",
"durationMs": 0,
"identity": "deviceCode",
"location": "US",
"operationName": "Sign-in activity",
"operationVersion": "1.0",
"properties": {
"appDisplayName": "Device Code App",
"appId": "46cf8473-3d18-40f5-9a68-c5b3d5ef0610",
"appOwnerTenantId": "fb83355b-3bfe-4849-a3bc-480c7564e41b",
"appServicePrincipalId": null,
"appliedConditionalAccessPolicies": [
{
"conditionsNotSatisfied": 0,
"conditionsSatisfied": 3,
"displayName": "Require multifactor authentication for admins",
"enforcedGrantControls": ["Mfa"],
"enforcedSessionControls": [],
"id": "a6123755-6000-48e4-a718-3f99379f824b",
"result": "success"
},
{
"conditionsNotSatisfied": 0,
"conditionsSatisfied": 32787,
"displayName": "Monitor Device Code Authentication",
"enforcedGrantControls": ["Mfa"],
"enforcedSessionControls": [],
"id": "f2deefef-f795-410d-a582-1f3fd607e4b7",
"result": "success"
},
{
"conditionsNotSatisfied": 2,
"conditionsSatisfied": 1,
"displayName": "Multi-Factor Authentication",
"enforcedGrantControls": ["Mfa"],
"enforcedSessionControls": [],
"id": "66ba81e8-2404-40ad-a87c-e16457b71d16",
"result": "notApplied"
}
],
"authenticationContextClassReferences": [],
"authenticationDetails": [
{
"authenticationMethod": "Previously satisfied",
"authenticationStepDateTime": "2025-02-19T01:24:03.9985476+00:00",
"authenticationStepRequirement": "Primary authentication",
"authenticationStepResultDetail": "MFA requirement satisfied by claim in the token",
"succeeded": true
}
],
"authenticationProcessingDetails": [
{ "key": "Legacy TLS (TLS 1.0, 1.1, 3DES)", "value": "False" },
{ "key": "Is CAE Token", "value": "False" }
],
"authenticationProtocol": "deviceCode",
"authenticationRequirement": "multiFactorAuthentication",
"authenticationRequirementPolicies": [
{
"detail": "Conditional Access",
"requirementProvider": "multiConditionalAccess"
}
],
"authenticationStrengths": [],
"autonomousSystemNumber": 12097,
"clientAppUsed": "Mobile Apps and Desktop clients",
"clientCredentialType": "none",
"conditionalAccessAudiences": [
{
"applicationId": "00000003-0000-0ff1-ce00-000000000000",
"audienceReasons": "none"
},
{
"applicationId": "00000002-0000-0ff1-ce00-000000000000",
"audienceReasons": "none"
},
{
"applicationId": "00000002-0000-0000-c000-000000000000",
"audienceReasons": "none"
}
],
"conditionalAccessStatus": "success",
"correlationId": "fc7f84b3-e612-4334-afcc-28a9f56d1d1b",
"createdDateTime": "2025-02-19T01:24:03.9985476+00:00",
"crossTenantAccessType": "none",
"deviceDetail": { "browser": "Chrome 133.0.0", "deviceId": "" },
"flaggedForReview": false,
"homeTenantId": "fb83355b-3bfe-4849-a3bc-480c7564e41b",
"id": "cff80330-8585-4784-a659-f50e91873400",
"incomingTokenType": "none",
"ipAddress": "x.x.x.x",
"isInteractive": true,
"isTenantRestricted": false,
"isThroughGlobalSecureAccess": false,
"location": {
"city": "SANITIZED",
"countryOrRegion": "US",
"geoCoordinates": {
"latitude": "SANITIZED",
"longitude": "SANITIZED"
},
"state": "Ohio"
},
"mfaDetail": {},
"networkLocationDetails": [],
"originalRequestId": "cff80330-8585-4784-a659-f50e91873400",
"originalTransferMethod": "none",
"privateLinkDetails": {},
"processingTimeInMilliseconds": 2192,
"resourceDisplayName": "Microsoft Graph",
"resourceId": "00000003-0000-0000-c000-000000000000",
"resourceOwnerTenantId": "f8cdef31-a31e-4b4a-93e4-5f571e91255a",
"resourceServicePrincipalId": "6d5c02a0-9127-4686-abff-d770323c28ab",
"resourceTenantId": "fb83355b-3bfe-4849-a3bc-480c7564e41b",
"riskDetail": "none",
"riskEventTypes": [],
"riskEventTypes_v2": [],
"riskLevelAggregated": "none",
"riskLevelDuringSignIn": "none",
"riskState": "none",
"rngcStatus": 0,
"servicePrincipalId": "",
"sessionId": "00214b89-663c-2f85-a18b-c24f098564cd",
"sessionLifetimePolicies": [],
"signInTokenProtectionStatus": "none",
"ssoExtensionVersion": "",
"status": {
"additionalDetails": "MFA requirement satisfied by claim in the token",
"errorCode": 0
},
"tenantId": "fb83355b-3bfe-4849-a3bc-480c7564e41b",
"tokenIssuerName": "",
"tokenIssuerType": "AzureAD",
"tokenProtectionStatusDetails": {
"signInSessionStatus": "unbound",
"signInSessionStatusCode": 1002
},
"uniqueTokenIdentifier": "MAP4z4WFhEemWfUOkYc0AA",
"userAgent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36",
"userDisplayName": "deviceCode",
"userId": "dc217a03-c8c0-40c2-98b0-b0b09e241e18",
"userPrincipalName": "devicecode@elastictrade.onmicrosoft.com",
"userType": "Member"
},
"resourceId": "/tenants/fb83355b-3bfe-4849-a3bc-480c7564e41b/providers/Microsoft.aadiam",
"resultSignature": "None",
"resultType": "0",
"tenantId": "fb83355b-3bfe-4849-a3bc-480c7564e41b",
"time": "2025-02-19T01:26:00.3494424Z"
}
```

### What did you do?

Enabled "Collect all Azure Logs (v2 preview)" instead of all v1 settings in the integration policy settings.

Leveraged event hub and storage account from Azure as required in setup.

### What did you see?

Nothing specifically.

### What did you expect to see?

`azure.signinlogs.properties.original_transfer_method`:`Device code flow`

### Anything else?

Here are some additional screenshots.

Image

Image

Image

Image

We have a serverless stack available to share.
We also have an Azure environment available to share as well.

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.