elastic / elastic/integrations
[Azure]: Bug - Sign-In Logs Reporting `none` Where Value Exists
- Dominant language
- Handlebars
- Stars
- 333
- Forks
- 647
- Avg merge
- 2d 18h
- Merged PRs (30d)
- 182
Description
### Integration Name
Azure Logs [azure]
### Dataset Name
azure.signinlogs
### Integration Version
1.22.0
### Agent Version
8.16.1
### Agent Output Type
elasticsearch
### Elasticsearch Version
latest
### OS Version and Architecture
Ubuntu 22.04 LTS
### Software/API Version
_No response_
### Error Message
Azure Sign-In Logs are not reporting the correct value for `azure.signinlogs.properties.original_transfer_method`.
This value is typically reported as `none`
### Event Original
```
{
"Level": 4,
"callerIpAddress": "x.x.x.x",
"category": "SignInLogs",
"correlationId": "fc7f84b3-e612-4334-afcc-28a9f56d1d1b",
"durationMs": 0,
"identity": "deviceCode",
"location": "US",
"operationName": "Sign-in activity",
"operationVersion": "1.0",
"properties": {
"appDisplayName": "Device Code App",
"appId": "46cf8473-3d18-40f5-9a68-c5b3d5ef0610",
"appOwnerTenantId": "fb83355b-3bfe-4849-a3bc-480c7564e41b",
"appServicePrincipalId": null,
"appliedConditionalAccessPolicies": [
{
"conditionsNotSatisfied": 0,
"conditionsSatisfied": 3,
"displayName": "Require multifactor authentication for admins",
"enforcedGrantControls": ["Mfa"],
"enforcedSessionControls": [],
"id": "a6123755-6000-48e4-a718-3f99379f824b",
"result": "success"
},
{
"conditionsNotSatisfied": 0,
"conditionsSatisfied": 32787,
"displayName": "Monitor Device Code Authentication",
"enforcedGrantControls": ["Mfa"],
"enforcedSessionControls": [],
"id": "f2deefef-f795-410d-a582-1f3fd607e4b7",
"result": "success"
},
{
"conditionsNotSatisfied": 2,
"conditionsSatisfied": 1,
"displayName": "Multi-Factor Authentication",
"enforcedGrantControls": ["Mfa"],
"enforcedSessionControls": [],
"id": "66ba81e8-2404-40ad-a87c-e16457b71d16",
"result": "notApplied"
}
],
"authenticationContextClassReferences": [],
"authenticationDetails": [
{
"authenticationMethod": "Previously satisfied",
"authenticationStepDateTime": "2025-02-19T01:24:03.9985476+00:00",
"authenticationStepRequirement": "Primary authentication",
"authenticationStepResultDetail": "MFA requirement satisfied by claim in the token",
"succeeded": true
}
],
"authenticationProcessingDetails": [
{ "key": "Legacy TLS (TLS 1.0, 1.1, 3DES)", "value": "False" },
{ "key": "Is CAE Token", "value": "False" }
],
"authenticationProtocol": "deviceCode",
"authenticationRequirement": "multiFactorAuthentication",
"authenticationRequirementPolicies": [
{
"detail": "Conditional Access",
"requirementProvider": "multiConditionalAccess"
}
],
"authenticationStrengths": [],
"autonomousSystemNumber": 12097,
"clientAppUsed": "Mobile Apps and Desktop clients",
"clientCredentialType": "none",
"conditionalAccessAudiences": [
{
"applicationId": "00000003-0000-0ff1-ce00-000000000000",
"audienceReasons": "none"
},
{
"applicationId": "00000002-0000-0ff1-ce00-000000000000",
"audienceReasons": "none"
},
{
"applicationId": "00000002-0000-0000-c000-000000000000",
"audienceReasons": "none"
}
],
"conditionalAccessStatus": "success",
"correlationId": "fc7f84b3-e612-4334-afcc-28a9f56d1d1b",
"createdDateTime": "2025-02-19T01:24:03.9985476+00:00",
"crossTenantAccessType": "none",
"deviceDetail": { "browser": "Chrome 133.0.0", "deviceId": "" },
"flaggedForReview": false,
"homeTenantId": "fb83355b-3bfe-4849-a3bc-480c7564e41b",
"id": "cff80330-8585-4784-a659-f50e91873400",
"incomingTokenType": "none",
"ipAddress": "x.x.x.x",
"isInteractive": true,
"isTenantRestricted": false,
"isThroughGlobalSecureAccess": false,
"location": {
"city": "SANITIZED",
"countryOrRegion": "US",
"geoCoordinates": {
"latitude": "SANITIZED",
"longitude": "SANITIZED"
},
"state": "Ohio"
},
"mfaDetail": {},
"networkLocationDetails": [],
"originalRequestId": "cff80330-8585-4784-a659-f50e91873400",
"originalTransferMethod": "none",
"privateLinkDetails": {},
"processingTimeInMilliseconds": 2192,
"resourceDisplayName": "Microsoft Graph",
"resourceId": "00000003-0000-0000-c000-000000000000",
"resourceOwnerTenantId": "f8cdef31-a31e-4b4a-93e4-5f571e91255a",
"resourceServicePrincipalId": "6d5c02a0-9127-4686-abff-d770323c28ab",
"resourceTenantId": "fb83355b-3bfe-4849-a3bc-480c7564e41b",
"riskDetail": "none",
"riskEventTypes": [],
"riskEventTypes_v2": [],
"riskLevelAggregated": "none",
"riskLevelDuringSignIn": "none",
"riskState": "none",
"rngcStatus": 0,
"servicePrincipalId": "",
"sessionId": "00214b89-663c-2f85-a18b-c24f098564cd",
"sessionLifetimePolicies": [],
"signInTokenProtectionStatus": "none",
"ssoExtensionVersion": "",
"status": {
"additionalDetails": "MFA requirement satisfied by claim in the token",
"errorCode": 0
},
"tenantId": "fb83355b-3bfe-4849-a3bc-480c7564e41b",
"tokenIssuerName": "",
"tokenIssuerType": "AzureAD",
"tokenProtectionStatusDetails": {
"signInSessionStatus": "unbound",
"signInSessionStatusCode": 1002
},
"uniqueTokenIdentifier": "MAP4z4WFhEemWfUOkYc0AA",
"userAgent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36",
"userDisplayName": "deviceCode",
"userId": "dc217a03-c8c0-40c2-98b0-b0b09e241e18",
"userPrincipalName": "devicecode@elastictrade.onmicrosoft.com",
"userType": "Member"
},
"resourceId": "/tenants/fb83355b-3bfe-4849-a3bc-480c7564e41b/providers/Microsoft.aadiam",
"resultSignature": "None",
"resultType": "0",
"tenantId": "fb83355b-3bfe-4849-a3bc-480c7564e41b",
"time": "2025-02-19T01:26:00.3494424Z"
}
```
### What did you do?
Enabled "Collect all Azure Logs (v2 preview)" instead of all v1 settings in the integration policy settings.
Leveraged event hub and storage account from Azure as required in setup.
### What did you see?
Nothing specifically.
### What did you expect to see?
`azure.signinlogs.properties.original_transfer_method`:`Device code flow`
### Anything else?
Here are some additional screenshots.
We have a serverless stack available to share.
We also have an Azure environment available to share as well.
Contributor guide
Assessment
This issue has not been assessed yet.