azureblog.co.uk
← cd ~/learn
// learning path · intermediate to advanced

Identity security operations

Spot trouble in the logs, contain compromised accounts and close the gaps attackers use: apps, tokens and agents.

0 of 6 read · about 15 minutes in total
start with part 1 →
  1. 01Six KQL queries for Entra sign-in logs every admin should keepOnce sign-in logs flow into Log Analytics, a few queries answer most of the questions you'll get. Copy these into a workbook or saved searches.2 min✓ read
  2. 02SOC Identity Responder: contain a compromised account without handing out admin rolesA new built-in Entra role lets security analysts disable users, revoke sessions and reset passwords from Microsoft Defender, and nothing else. Here's what it can and can't do, and how to set it up with PIM.5 min✓ read
  3. 03Microsoft Authenticator now blocks jailbroken and rooted devicesAuthenticator now refuses to add or use work and school accounts on jailbroken or rooted phones. There's nothing to configure, but your service desk should know.2 min✓ read
  4. 04Find expiring app secrets and certificates before they biteExpired client secrets cause some of the most avoidable outages in Entra. A short Graph script shows what's about to expire across the tenant.2 min✓ read
  5. 05Configurable token lifetimes are GA: when to shorten them (and when not to)You can now set the lifetime of access, ID and SAML tokens per application. Useful for sensitive apps, but there are better tools for most session problems.2 min✓ read
  6. 06Entra Agent ID: giving AI agents real identitiesAI agents now get first-class identities in Entra, with Conditional Access and lifecycle controls following. Here's why identity teams should get involved early.2 min✓ read

Progress is saved in this browser only. A post counts as read once you've scrolled most of the way through it.

Check what you've learned

5 questions. Get 4 or more right to earn the Identity security operations badge. You can take it before reading, too.

  1. Which role lets SOC analysts disable users and revoke sessions without broad admin rights?
  2. Revoking a user's sessions invalidates what?
  3. What's the right containment order for a compromised account?
  4. Which KQL table holds interactive user sign-ins?
  5. Why give every AI agent its own identity?