SOLVED

query defender for identity logs

%3CLINGO-SUB%20id%3D%22lingo-sub-2109803%22%20slang%3D%22en-US%22%3Equery%20defender%20for%20identity%20logs%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2109803%22%20slang%3D%22en-US%22%3E%3CP%3Ehi%20-%20how%20can%20i%20query%20using%20either%20sentinel%20or%20kql%20the%20data%20witin%20defender%20for%20identity.%26nbsp%3B%20i%20want%20to%20do%20some%20analysis%20on%20our%20service%20accounts%20and%20the%20data%20will%20help%20with%20this.%26nbsp%3B%20thanks%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2109896%22%20slang%3D%22en-US%22%3ERe%3A%20query%20defender%20for%20identity%20logs%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2109896%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F7270%22%20target%3D%22_blank%22%3E%40Sanjit%20Hayer%3C%2FA%3E%26nbsp%3BYou%20can%20use%20Advanced%20Hunting%20feature%20from%20Microsoft%20365%20Security%20Portal%20-%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Fsecurity.microsoft.com%2Fadvanced-hunting%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3Ehttps%3A%2F%2Fsecurity.microsoft.com%2Fadvanced-hunting%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3CP%3EYou'll%20find%20tables%20for%20IdentityInfo%2C%20IdentitylogonEvents%2C%20IdentityQueryEvents%20and%20IdentityDirectoryEvents.%3C%2FP%3E%3CP%3EThese%20tables%20can%20be%20used%20to%20create%20relevant%20KQL%20queries.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2597439%22%20slang%3D%22en-US%22%3ERe%3A%20query%20defender%20for%20identity%20logs%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2597439%22%20slang%3D%22en-US%22%3E%3CP%3ENew%20writeup%20on%20IdentityInfo%20from%20Itay%20Argoety%3CBR%20%2F%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fazure-sentinel%2Fwhat-s-new-identityinfo-table-is-now-in-public-preview%2Fba-p%2F2571037%22%20target%3D%22_blank%22%3Ehttps%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fazure-sentinel%2Fwhat-s-new-identityinfo-table-is-now-in-public-preview%2Fba-p%2F2571037%3C%2FA%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2802478%22%20slang%3D%22en-US%22%3ERe%3A%20query%20defender%20for%20identity%20logs%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2802478%22%20slang%3D%22en-US%22%3EIs%20this%20table%20also%20available%20via%20the%20API%3F%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2802530%22%20slang%3D%22en-US%22%3ERe%3A%20query%20defender%20for%20identity%20logs%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2802530%22%20slang%3D%22en-US%22%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F1169686%22%20target%3D%22_blank%22%3E%40igaralf%3C%2FA%3E%3CBR%20%2F%3E%3CBR%20%2F%3EYes%20this%20is%20available%20via%20api%20as%20well%20-%3CBR%20%2F%3E%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-US%2Fmicrosoft-365%2Fsecurity%2Fmtp%2Fapi-advanced-hunting%3Fview%3Do365-worldwide%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-US%2Fmicrosoft-365%2Fsecurity%2Fmtp%2Fapi-advanced-hunting%3Fview%3Do365-worldwide%3C%2FA%3E%3C%2FLINGO-BODY%3E
Occasional Contributor

hi - how can i query using either sentinel or kql the data witin defender for identity.  i want to do some analysis on our service accounts and the data will help with this.  thanks

4 Replies
best response confirmed by Sanjit Hayer (Occasional Contributor)
Solution

@Sanjit Hayer You can use Advanced Hunting feature from Microsoft 365 Security Portal - https://security.microsoft.com/advanced-hunting 

You'll find tables for IdentityInfo, IdentitylogonEvents, IdentityQueryEvents and IdentityDirectoryEvents.

These tables can be used to create relevant KQL queries.

Is this table also available via the API?