Docs: Update with new API permission requirement supporting BED-7248: Entra ID User Last Logon Timestamp AZUser Node Property #170
Conversation
WalkthroughThis PR updates the Azure configuration documentation by introducing an optional step to enable the AuditLog.Read.All permission, which allows collection of AZUser.LastSuccessfulSignInDateTime data. Subsequent steps are renumbered to reflect this addition. Changes
Estimated code review effort🎯 2 (Simple) | ⏱️ ~8 minutes Possibly related PRs
Suggested labels
Suggested reviewers
Poem
🚥 Pre-merge checks | ✅ 3✅ Passed checks (3 passed)
✏️ Tip: You can configure your own custom pre-merge checks in the settings. Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
Thanks for the PR @Mayyhem! This is a good reminder for me to create a release branch for 8.6.0. I'll do that and merge this PR into it along with all other release-related doc PRs. |
The AuditLog.Read.All permission is required to collect the
signInActivityproperty from the users endpoint.PRs have been submitted to AzureHound and BloodHound to collect and display
LastSuccessfulSignInDateTimeif the user running AzureHound has this permission, otherwise resubmit the request without selecting this property.AzureHound: SpecterOps/AzureHound#163
BloodHound: SpecterOps/BloodHound#2307
Summary by CodeRabbit
✏️ Tip: You can customize this high-level summary in your review settings.