Skip to content

Docs: Update with new API permission requirement supporting BED-7248: Entra ID User Last Logon Timestamp AZUser Node Property #170

Merged
jeff-matthews merged 2 commits intoSpecterOps:release/v8.6.0from
Mayyhem:main
Jan 30, 2026
Merged

Docs: Update with new API permission requirement supporting BED-7248: Entra ID User Last Logon Timestamp AZUser Node Property #170
jeff-matthews merged 2 commits intoSpecterOps:release/v8.6.0from
Mayyhem:main

Conversation

@Mayyhem
Copy link
Contributor

@Mayyhem Mayyhem commented Jan 28, 2026

The AuditLog.Read.All permission is required to collect the signInActivity property from the users endpoint.

PRs have been submitted to AzureHound and BloodHound to collect and display LastSuccessfulSignInDateTime if the user running AzureHound has this permission, otherwise resubmit the request without selecting this property.

AzureHound: SpecterOps/AzureHound#163
BloodHound: SpecterOps/BloodHound#2307

Summary by CodeRabbit

  • Documentation
    • Updated Azure configuration installation guide to include an optional AuditLog.Read.All permission step for collecting additional user activity data, with corresponding UI updates and adjusted step numbering throughout the section.

✏️ Tip: You can customize this high-level summary in your review settings.

@coderabbitai
Copy link
Contributor

coderabbitai bot commented Jan 28, 2026

Walkthrough

This PR updates the Azure configuration documentation by introducing an optional step to enable the AuditLog.Read.All permission, which allows collection of AZUser.LastSuccessfulSignInDateTime data. Subsequent steps are renumbered to reflect this addition.

Changes

Cohort / File(s) Summary
Azure Configuration Documentation
docs/install-data-collector/install-azurehound/azure-configuration.mdx
Added optional step for enabling AuditLog.Read.All permission with UI snippet; renumbered subsequent steps in the "Grant Microsoft Graph Permissions" section

Estimated code review effort

🎯 2 (Simple) | ⏱️ ~8 minutes

Possibly related PRs

Suggested labels

documentation

Suggested reviewers

  • StephenHinck

Poem

🐰 A hop, a skip, through docs so bright,
New permissions dance into the light,
AuditLog reads what we seek to find,
Each numbered step perfectly aligned! ✨

🚥 Pre-merge checks | ✅ 3
✅ Passed checks (3 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly summarizes the main change: updating documentation to reflect a new API permission requirement (AuditLog.Read.All) needed for collecting user last logon timestamps in AZUser nodes.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

Copy link
Contributor

@zinic zinic left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

lgtm

@jeff-matthews jeff-matthews self-assigned this Jan 29, 2026
@jeff-matthews jeff-matthews added documentation Improvements or additions to documentation v8.6.0 labels Jan 29, 2026
@jeff-matthews
Copy link
Contributor

Thanks for the PR @Mayyhem! This is a good reminder for me to create a release branch for 8.6.0. I'll do that and merge this PR into it along with all other release-related doc PRs.

@jeff-matthews jeff-matthews changed the base branch from main to release/v8.6.0 January 30, 2026 22:54
@jeff-matthews jeff-matthews merged commit a817de6 into SpecterOps:release/v8.6.0 Jan 30, 2026
2 checks passed
@github-actions github-actions bot locked and limited conversation to collaborators Jan 30, 2026
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

documentation Improvements or additions to documentation v8.6.0

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants