<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Azuresentinel on Anything About IT</title><link>https://www.verboon.info/tags/azuresentinel/</link><description>Recent content in Azuresentinel on Anything About IT</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Sat, 10 Oct 2020 14:14:12 +0000</lastBuildDate><atom:link href="https://www.verboon.info/tags/azuresentinel/index.xml" rel="self" type="application/rss+xml"/><item><title>Monitoring Service principal sign-ins with AzureAD and Azure Sentinel</title><link>https://www.verboon.info/2020/10/monitoring-service-principal-sign-ins-with-azuread-and-azure-sentinel/</link><pubDate>Sat, 10 Oct 2020 14:14:12 +0000</pubDate><guid>https://www.verboon.info/2020/10/monitoring-service-principal-sign-ins-with-azuread-and-azure-sentinel/</guid><description>&lt;p&gt;Here is a conversation between Jeffrey (Developer) and Marc (IT Admin) working for ECorp Ltd.&lt;/p&gt;
&lt;p&gt;
 &lt;img src="images/101020_1404_MonitoringS1.png" alt=""&gt;

&lt;/p&gt;
&lt;p&gt;Looks familiar? Take a look in your Azure Active directory, how many applications do you have there? In an ideal world you maintain an inventory of all these applications somewhere in your asset management database so that you know who is the owner of the Application and what it is used for and what API permissions are granted. As for the client secret, this should be stored in a Vault.&lt;/p&gt;</description></item></channel></rss>