Default Playbooks
- XDR: Successful Login Outside the US Detections
- XDR: Conditional Access Blocked Login
- XDR: User Impossible Travel Anomaly
Base Workflow
Note: In environments configured with a hybrid of Entra and on-premises Active Directory, the SOC advises using the "Add user to group" step instead of the "Disable user account" step. This approach is advantageous for several reasons: Disabling a user account revokes all user licenses and can take approximately 30-40 minutes to restore access after rebuilding the account following an SOC-reported incident. Additionally, when Entra synchronizes with on-premises AD, discrepancies in user flags can sometimes automatically re-enable a disabled user, complicating the remediation process after an incident.
What is Needed
- Client ID
- From Azure App registration page
- Client Secret
- Directory ID (Tenant ID)