Entra App Instance Property Lock Tampering Service Principal Lock Configuration
Query
//https://learn.microsoft.com/en-us/entra/identity-platform/howto-configure-app-instance-property-locks
AuditLogs
| where Category == "ApplicationManagement"
| mv-expand TargetResource = TargetResources
| mv-expand Property = TargetResource.modifiedProperties
| where tostring(Property.displayName) == "ServicePrincipalLockConfiguration" //| where TargetResources[0].modifiedProperties[0].displayName == "ServicePrincipalLockConfiguration"
| extend Old = parse_json(tostring(Property.oldValue))
| extend New = parse_json(tostring(Property.newValue))
| extend
Old_IsEnabled = tobool(Old[0].IsEnabled),
New_IsEnabled = tobool(New[0].IsEnabled),
Old_AllProperties = tobool(Old[0].AllProperties),
New_AllProperties = tobool(New[0].AllProperties),
Old_CredentialsWithUsageVerify = tobool(Old[0].CredentialsWithUsageVerify),
New_CredentialsWithUsageVerify = tobool(New[0].CredentialsWithUsageVerify),
Old_CredentialsWithUsageSign = tobool(Old[0].CredentialsWithUsageSign),
New_CredentialsWithUsageSign = tobool(New[0].CredentialsWithUsageSign),
Old_IdentifierUris = tobool(Old[0].IdentifierUris),
New_IdentifierUris = tobool(New[0].IdentifierUris),
Old_TokenEncryptionKeyId = tobool(Old[0].TokenEncryptionKeyId),
New_TokenEncryptionKeyId = tobool(New[0].TokenEncryptionKeyId)
| where
(Old_IsEnabled == true and New_IsEnabled == false) or
(Old_AllProperties == true and New_AllProperties == false) or
(Old_CredentialsWithUsageVerify == true and New_CredentialsWithUsageVerify == false) or
(Old_CredentialsWithUsageSign == true and New_CredentialsWithUsageSign == false) or
(Old_IdentifierUris == true and New_IdentifierUris == false) or
(Old_TokenEncryptionKeyId == true and New_TokenEncryptionKeyId == false)
| project TimeGenerated,OperationName,AppName = tostring(TargetResource.displayName),InitiatedBy,Old,NewExplanation
This KQL (Kusto Query Language) query is designed to analyze audit logs related to application management, specifically focusing on changes in the "ServicePrincipalLockConfiguration" property of application instances. Here's a simplified breakdown of what the query does:
-
Source Data: It starts by examining the
AuditLogstable, filtering for logs categorized under "ApplicationManagement". -
Data Expansion: It expands the
TargetResourcesand theirmodifiedPropertiesto access individual changes made to application properties. -
Property Filtering: The query specifically looks for changes where the property name is "ServicePrincipalLockConfiguration".
-
Old vs. New Values: It extracts and parses the old and new values of this property to compare them.
-
Boolean Conversion: Several specific attributes within the property are converted to boolean values for both old and new states. These attributes include:
IsEnabledAllPropertiesCredentialsWithUsageVerifyCredentialsWithUsageSignIdentifierUrisTokenEncryptionKeyId
-
Change Detection: The query identifies instances where any of these attributes have changed from
true(enabled) tofalse(disabled). -
Result Projection: Finally, it projects a set of columns for the output, including:
TimeGenerated: The time the log was generated.OperationName: The name of the operation performed.AppName: The name of the application (derived fromTargetResource.displayName).InitiatedBy: Who initiated the change.Old: The old configuration values.New: The new configuration values.
In summary, this query is used to track and report on specific security-related configuration changes in application instances, particularly focusing on settings that have been disabled.