Query Details

Entra App Instance Property Lock Tampering Service Principal Lock Configuration

Query

//https://learn.microsoft.com/en-us/entra/identity-platform/howto-configure-app-instance-property-locks
AuditLogs
| where Category == "ApplicationManagement"
| mv-expand TargetResource = TargetResources
| mv-expand Property = TargetResource.modifiedProperties
| where tostring(Property.displayName) == "ServicePrincipalLockConfiguration" //| where TargetResources[0].modifiedProperties[0].displayName == "ServicePrincipalLockConfiguration"
| extend Old = parse_json(tostring(Property.oldValue))
| extend New = parse_json(tostring(Property.newValue))
| extend
Old_IsEnabled = tobool(Old[0].IsEnabled),
New_IsEnabled = tobool(New[0].IsEnabled),
Old_AllProperties = tobool(Old[0].AllProperties),
New_AllProperties = tobool(New[0].AllProperties),
Old_CredentialsWithUsageVerify = tobool(Old[0].CredentialsWithUsageVerify),
New_CredentialsWithUsageVerify = tobool(New[0].CredentialsWithUsageVerify),
Old_CredentialsWithUsageSign = tobool(Old[0].CredentialsWithUsageSign),
New_CredentialsWithUsageSign = tobool(New[0].CredentialsWithUsageSign),
Old_IdentifierUris = tobool(Old[0].IdentifierUris),
New_IdentifierUris = tobool(New[0].IdentifierUris),
Old_TokenEncryptionKeyId = tobool(Old[0].TokenEncryptionKeyId),
New_TokenEncryptionKeyId = tobool(New[0].TokenEncryptionKeyId)
| where
(Old_IsEnabled == true and New_IsEnabled == false) or
(Old_AllProperties == true and New_AllProperties == false) or
(Old_CredentialsWithUsageVerify == true and New_CredentialsWithUsageVerify == false) or
(Old_CredentialsWithUsageSign == true and New_CredentialsWithUsageSign == false) or
(Old_IdentifierUris == true and New_IdentifierUris == false) or
(Old_TokenEncryptionKeyId == true and New_TokenEncryptionKeyId == false)
| project TimeGenerated,OperationName,AppName = tostring(TargetResource.displayName),InitiatedBy,Old,New

Explanation

This KQL (Kusto Query Language) query is designed to analyze audit logs related to application management, specifically focusing on changes in the "ServicePrincipalLockConfiguration" property of application instances. Here's a simplified breakdown of what the query does:

  1. Source Data: It starts by examining the AuditLogs table, filtering for logs categorized under "ApplicationManagement".

  2. Data Expansion: It expands the TargetResources and their modifiedProperties to access individual changes made to application properties.

  3. Property Filtering: The query specifically looks for changes where the property name is "ServicePrincipalLockConfiguration".

  4. Old vs. New Values: It extracts and parses the old and new values of this property to compare them.

  5. Boolean Conversion: Several specific attributes within the property are converted to boolean values for both old and new states. These attributes include:

    • IsEnabled
    • AllProperties
    • CredentialsWithUsageVerify
    • CredentialsWithUsageSign
    • IdentifierUris
    • TokenEncryptionKeyId
  6. Change Detection: The query identifies instances where any of these attributes have changed from true (enabled) to false (disabled).

  7. Result Projection: Finally, it projects a set of columns for the output, including:

    • TimeGenerated: The time the log was generated.
    • OperationName: The name of the operation performed.
    • AppName: The name of the application (derived from TargetResource.displayName).
    • InitiatedBy: Who initiated the change.
    • Old: The old configuration values.
    • New: The new configuration values.

In summary, this query is used to track and report on specific security-related configuration changes in application instances, particularly focusing on settings that have been disabled.