Collect Microsoft Entra ID Organizational Context data (formerly Azure Active Directory) logs
Parser Version: 12.0
This document explains how to collect Microsoft Entra ID (formerly Azure Active Directory) organizational context data by setting up a Google Security Operations feed using the Third Party API.
Microsoft Entra ID Organizational Context provides directory information such as users, groups, and devices from your Microsoft Entra ID tenant. This is not event or log data - it is a periodic snapshot of directory state that enriches other log types in Google SecOps with identity context.
Before you begin
Make sure you have the following prerequisites:
- A Google SecOps instance
- Privileged access to the Microsoft Azure portal
- One of the following roles for granting administrator consent:
- Global Administrator - can grant consent for any permission, for any API
- Privileged Role Administrator - can grant consent for any permission, for any API
Configure IP allowlisting
You should add the Google SecOps IP ranges in your Microsoft Azure network settings or Conditional Access policies before creating your feed. This matters where the data source enforces IP-based restrictions. If the feed returns a 403 error, verify that allowlisting is enabled there. To restrict access by a narrower range, open a support ticket.
For more information, see IP Allowlisting.
Get Google SecOps IP ranges
- Go to SIEM Settings > Feeds.
- Click Add New Feed.
- Note the IP ranges displayed in the feed creation interface.
- Alternatively, retrieve IP ranges programmatically using the Feed Management API.
Configure conditional access for workload identities (if required)
If your organization uses conditional access policies that restrict access by location do the following:
- In the Microsoft Entra admin center, go to Protection > Conditional Access > Named locations.
- Click + New location.
- Provide the following configuration details:
- Name: Enter
Google SecOps IP Ranges. - Mark as trusted location: Optional, based on your security policy.
- IP ranges: Add each Google SecOps IP range in CIDR notation.
- Name: Enter
- Click Create.
- Go to Conditional Access > Policies.
- For any policies that apply to workload identities, configure an exclusion for the
Google SecOps IP Rangesnamed location or the specific service principal.
Configure Microsoft Entra app registration
Create app registration
- Sign in to the Microsoft Entra admin center or Azure portal.
- Go to Identity > Applications > App registrations.
- Click New registration.
- Provide the following configuration details:
- Name: Enter a descriptive name (for example,
Google SecOps Entra ID Context Integration). - Supported account types: Select Accounts in this organizational directory only (Single tenant).
- Redirect URI: Leave blank (not required for service principal authentication).
- Name: Enter a descriptive name (for example,
- Click Register.
- After registration, copy and save the following values:
- Application (client) ID
- Directory (tenant) ID
Configure API permissions
The feed reads the user directory through the Microsoft Graph List users endpoint, with each user's manager expanded. Grant the application permissions that match the feed options you enable.
- In the app registration, go to API permissions.
- Click Add a permission.
- Select Microsoft Graph > Application permissions.
- Search for and select the following permissions:
- User.Read.All - Required. Reads the user profiles and the manager relationship that the feed ingests.
- Group.Read.All - Only if you set Retrieve groups to True in the feed. Reads the groups returned for each user's membership.
- Device.Read.All - Only if you set Retrieve devices to True in the feed. Reads the devices associated with each user.
- Click Add permissions.
- Click Grant admin consent for Your Organization.
Verify that the Status column shows Granted for Your Organization for all permissions.
Permission Type When required User.Read.All Application Always Group.Read.All Application Retrieve groups is True Device.Read.All Application Retrieve devices is True
Create a client secret
- In the app registration, go to Certificates & secrets.
- Click New client secret.
Provide the following configuration details:
- Description: Enter a descriptive name (for example,
Google SecOps Feed). - Expires: Select an expiration period.
- Description: Enter a descriptive name (for example,
Click Add.
Copy the client secret Value immediately.
Configure a feed in Google SecOps to ingest Microsoft Entra ID organizational context data
To configure the feed, do the following:
- Go to SIEM Settings > Feeds.
- Click Add New Feed.
- On the next page, click Configure a single feed.
- In the Feed name field, enter a name for the feed (for example,
Azure AD Organizational Context). - Select Third party API as the Source type.
- Select Azure AD Organizational Context as the Log type.
- Click Next.
Specify values for the following input parameters as follows:
- OAuth Client ID: Enter the Application (client) ID from the app registration.
- OAuth Client Secret: Enter the client secret value you copied earlier.
- Tenant ID: Enter the Directory (tenant) ID from the app registration in UUID format (for example,
0fc279f9-fe30-41be-97d3-abe1d7681418). - Retrieve devices: Select whether to retrieve device information within user context. Set to True to include device data.
- Retrieve groups: Select whether to retrieve group membership information within user context. Set to True to include group data.
API Full Path: Microsoft Graph REST API endpoint URL:
graph.microsoft.com/beta
API Authentication Endpoint: Microsoft Entra ID Authentication Endpoint:
login.microsoftonline.com
Advanced Options:
- Asset namespace: The asset namespace.
- Ingestion labels: The label to be applied to the events from this feed.
Click Next.
Review your new feed configuration in the Finalize screen, and then click Submit.
Regional endpoints
For Microsoft Entra ID deployments in sovereign clouds, use the appropriate regional endpoints:
| Cloud Environment | API Full Path | API Authentication Endpoint |
|---|---|---|
| Global | graph.microsoft.com/beta |
login.microsoftonline.com |
| US Government L4 | graph.microsoft.us/beta |
login.microsoftonline.us |
| US Government L5 (DOD) | dod-graph.microsoft.us/beta |
login.microsoftonline.us |
| China (21Vianet) | microsoftgraph.chinacloudapi.cn/beta |
login.chinacloudapi.cn |
UDM mapping table
| Log Field | UDM Mapping | Logic |
|---|---|---|
extension_wfc_AccountType |
entity.labels.value |
Directly mapped |
extension_wfc_AccountingUnitName |
entity.labels.value |
Directly mapped |
extension_wfc_execDescription |
entity.labels.value |
Directly mapped |
extension_wfc_groupDescription |
entity.labels.value |
Directly mapped |
extension_wfc_orgDescription |
entity.labels.value |
Directly mapped |
createdDateTime |
entity.user.attribute.creation_time |
Parsed as RFC3339 |
sign_in_type |
entity.user.attribute.labels.key |
Directly mapped |
assignedLicense.skuId |
entity.user.attribute.labels.value |
Directly mapped |
employeeType |
entity.user.attribute.labels.value |
Directly mapped |
empmanager-src.usageLocation |
entity.user.attribute.labels.value |
Directly mapped |
externalUserState |
entity.user.attribute.labels.value |
Directly mapped |
gopher-manager.onPremisesImmutableId |
entity.user.attribute.labels.value |
Directly mapped |
mailNickname |
entity.user.attribute.labels.value |
Directly mapped |
onPremisesDistinguishedName |
entity.user.attribute.labels.value |
Directly mapped |
onPremisesDomainName |
entity.user.attribute.labels.value |
Directly mapped |
onPremisesExtensionAttributes.extensionAttribute4 |
entity.user.attribute.labels.value |
Directly mapped |
onPremisesImmutableId |
entity.user.attribute.labels.value |
Directly mapped |
onPremisesSamAccountName |
entity.user.attribute.labels.value |
Directly mapped |
refreshTokensValidFromDateTime |
entity.user.attribute.labels.value |
Directly mapped |
token_date_time |
entity.user.attribute.labels.value |
Directly mapped |
userPrincipalName |
entity.user.attribute.labels.value |
Directly mapped |
user_ou_data |
entity.user.attribute.labels.value |
Directly mapped |
userType |
entity.user.attribute.roles.name |
Directly mapped |
user_ou_data |
entity.user.attribute.roles.type |
Mapped: Admin → ADMINISTRATOR, Service Accounts → SERVICE_ACCOUNT |
department |
entity.user.department |
Merged |
mail |
entity.user.email_addresses |
Merged |
proxyAddress |
entity.user.email_addresses |
Mapped: smtp/SMTP → proxyAddress |
userPrincipalName |
entity.user.email_addresses |
Merged |
employeeId |
entity.user.employee_id |
Renamed/mapped |
extension_employeeNumber |
entity.user.employee_id |
Renamed/mapped |
onPremisesDomainName |
entity.user.group_identifiers |
Merged |
proxyAddress |
entity.user.group_identifiers |
Merged |
sign_in_type_manager |
entity.user.managers.attribute.labels.key |
Directly mapped |
temp |
entity.user.managers.attribute.labels.key |
Mapped: true → manager accountEnabled |
empmanager-src.sbuxCompanyCode |
entity.user.managers.attribute.labels.value |
Directly mapped |
empmanager-src.sbuxCostCenter |
entity.user.managers.attribute.labels.value |
Directly mapped |
empmanager-src.sbuxDirectorySync |
entity.user.managers.attribute.labels.value |
Directly mapped |
empmanager-src.sbuxEmployeeStatus |
entity.user.managers.attribute.labels.value |
Directly mapped |
empmanager-src.sbuxEmployeeType |
entity.user.managers.attribute.labels.value |
Directly mapped |
empmanager-src.sbuxFullName |
entity.user.managers.attribute.labels.value |
Directly mapped |
empmanager-src.sbuxFullNameAKA |
entity.user.managers.attribute.labels.value |
Directly mapped |
empmanager-src.sbuxFullNameAKAAlt |
entity.user.managers.attribute.labels.value |
Directly mapped |
empmanager-src.sbuxFullNameAlt |
entity.user.managers.attribute.labels.value |
Directly mapped |
empmanager-src.sbuxGivenNameAlt |
entity.user.managers.attribute.labels.value |
Directly mapped |
empmanager-src.sbuxGlobalID |
entity.user.managers.attribute.labels.value |
Directly mapped |
empmanager-src.sbuxJobNumber |
entity.user.managers.attribute.labels.value |
Directly mapped |
empmanager-src.sbuxKnownAs |
entity.user.managers.attribute.labels.value |
Directly mapped |
empmanager-src.sbuxKnownAsAlt |
entity.user.managers.attribute.labels.value |
Directly mapped |
empmanager-src.sbuxLocalMarket |
entity.user.managers.attribute.labels.value |
Directly mapped |
empmanager-src.sbuxLocalMarketEmployeeID |
entity.user.managers.attribute.labels.value |
Directly mapped |
empmanager-src.sbuxManagerImmutableID |
entity.user.managers.attribute.labels.value |
Directly mapped |
empmanager-src.sbuxManagerNumber |
entity.user.managers.attribute.labels.value |
Directly mapped |
empmanager-src.sbuxOnTLA |
entity.user.managers.attribute.labels.value |
Directly mapped |
empmanager-src.sbuxOrgAreaID |
entity.user.managers.attribute.labels.value |
Directly mapped |
empmanager-src.sbuxOrgDistrictID |
entity.user.managers.attribute.labels.value |
Directly mapped |
empmanager-src.sbuxOrgDivisionID |
entity.user.managers.attribute.labels.value |
Directly mapped |
empmanager-src.sbuxOrgRegionID |
entity.user.managers.attribute.labels.value |
Directly mapped |
empmanager-src.sbuxOrgShortName |
entity.user.managers.attribute.labels.value |
Directly mapped |
empmanager-src.sbuxOrgStoreID |
entity.user.managers.attribute.labels.value |
Directly mapped |
empmanager-src.sbuxOrgType |
entity.user.managers.attribute.labels.value |
Directly mapped |
empmanager-src.sbuxOrgUnit |
entity.user.managers.attribute.labels.value |
Directly mapped |
empmanager-src.sbuxSnAlt |
entity.user.managers.attribute.labels.value |
Directly mapped |
empmanager-src.sbuxSourceSystem |
entity.user.managers.attribute.labels.value |
Directly mapped |
empmanager-src.userPrincipalName |
entity.user.managers.attribute.labels.value |
Directly mapped |
manager_ou_data |
entity.user.managers.attribute.labels.value |
Directly mapped |
temp |
entity.user.managers.attribute.labels.value |
Directly mapped |
manager_user_type |
entity.user.managers.attribute.roles.name |
Directly mapped |
manager_ou_data |
entity.user.managers.attribute.roles.type |
Mapped: Users → ADMINISTRATOR, Service Accounts → SERVICE_ACCOUNT |
empmanager-src.companyName |
entity.user.managers.company_name |
Renamed/mapped |
empmanager-src.department |
entity.user.managers.department |
Merged |
empProxyAddress |
entity.user.managers.email_addresses |
Mapped: smtp/SMTP → empProxyAddress |
empmanager-src.mail |
entity.user.managers.email_addresses |
Merged |
principal_name |
entity.user.managers.email_addresses |
Merged |
empmanager-src.employeeId |
entity.user.managers.employee_id |
Renamed/mapped |
empmanager-src.extension_employeeNumber |
entity.user.managers.employee_id |
Renamed/mapped |
empmanager-src.givenName |
entity.user.managers.first_name |
Renamed/mapped |
empProxyAddress |
entity.user.managers.group_identifiers |
Merged |
empmanager-src.surname |
entity.user.managers.last_name |
Renamed/mapped |
empmanager-src.city |
entity.user.managers.personal_address.city |
Renamed/mapped |
country_n_code |
entity.user.managers.personal_address.country_or_region |
Directly mapped |
empmanager-src.streetAddress |
entity.user.managers.personal_address.name |
Renamed/mapped |
empmanager-src.state |
entity.user.managers.personal_address.state |
Renamed/mapped |
empmanager-src.businessPhones.0 |
entity.user.managers.phone_numbers |
Merged |
empmanager-src.id |
entity.user.managers.product_object_id |
Renamed/mapped |
empmanager-src.jobTitle |
entity.user.managers.title |
Renamed/mapped |
empmanager-src.displayName |
entity.user.managers.user_display_name |
Renamed/mapped |
empmanager-src.sAMAccountName |
entity.user.managers.userid |
Renamed/mapped |
empmanager-src.onPremisesSecurityIdentifier |
entity.user.managers.windows_sid |
Renamed/mapped |
country |
entity.user.personal_address.country_or_region |
Directly mapped |
usageLocation |
entity.user.personal_address.country_or_region |
Directly mapped |
phoneNumber |
entity.user.phone_numbers |
Merged |
onPremisesSamAccountName |
entity.user.userid |
Renamed/mapped |
sAMAccountName |
entity.user.userid |
Renamed/mapped |
gopher-device-item.createdDateTime |
metadata.event_timestamp |
Parsed as RFC3339 |
| N/A | entity.labels.key |
Constant: wfc_AccountType |
| N/A | entity.user.attribute.labels.key |
Constant: gopher-manager onPremisesImmutableId |
| N/A | entity.user.attribute.roles.type |
Constant: SERVICE_ACCOUNT |
| N/A | entity.user.managers.attribute.labels.key |
Constant: manager accountEnabled |
| N/A | entity.user.managers.attribute.roles.type |
Constant: SERVICE_ACCOUNT |
| N/A | entity.user.user_authentication_status |
Constant: ACTIVE |
| N/A | metadata.entity_type |
Constant: USER |
| N/A | metadata.event_metadata.log_type |
Constant: AZURE_AD_CONTEXT |
| N/A | metadata.product_name |
Constant: Azure Active Directory |
| N/A | metadata.vendor_name |
Constant: Microsoft |
Change Log
View the Change Log for this parser
Need more help? Get answers from Community members and Google SecOps professionals.