Monitor Entra ID high-risk users with Microsoft Graph, TheHive and Slack
Quick Overview This workflow polls Microsoft Entra ID Protection for new high-risk risk detections, aggregates them per user, enriches them with risky-user and recent sign-in context from Microsoft Graph, then creates or updates matching alerts in TheHive and posts a summary to a Slack security channel.
How it works Runs every 30 minutes on a schedule. Queries Microsoft Graph Identity Protection for risk detections with risk level set to high from the last 20 minutes, following @odata.nextLink pagination. Groups detections by user and aggregates key context such as detection types, risk states, IP addresses, locations, and first/last detection timestamps. Retrieves additional user context from Microsoft Graph by fetching the risky user record and the user’s five most recent sign-in events. Correlates deterministic signals (for example privileged roles, multiple countries, confirmed compromise state, or non-compliant devices) to classify severity and build a detailed incident description. Queries TheHive for existing open alerts of type entra-id-risk and either updates the matching alert (by sourceRef) or creates a new alert with observables. Posts a formatted alert summary and TheHive reference to a chosen Slack channel.
Setup Create a Microsoft Entra ID (Microsoft Graph) OAuth2 credential with permissions for IdentityRiskEvent.Read.All, IdentityRiskyUser.Read.All, and AuditLog.Read.All. Add a TheHive 5 credential with permission to query, create, and update alerts, and ensure your TheHive instance is reachable from n8n. Add a Slack OAuth2 credential and select the security/SOC channel to post notifications to. Review and adjust the lookback filter (currently last 20 minutes) and schedule interval (every 30 minutes) to match your monitoring requirements.
Related Templates
Automated Work Attendance with Location Triggers
his workflow automates time tracking using location-based triggers. How it works Trigger: It starts when you enter or e...
Automated SEO Performance Collection from Google Search Console to NocoDB
Problem Monitoring SEO performance from Google Search Console (GSC) manually is repetitive and prone to human error. Fo...
Summarize SERPBear data with AI (via Openrouter) and save it to Baserow
Who's this for? If you own a website and need to analyze your keyword rankings If you need to create a keyword report on...
🔒 Please log in to import templates to n8n and favorite templates
Workflow Visualization
Loading...
Preparing workflow renderer
Comments (0)
Login to post comments