Microsoft Azure Sentinel
Overview
Microsoft Sentinel (formerly Azure Sentinel) is a cloud-native SIEM and SOAR solution built on Azure Log Analytics. KYRA MDR ingests Sentinel incidents, alerts, and analytics rule matches via the Azure REST API and Microsoft Graph Security API for unified cross-platform visibility.
Prerequisites
- KYRA MDR account (MDR tier or above)
- KYRA Collector installed with outbound HTTPS access to Azure
- Azure subscription with Microsoft Sentinel enabled on a Log Analytics workspace
- Azure AD app registration with Microsoft Sentinel Reader role
- Application (client) ID, tenant ID, and client secret
Configuration
Step 1: Register an Azure AD Application
- Navigate to Azure Portal > App Registrations > New Registration
- Name:
KYRA-MDR-Sentinel, Supported account types: Single tenant - After creation, go to Certificates & secrets > New client secret
- Record the Application (client) ID, Directory (tenant) ID, and Client secret value
Grant API permissions:
- Go to API permissions > Add a permission > Microsoft Graph
- Add:
SecurityEvents.Read.All,SecurityIncident.Read.All - Click Grant admin consent
Step 2: Assign Sentinel Reader Role
# Get workspace resource IDWORKSPACE_ID=$(az monitor log-analytics workspace show \ --resource-group <RG_NAME> \ --workspace-name <WORKSPACE_NAME> \ --query id -o tsv)
# Assign roleaz role assignment create \ --assignee <APP_ID> \ --role "Microsoft Sentinel Reader" \ --scope "$WORKSPACE_ID"Step 3: Enable Diagnostic Settings
az monitor diagnostic-settings create \ --name "kyra-mdr-export" \ --resource "$WORKSPACE_ID" \ --event-hub "kyra-sentinel-events" \ --event-hub-rule "/subscriptions/<SUB>/resourceGroups/<RG>/providers/Microsoft.EventHub/namespaces/<NS>/authorizationRules/RootManageSharedAccessKey" \ --logs '[{"category":"SentinelAudit","enabled":true},{"category":"SentinelHealth","enabled":true}]'Step 4: Configure KYRA Collector
source: type: azure-sentinel tenant_id: "<TENANT_ID>" client_id: "<APP_ID>" client_secret: "<CLIENT_SECRET>" subscription_id: "<SUBSCRIPTION_ID>" resource_group: "<RG_NAME>" workspace_name: "<WORKSPACE_NAME>" poll_interval: 60 # seconds collect: - incidents - alerts - hunting_querieskyra-collector reloadkyra-collector statusStep 5: Verify API Connectivity
# Get access tokenTOKEN=$(az account get-access-token \ --resource https://management.azure.com \ --query accessToken -o tsv)
# List recent incidentscurl -s -H "Authorization: Bearer $TOKEN" \ "https://management.azure.com/subscriptions/<SUB>/resourceGroups/<RG>/providers/Microsoft.OperationalInsights/workspaces/<WS>/providers/Microsoft.SecurityInsights/incidents?api-version=2024-03-01" \ | jq '.value[:3] | .[].properties | {title, severity, status}'Step 6: KQL Queries via Log Analytics
az monitor log-analytics query \ --workspace "$WORKSPACE_ID" \ --analytics-query "SecurityAlert | where TimeGenerated > ago(1h) | project TimeGenerated, AlertName, AlertSeverity | take 20" \ --output tableExample KQL queries used by KYRA MDR:
// Brute force detectionSigninLogs| where ResultType != "0"| summarize FailureCount=count() by UserPrincipalName, IPAddress, bin(TimeGenerated, 5m)| where FailureCount > 10
// Incident summary by severitySecurityIncident| where TimeGenerated > ago(24h)| summarize count() by Severity, StatusStep 7: Data Connectors to Enable
| Connector | Data Tables |
|---|---|
| Azure Active Directory | SigninLogs, AuditLogs |
| Microsoft 365 Defender | AlertEvidence, DeviceEvents |
| Azure Activity | AzureActivity |
| Azure Key Vault | AzureDiagnostics |
| Microsoft Defender for Cloud | SecurityAlert |
Collected Log Types
| Log Type | Description | Security Use |
|---|---|---|
| Incidents | Correlated security incidents with severity, status, owner | Case management, SOC triage |
| Alerts | Individual detection rule matches | Threat detection |
| Hunting Results | Custom KQL hunting query results | Proactive threat hunting |
| Sentinel Audit | Configuration changes to rules and connectors | Change tracking |
| Sentinel Health | Data connector health and ingestion status | Monitoring reliability |
| Watchlists | Watchlist match events | Custom indicator matching |
Troubleshooting
- 401 Unauthorized: Client secret may have expired. Regenerate via Azure Portal or
az ad app credential reset --id <APP_ID>. - 403 Forbidden: Verify the service principal has Microsoft Sentinel Reader role. Check with
az role assignment list --assignee <APP_ID>. - No incidents returned: Verify Sentinel has active analytics rules at Azure Portal > Sentinel > Analytics.
- Stale data: Default poll interval is 60s. For near real-time, reduce to 30s but monitor API rate limits (200 requests/5 min per tenant).
- KQL query timeout: Add
TimeGenerated > ago(1h)filters to scope large table queries.
Contact kyra@seekerslab.com for integration support.