Enabling KQL Query for the risky users without Entra ID Premium P2?

EnterpriseArchitect 5,406 Reputation points
2024-08-13T12:22:31.49+00:00

Does the Entra ID Premium P2 required to be able to query the risky users with KQL (Kusto) and then send the email alert to the relevant team?

Thank you in advance for any help and suggestions.

Microsoft Graph
Microsoft Graph
A Microsoft programmability model that exposes REST APIs and client libraries to access data on Microsoft 365 services.
12,238 questions
Microsoft Intune Security
Microsoft Intune Security
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Security: The precautions taken to guard against crime, attack, sabotage, espionage, or another threat.
430 questions
Microsoft Entra External ID
Microsoft Entra External ID
A modern identity solution for securing access to customer, citizen and partner-facing apps and services. It is the converged platform of Azure AD External Identities B2B and B2C. Replaces Azure Active Directory External Identities.
2,908 questions
Microsoft Entra
Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
22,062 questions
0 comments No comments
{count} votes

Accepted answer
  1. Marcin Policht 25,675 Reputation points MVP
    2024-08-13T17:24:39.9733333+00:00

    That's correct. Entra ID Premium P2 is required to query risky users and utilize advanced security features, including Identity Protection, which identifies and reports risky users. This premium tier provides the capabilities necessary to detect and respond to identity-based threats within your organization.

    With Entra ID Premium P2, you can access advanced features like:

    1. Risky Users Detection: Identifying and flagging users with suspicious activities or compromised credentials.
    2. Kusto Query Language (KQL): Running custom queries against the identity protection logs to retrieve detailed information about risky users.
    3. Automated Responses: Setting up alerts and automated workflows, such as sending email alerts to the relevant team when risky user activity is detected.

    Details at https://www.microsoft.com/en-us/security/business/microsoft-entra-pricing


    If the above response helps answer your question, remember to "Accept Answer" so that others in the community facing similar issues can easily find the solution. Your contribution is highly appreciated.

    hth

    Marcin


0 additional answers

Sort by: Most helpful

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.