How can I investigate an unknown app appearing in my Entra sign-in logs?

Tilman Schmidt 60 Reputation points
2024-12-03T09:54:01.3466667+00:00

While investigating suspicious sign-in events with Microsoft Sentinel in the SignInLogs table I came across a couple of successful sign-ins with AppDisplayName "Social27local" and AppId ba3cfa03-0eea-43d2-a2e7-e72d19d22f7e, all to the same username.

The user is not aware of an application by that name.

An Internet search for the name turned up zero results.

How can I find out more about that app, where it comes from, why it is allowed to access my tenant, whether it is malicious and the risks it might pose?

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,248 questions
Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
23,838 questions
0 comments No comments
{count} votes

2 answers

Sort by: Most helpful
  1. Marti Peig 965 Reputation points Microsoft Employee
    2024-12-03T11:18:58.89+00:00

    Hi Tilman,

    You should be able to see who created that app by checking in the Entra ID Audit logs (https://portal.azure.com/#view/Microsoft_AAD_IAM/ActiveDirectoryMenuBlade/~/Audit), filtering by Activity: Add Application.

    Ref. https://learn.microsoft.com/en-us/entra/identity/monitoring-health/concept-audit-logs

    Cheers


  2. Andy David - MVP 153.9K Reputation points MVP
    2024-12-03T11:53:15.21+00:00

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.