How to get User SID and UPN from Defender Alert's Device Evidence

Ernar Zhanadil 20 Reputation points
2025-02-19T20:30:08.8566667+00:00

I need to get User SID and UserPrincipalName from Alert's Device Evidence. Device Evidence contains loggedOnUsers that consists of accountName and domainName based on info here: https://learn.microsoft.com/en-us/graph/api/resources/security-loggedonuser?view=graph-rest-1.0.

How can I enrich loggedOnUsers information with User SID and UserPrincipalName using Graph Security hunting query?

Microsoft Graph
Microsoft Graph
A Microsoft programmability model that exposes REST APIs and client libraries to access data on Microsoft 365 services.
13,264 questions
0 comments No comments
{count} votes

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.