<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Microsoft Azure Active Directory Add-on for Splunk - Azure AD Group Data in All Apps and Add-ons</title>
    <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Microsoft-Azure-Active-Directory-Add-on-for-Splunk-Azure-AD/m-p/420042#M51215</link>
    <description>&lt;P&gt;Hi, do you have any further details of the python script you mention? As far as I can see it doesn't already exist within the Azure AD TA.&lt;/P&gt;

&lt;P&gt;Has anyone else done this?&lt;/P&gt;

&lt;P&gt;Thanks in advance.&lt;/P&gt;</description>
    <pubDate>Mon, 16 Sep 2019 10:58:26 GMT</pubDate>
    <dc:creator>Dworsnop</dc:creator>
    <dc:date>2019-09-16T10:58:26Z</dc:date>
    <item>
      <title>Microsoft Azure Active Directory Add-on for Splunk - Azure AD Group Data</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Microsoft-Azure-Active-Directory-Add-on-for-Splunk-Azure-AD/m-p/420040#M51213</link>
      <description>&lt;P&gt;I've installed version Version 1.2.1 (June 10, 2019) of Microsoft Azure Active Directory Add-on for Splunk and can now obtain the Azure AD User data.&lt;/P&gt;

&lt;P&gt;Is it possible to make a modification to the TA to collect the group data from Azure AD via a rest api to collect from microsoft graph.&lt;/P&gt;</description>
      <pubDate>Wed, 12 Jun 2019 12:24:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Microsoft-Azure-Active-Directory-Add-on-for-Splunk-Azure-AD/m-p/420040#M51213</guid>
      <dc:creator>splunkmachine</dc:creator>
      <dc:date>2019-06-12T12:24:37Z</dc:date>
    </item>
    <item>
      <title>Re: Microsoft Azure Active Directory Add-on for Splunk - Azure AD Group Data</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Microsoft-Azure-Active-Directory-Add-on-for-Splunk-Azure-AD/m-p/420041#M51214</link>
      <description>&lt;P&gt;I believe it would require a new import module writing - input_module_MS_AAD_group.py&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;    url = "https://graph.microsoft.com/v1.0/groups?$expand=members"
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Wed, 30 Sep 2020 00:58:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Microsoft-Azure-Active-Directory-Add-on-for-Splunk-Azure-AD/m-p/420041#M51214</guid>
      <dc:creator>splunkmachine</dc:creator>
      <dc:date>2020-09-30T00:58:45Z</dc:date>
    </item>
    <item>
      <title>Re: Microsoft Azure Active Directory Add-on for Splunk - Azure AD Group Data</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Microsoft-Azure-Active-Directory-Add-on-for-Splunk-Azure-AD/m-p/420042#M51215</link>
      <description>&lt;P&gt;Hi, do you have any further details of the python script you mention? As far as I can see it doesn't already exist within the Azure AD TA.&lt;/P&gt;

&lt;P&gt;Has anyone else done this?&lt;/P&gt;

&lt;P&gt;Thanks in advance.&lt;/P&gt;</description>
      <pubDate>Mon, 16 Sep 2019 10:58:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Microsoft-Azure-Active-Directory-Add-on-for-Splunk-Azure-AD/m-p/420042#M51215</guid>
      <dc:creator>Dworsnop</dc:creator>
      <dc:date>2019-09-16T10:58:26Z</dc:date>
    </item>
    <item>
      <title>Re: Microsoft Azure Active Directory Add-on for Splunk - Azure AD Group Data</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Microsoft-Azure-Active-Directory-Add-on-for-Splunk-Azure-AD/m-p/545084#M65212</link>
      <description>&lt;P&gt;Has anything progressed on this subject, I'm very keen to get Microsoft Group Membership information into Splunk, either as an additional field in the azure:aad:user sourcetype or as a seperate input as azure:aad:group. This would be useful to prioritise and categorise users in Enterprise Security's Identity Framework&lt;/P&gt;</description>
      <pubDate>Wed, 24 Mar 2021 09:26:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Microsoft-Azure-Active-Directory-Add-on-for-Splunk-Azure-AD/m-p/545084#M65212</guid>
      <dc:creator>bmarrable</dc:creator>
      <dc:date>2021-03-24T09:26:49Z</dc:date>
    </item>
  </channel>
</rss>

