Skip to main content

Azure AD Connect Health Feed

This Integration is part of the Microsoft Azure AD Connect Health Feed Pack.#

Supported versions

Supported Cortex XSOAR versions: 5.5.0 and later.

Use the Microsoft Azure AD Connect Health Feed integration to get indicators from the feed. This integration was integrated and tested with version 1 of Azure AD Connect Health Feed

Configure Azure AD Connect Health Feed in Cortex#

ParameterDescriptionRequired
feedFetch indicatorsFalse
feedReputationIndicator ReputationFalse
feedReliabilitySource ReliabilityTrue
tlp_colorThe Traffic Light Protocol (TLP) designation to apply to indicators fetched from the feed. More information about the protocol can be found at https://us-cert.cisa.gov/tlpFalse
feedExpirationIntervalFalse
feedFetchIntervalFeed Fetch IntervalFalse
urlThe Microsoft Azure endpoint URLTrue
feedTagsTagsFalse
feedBypassExclusionListBypass exclusion listFalse
insecureTrust any certificate (not secure)False
proxyUse system proxy settingsFalse

Commands#

You can execute these commands from the CLI, as part of an automation, or in a playbook. After you successfully execute a command, a DBot message appears in the War Room with the command details.

azure-ad-health-get-indicators#


Gets indicators from the feed.

Base Command#

azure-ad-health-get-indicators

Input#

Argument NameDescriptionRequired
limitThe maximum number of results to return. The default value is 10.Optional

Context Output#

There is no context output for this command.

Command Example#

!azure-ad-health-get-indicators

Context Example#

{}

Human Readable Output#

Indicators from Microsoft Azure Feed:#

valuetype
https://login.microsoftonline.comURL
https://secure.aadcdn.microsoftonline-p.comURL
https://login.windows.netURL