Skip to main content

Cloud Credentials Rotation - Azure

This Playbook is part of the Azure Enrichment and Remediation Pack.#

Supported versions

Supported Cortex XSOAR versions: 6.9.0 and later.

Azure Credentials Rotation Playbook#

IAM Remediation#

Protect your identity and access management:

  • Reset Password: Resets the user password to halt any unauthorized access.

  • Revoke Session: Terminates current active sessions to ensure the malicious actor is locked out.

  • Combo Action: Resets the password and terminates all active sessions.

Service Principal Remediation#

Guard your applications:

  • Password Regeneration: Generate a new password for the service principal, making sure the old one becomes obsolete.


This playbook uses the following sub-playbooks, integrations, and scripts.


This playbook does not use any sub-playbooks.


This playbook does not use any integrations.


  • GeneratePassword


  • msgraph-user-session-revoke
  • msgraph-apps-service-principal-get
  • msgraph-apps-service-principal-lock-configuration
  • msgraph-apps-service-principal-unlock-configuration
  • msgraph-apps-service-principal-password-add
  • msgraph-user-update

Playbook Inputs#

NameDescriptionDefault ValueRequired
IAMRemediationTypeThe response playbook provides the following remediation actions using MSGraph Users:

Reset: By entering "Reset" in the input, the playbook will execute password reset.

Revoke: By entering "Revoke" in the input, the playbook will revoke the user's session.

ALL: By entering "ALL" in the input, the playbook will execute the reset password and revoke session tasks.
appIDThis is the unique application (client) ID of the application.Optional
objectIDThis is the unique ID of the service principal object associated with the application.Optional
userIDThe user ID or user principal name.Optional
identityTypeThe type of identity involved. Usually mapped to incident field named 'cloudidentitytype'.

Playbook Outputs#

MSGraphUserThe Microsoft Graph Users information.unknown
MSGraphApplicationThe Microsoft Graph Application information.unknown

Playbook Image#

Cloud Credentials Rotation - Azure