Overview of Entra ID and Zscaler MDR - RC DRAFT

Prev Next

The Microsoft Entra ID Integration supports connecting Zscaler MDR with a customer’s Microsoft Entra ID environment at the tenant level.

The integration specifically focuses on Microsoft Entra ID, which is responsible for generating and managing Identity & Access Management (IAM) logs. These logs are transferred from a customer’s Microsoft Entra ID environment to Zscaler MDR using a combination of Azure services. Below is an outline of the log collection and ingestion process:

  • Diagnostic Settings: Customers configure Diagnostic Settings in Microsoft Entra ID to collect relevant logs in an Azure Log Analytics Workspace.

  • Data Export: Zscaler MDR automates the creation of Data Export settings to send collected logs from the Log Analytics Workspace to an Azure Event Hub.

  • Ingestion: The Event Hub queues and prepares the logs for downstream ingestion and analysis by Zscaler MDR.

For more information, see Integrate Microsoft Entra ID with Zscaler MDR.

Requirements

Azure Lighthouse, a service for cross-tenant management, is required for this integration to function correctly. Customers should refer to the integration documentation for more details on setting up Azure Lighthouse.

Entra ID Licensing and Associated Azure Costs

This integration is available to all customers with any level of Entra ID licensing. However, customers should be aware of potential Azure costs associated with storing logs in a Log Analytics Workspace and exporting them to Zscaler MDR. Zscaler MDR has minimized the number of tables exported to control these costs.

  • Log Analytics Data Ingestion: Charges incurred for storing logs in a Log Analytics Workspace.

  • Log Analytics Data Export: Costs associated with transferring logs from the workspace to Zscaler MDR via the Event Hub. For more information, refer to:

Comparison of Entra ID Integrations

Zscaler MDR offers multiple integrations related to Microsoft Entra ID. Here is a summary of the key differences:

  • Entra ID: The telemetry integration described in this article, which ingests and analyzes raw log data.

  • Entra ID Alerts: An older legacy integration, generally not recommended as it lacks modern parsing and detection capabilities.

  • Entra ID Identity Protection v2: A supported alert source from the Microsoft XDR Defender suite that correlates identity-related alerts with telemetry from other integrations, we recommend configuring this integration if it is included in your Microsoft licensing.

  • Entra ID Response Actions: A response integration configured through the Zscaler MDR Automate interface, enabling automated actions targeting Entra ID identities.

  • Microsoft Office 365: A separate integration that collects Office 365 audit logs. We recommend configuring the Microsoft Office 365 integration in addition to the Entra ID integration, as both collect different and important types of data.

Data Ingestion

Zscaler MDR ingests the following data from Entra ID.

Data Type

Purpose

AADManagedIdentitySignInLogs

Tracks sign-ins by managed identities within Azure.

AADServicePrincipalSignInLogs

Captures sign-ins by service principals.

AADServicePrincipalRiskEvents

Logs events related to risky behavior by service principals.

AADUserRiskEvents

Tracks risky sign-in attempts by users.

ADFSSignInLogs

Logs sign-ins using Active Directory Federation Services (ADFS).

AuditLogs

Records changes to applications, groups, users, and licensing.

SignInLogs

Tracks sign-in activity across the Azure Tenant.