Microsoft Entra Connect Health Azure-Microsoft.ADHybridHealthService

operationNameDescriptionSampleRule
anyCatch-all for Azure-Microsoft.ADHybridHealthService rules that match the resource provider but no specific operation.NN
Microsoft.ADHybridHealthService/addsservices/actionCreate a new forest for the tenant.NN
Microsoft.ADHybridHealthService/addsservices/deleteDeletes a Service and it's servers along with Health data.NN
Microsoft.ADHybridHealthService/addsservices/servicemembers/actionAdd a server instance to the service.NN
Microsoft.ADHybridHealthService/addsservices/servicemembers/deleteDeletes a server for a given service and tenant.NN
Microsoft.ADHybridHealthService/addsservices/writeCreates or Updates the ADDomainService instance for the tenant.NN
Microsoft.ADHybridHealthService/configuration/actionUpdates Tenant Configuration.NN
Microsoft.ADHybridHealthService/configuration/writeCreates a Tenant Configuration.NN
Microsoft.ADHybridHealthService/register/actionRegisters the ADHybrid Health Service Resource Provider and enables the creation of ADHybrid Health Service resource.NN
Microsoft.ADHybridHealthService/services/actionUpdates a service instance in the tenant.NN
Microsoft.ADHybridHealthService/services/deleteDeletes a service instance in the tenant.NY
Microsoft.ADHybridHealthService/services/ipAddressAggregateSettings/writeWrites alarm thresholds for bad IPs.NN
Microsoft.ADHybridHealthService/services/monitoringconfiguration/writeAdd or updates monitoring configuration for a service.NN
Microsoft.ADHybridHealthService/services/monitoringconfigurations/writeAdd or updates monitoring configurations for a service.NN
Microsoft.ADHybridHealthService/services/reports/generateBlobUri/actionGenerates Risky IP report and returns a URI pointing to it.NN
Microsoft.ADHybridHealthService/services/servicemembers/actionCreates or updates a server instance in the service.NY
Microsoft.ADHybridHealthService/services/servicemembers/deleteDeletes a server instance in the service.NN
Microsoft.ADHybridHealthService/services/writeCreates a service instance in the tenant.NN
Microsoft.ADHybridHealthService/unregister/actionUnregisters the subscription for ADHybrid Health Service Resource Provider.NN

any: Microsoft Entra Connect Health (catch-all)

#
Namespace
Microsoft.ADHybridHealthService

Description

Catch-all for Azure-Microsoft.ADHybridHealthService rules that match the resource provider but no specific operation.

Microsoft.ADHybridHealthService/addsservices/action

#
Namespace
Microsoft.ADHybridHealthService

Description

Create a new forest for the tenant.

Microsoft.ADHybridHealthService/addsservices/delete

#
Namespace
Microsoft.ADHybridHealthService

Description

Deletes a Service and it's servers along with Health data.

Microsoft.ADHybridHealthService/addsservices/servicemembers/action

#
Namespace
Microsoft.ADHybridHealthService

Description

Add a server instance to the service.

Microsoft.ADHybridHealthService/addsservices/servicemembers/delete

#
Namespace
Microsoft.ADHybridHealthService

Description

Deletes a server for a given service and tenant.

Microsoft.ADHybridHealthService/addsservices/write

#
Namespace
Microsoft.ADHybridHealthService

Description

Creates or Updates the ADDomainService instance for the tenant.

Microsoft.ADHybridHealthService/configuration/action

#
Namespace
Microsoft.ADHybridHealthService

Description

Updates Tenant Configuration.

Microsoft.ADHybridHealthService/configuration/write

#
Namespace
Microsoft.ADHybridHealthService

Description

Creates a Tenant Configuration.

Microsoft.ADHybridHealthService/register/action

#
Namespace
Microsoft.ADHybridHealthService

Description

Registers the ADHybrid Health Service Resource Provider and enables the creation of ADHybrid Health Service resource.

Microsoft.ADHybridHealthService/services/action

#
Namespace
Microsoft.ADHybridHealthService

Description

Updates a service instance in the tenant.

Microsoft.ADHybridHealthService/services/delete

#
Namespace
Microsoft.ADHybridHealthService

Description

Deletes a service instance in the tenant.

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
CategoryValueeqadministrative3 ruleskusto, sigma
_ResourceId (kusto rule field)containsadfederationservice2 ruleskusto
azure_ad::operation_name_valueeqmicrosoft.adhybridhealthservice/services/delete2 ruleskusto, sigma
ResourceId (sigma rule field)containsadfederationservice1 rulesigma

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sigma #

  • Azure Active Directory Hybrid Health AD FS Service Delete source medium: This detection uses azureactivity logs (Administrative category) to identify the deletion of an Azure AD Hybrid health AD FS service instance in a tenant. A threat actor can create a new AD Health ADFS service and create a fake server to spoof AD FS signing logs. The health AD FS service can then be deleted after it is not longer needed via HTTP requests to Azure.T1578, T1578.003

Kusto #

Microsoft.ADHybridHealthService/services/ipAddressAggregateSettings/write

#
Namespace
Microsoft.ADHybridHealthService

Description

Writes alarm thresholds for bad IPs.

Microsoft.ADHybridHealthService/services/monitoringconfiguration/write

#
Namespace
Microsoft.ADHybridHealthService

Description

Add or updates monitoring configuration for a service.

Microsoft.ADHybridHealthService/services/monitoringconfigurations/write

#
Namespace
Microsoft.ADHybridHealthService

Description

Add or updates monitoring configurations for a service.

Microsoft.ADHybridHealthService/services/reports/generateBlobUri/action

#
Namespace
Microsoft.ADHybridHealthService

Description

Generates Risky IP report and returns a URI pointing to it.

Microsoft.ADHybridHealthService/services/servicemembers/action

#
Namespace
Microsoft.ADHybridHealthService

Description

Creates or updates a server instance in the service.

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
CategoryValueeqadministrative4 ruleskusto, sigma
_ResourceId (kusto rule field)containsadfederationservice3 ruleskusto
azure_ad::operation_name_valueeqmicrosoft.adhybridhealthservice/services/servicemembers/action3 ruleskusto, sigma
ResourceId (sigma rule field)containsadfederationservice1 rulesigma

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sigma #

  • Azure Active Directory Hybrid Health AD FS New Server source medium: This detection uses azureactivity logs (Administrative category) to identify the creation or update of a server instance in an Azure AD Hybrid health AD FS service. A threat actor can create a new AD Health ADFS service and create a fake server instance to spoof AD FS signing logs. There is no need to compromise an on-prem AD FS server. This can be done programmatically via HTTP requests to Azure.T1578

Kusto #

  • Microsoft Entra ID Hybrid Health AD FS New Server source medium: This detection uses AzureActivity logs (Administrative category) to identify the creation or update of a server instance in an Microsoft Entra ID Hybrid Health AD FS service. A threat actor can create a new AD Health ADFS service and create a fake server instance to spoof AD FS signing logs. There is no need to compromise an on-premises AD FS server. This can be done programmatically via HTTP requests to Azure. More information in this blog: https://o365blog.com/post/hybridhealthagent/T1578
  • NRT Microsoft Entra ID Hybrid Health AD FS New Server source medium: This detection uses AzureActivity logs (Administrative category) to identify the creation or update of a server instance in an Microsoft Entra ID Hybrid Health AD FS service. A threat actor can create a new AD Health ADFS service and create a fake server instance to spoof AD FS signing logs. There is no need to compromise an on-premises AD FS server. This can be done programmatically via HTTP requests to Azure. More information in this blog: https://o365blog.com/post/hybridhealthagent/T1578
  • Microsoft Entra ID Hybrid Health AD FS Suspicious Application source medium: This detection uses AzureActivity logs (Administrative category) to identify a suspicious application adding a server instance to an Microsoft Entra ID Hybrid Health AD FS service or deleting the AD FS service instance. Usually the Microsoft Entra ID Connect Health Agent application with ID cf6d7e68-f018-4e0a-a7b3-126e053fb88d and ID cb1056e2-e479-49de-ae31-7812af012ed8 is used to perform those operations.T1528, T1550↳ also matches Microsoft.ADHybridHealthService/services/delete

Microsoft.ADHybridHealthService/services/servicemembers/delete

#
Namespace
Microsoft.ADHybridHealthService

Description

Deletes a server instance in the service.

Microsoft.ADHybridHealthService/services/write

#
Namespace
Microsoft.ADHybridHealthService

Description

Creates a service instance in the tenant.

Microsoft.ADHybridHealthService/unregister/action

#
Namespace
Microsoft.ADHybridHealthService

Description

Unregisters the subscription for ADHybrid Health Service Resource Provider.

References #