Microsoft Entra Connect Health Azure-Microsoft.ADHybridHealthService
| operationName | Description | Sample | Rule |
|---|---|---|---|
| any | Catch-all for Azure-Microsoft.ADHybridHealthService rules that match the resource provider but no specific operation. | N | N |
| Microsoft.ADHybridHealthService/ | Create a new forest for the tenant. | N | N |
| Microsoft.ADHybridHealthService/ | Deletes a Service and it's servers along with Health data. | N | N |
| Microsoft.ADHybridHealthService/ | Add a server instance to the service. | N | N |
| Microsoft.ADHybridHealthService/ | Deletes a server for a given service and tenant. | N | N |
| Microsoft.ADHybridHealthService/ | Creates or Updates the ADDomainService instance for the tenant. | N | N |
| Microsoft.ADHybridHealthService/ | Updates Tenant Configuration. | N | N |
| Microsoft.ADHybridHealthService/ | Creates a Tenant Configuration. | N | N |
| Microsoft.ADHybridHealthService/ | Registers the ADHybrid Health Service Resource Provider and enables the creation of ADHybrid Health Service resource. | N | N |
| Microsoft.ADHybridHealthService/ | Updates a service instance in the tenant. | N | N |
| Microsoft.ADHybridHealthService/ | Deletes a service instance in the tenant. | N | Y |
| Microsoft.ADHybridHealthService/ | Writes alarm thresholds for bad IPs. | N | N |
| Microsoft.ADHybridHealthService/ | Add or updates monitoring configuration for a service. | N | N |
| Microsoft.ADHybridHealthService/ | Add or updates monitoring configurations for a service. | N | N |
| Microsoft.ADHybridHealthService/ | Generates Risky IP report and returns a URI pointing to it. | N | N |
| Microsoft.ADHybridHealthService/ | Creates or updates a server instance in the service. | N | Y |
| Microsoft.ADHybridHealthService/ | Deletes a server instance in the service. | N | N |
| Microsoft.ADHybridHealthService/ | Creates a service instance in the tenant. | N | N |
| Microsoft.ADHybridHealthService/ | Unregisters the subscription for ADHybrid Health Service Resource Provider. | N | N |
any: Microsoft Entra Connect Health (catch-all)
#Description
Catch-all for Azure-Microsoft.ADHybridHealthService rules that match the resource provider but no specific operation.
Microsoft.ADHybridHealthService/addsservices/action
#Description
Create a new forest for the tenant.
Microsoft.ADHybridHealthService/addsservices/delete
#Description
Deletes a Service and it's servers along with Health data.
Microsoft.ADHybridHealthService/addsservices/servicemembers/action
#Description
Add a server instance to the service.
Microsoft.ADHybridHealthService/addsservices/servicemembers/delete
#Description
Deletes a server for a given service and tenant.
Microsoft.ADHybridHealthService/addsservices/write
#Description
Creates or Updates the ADDomainService instance for the tenant.
Microsoft.ADHybridHealthService/configuration/action
#Description
Updates Tenant Configuration.
Microsoft.ADHybridHealthService/configuration/write
#Description
Creates a Tenant Configuration.
Microsoft.ADHybridHealthService/register/action
#Description
Registers the ADHybrid Health Service Resource Provider and enables the creation of ADHybrid Health Service resource.
Microsoft.ADHybridHealthService/services/action
#Description
Updates a service instance in the tenant.
Microsoft.ADHybridHealthService/services/delete
#Description
Deletes a service instance in the tenant.
Common Indicators #
Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.
| Field | Kind | Value | Rules | Vendors |
|---|---|---|---|---|
CategoryValue | eq | administrative | 3 rules | kusto, sigma |
_ResourceId (kusto rule field) | contains | adfederationservice | 2 rules | kusto |
azure_ad::operation_name_value | eq | microsoft.adhybridhealthservice/services/delete | 2 rules | kusto, sigma |
ResourceId (sigma rule field) | contains | adfederationservice | 1 rule | sigma |
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Sigma #
T1578, T1578.003Kusto #
T1578, T1578.003T1528, T1550↳ also matches Microsoft.ADHybridHealthService/services/servicemembers/action
Microsoft.ADHybridHealthService/services/ipAddressAggregateSettings/write
#Description
Writes alarm thresholds for bad IPs.
Microsoft.ADHybridHealthService/services/monitoringconfiguration/write
#Description
Add or updates monitoring configuration for a service.
Microsoft.ADHybridHealthService/services/monitoringconfigurations/write
#Description
Add or updates monitoring configurations for a service.
Microsoft.ADHybridHealthService/services/reports/generateBlobUri/action
#Description
Generates Risky IP report and returns a URI pointing to it.
Microsoft.ADHybridHealthService/services/servicemembers/action
#Description
Creates or updates a server instance in the service.
Common Indicators #
Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.
| Field | Kind | Value | Rules | Vendors |
|---|---|---|---|---|
CategoryValue | eq | administrative | 4 rules | kusto, sigma |
_ResourceId (kusto rule field) | contains | adfederationservice | 3 rules | kusto |
azure_ad::operation_name_value | eq | microsoft.adhybridhealthservice/services/servicemembers/action | 3 rules | kusto, sigma |
ResourceId (sigma rule field) | contains | adfederationservice | 1 rule | sigma |
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Sigma #
T1578Kusto #
T1578T1578T1528, T1550↳ also matches Microsoft.ADHybridHealthService/services/delete
Microsoft.ADHybridHealthService/services/servicemembers/delete
#Description
Deletes a server instance in the service.
Microsoft.ADHybridHealthService/services/write
#Description
Creates a service instance in the tenant.
Microsoft.ADHybridHealthService/unregister/action
#Description
Unregisters the subscription for ADHybrid Health Service Resource Provider.