Skip to content

Microsoft Sentinel integration

The Microsoft Sentinel connector provides two rule responses:

  • Notify Microsoft Sentinel writes each matched rule alert and its cited fully qualified domain names (FQDNs) to a Log Analytics table through the Azure Monitor Logs Ingestion API.
  • Detect in Microsoft Sentinel adds each lookalike domain an active alert cites to Sentinel threat intelligence as a STIX indicator that expires after seven days. Sentinel’s threat intelligence analytics rules then raise incidents when your DNS, proxy, or other logs contain the domain.

You sign in with Microsoft once and pick the Sentinel workspaces to use. Have I Been Squatted creates the table, the data collection rule, and the role assignments in each workspace for you. Each rule response then picks a workspace. Connecting Sentinel alone sends nothing.

  • A Log Analytics workspace with Microsoft Sentinel enabled, in the Azure public cloud.
  • A Microsoft Entra user who can consent to the Have I Been Squatted - Sentinel application. If your tenant does not let users consent to applications, an administrator who can grant tenant-wide consent, such as a Cloud Application Administrator, must approve it first.
  • For the user who signs in, Azure rights on the workspace’s resource group to create a table and a data collection rule: Contributor, or Log Analytics Contributor together with Monitoring Contributor.
  • To assign roles as well: Owner, User Access Administrator, or Role Based Access Control Administrator on the resource group. Without one of these, Have I Been Squatted still creates the table and data collection rule, and shows the role assignments for someone who holds such a role to make.
  • The Security Operations add-on on the Have I Been Squatted organization, and an organization admin to configure it.

Have I Been Squatted uses one multi-tenant Microsoft Entra application for this integration, separate from its other Microsoft applications. Signing in adds it to your tenant as the Have I Been Squatted - Sentinel enterprise application. It requests only delegated permissions, which act as the signed-in user and never beyond that user’s own access:

Permission API Purpose
openid, profile Microsoft identity Sign-in, to identify your tenant
User.Read Microsoft Graph Sign-in
user_impersonation Azure Service Management Set up the workspaces you pick, with your own Azure access

The Azure access is used only during setup. Have I Been Squatted keeps the token encrypted on its servers, never sends it to the browser, and deletes it when the setup run ends; a token you never use expires after about an hour. To add more workspaces later, you sign in again.

The application holds no application permissions. When deliveries run, it authenticates with its own credential and can do exactly what these Azure role assignments allow:

Response Role Scope
Notify Microsoft Sentinel Monitoring Metrics Publisher The data collection rule Have I Been Squatted creates
Detect in Microsoft Sentinel Microsoft Sentinel Contributor The Log Analytics workspace

The threat intelligence upload API requires Microsoft Sentinel Contributor at the workspace level. It is broader than uploading indicators needs, and Microsoft documents no narrower built-in role.

  1. In the app, open Connectors > Microsoft Sentinel.
  2. Select Connect with Microsoft and choose the account to sign in with.
  3. Review the requested permissions and accept them.
  4. Microsoft returns to the settings page, which runs a connection check and lists the Log Analytics workspaces your account can see.

The tenant is taken from the verified identity token of the user who signed in, never from the address bar.

The check requests a token for your tenant with the Have I Been Squatted - Sentinel application. It proves that the enterprise application exists in the tenant, not that any role is assigned; each workspace has its own test. Responses stay off until a check passes. Select Test connection to run it again.

Consent can take a few minutes to take effect, so the check that runs immediately after connecting may report missing consent. Test the connection again shortly afterward.

Result Meaning
Consent missing The tenant has no Have I Been Squatted - Sentinel enterprise application yet, or it was deleted. Test again after a few minutes, then reconnect if it persists.
Client rejected The Have I Been Squatted application credential was rejected. This is a platform problem; contact support.
Rate limited Microsoft throttled the check. Test again in a minute.
Unreachable Microsoft timed out or returned a server error. Test again later.

A failed check pauses both responses until a later check passes. Missing consent marks the connection as needing reauthorization.

After you sign in, the settings page lists the Log Analytics workspaces your account can read, with Sentinel workspaces first. Workspaces without Microsoft Sentinel are shown but cannot be selected, because Detect needs Sentinel.

Select up to five workspaces and choose Set up selected. For each workspace, Have I Been Squatted:

  1. Creates the HaveIBeenSquattedFindings_CL table, or updates it to the schema below. Retention follows the workspace default.
  2. Creates a data collection rule named hibs-findings- followed by the first 12 characters of the workspace ID, in the workspace’s resource group and region. It is a Direct rule with its own logs ingestion endpoint, declares the stream Custom-HaveIBeenSquattedFindings with the same columns, and passes rows through unchanged.
  3. Assigns the Have I Been Squatted - Sentinel enterprise application Monitoring Metrics Publisher on that data collection rule and Microsoft Sentinel Contributor on the workspace.

Setup runs in the background and usually takes a minute or two; Azure can take longer to provision a new table. The settings page shows each workspace’s progress, and setup continues after leaving the page. If setup stops before a workspace finishes, sign in again and set it up again. Every step is idempotent, so setup resumes where it stopped.

Column Type
TimeGenerated datetime
EventId string
EventType string
SchemaVersion int
FindingId string
DomainId string
LookupId string
RuleId string
RuleName string
FindingTitle string
FindingDescription string
Severity string
AlertStatus string
Fqdns dynamic

Every step is safe to repeat: setting up a workspace again finds the existing table, data collection rule, and role assignments, and repairs any that are missing. Your sign-in is deleted when the run ends, whatever its result, so sign in again to retry or to add more workspaces.

If your account can create resources but not assign roles, the workspace is added with its role assignments marked Roles pending. The settings page shows each missing assignment: the role, the data collection rule or workspace, and the application ID. Someone with Owner, User Access Administrator, or Role Based Access Control Administrator on the resource group makes them:

  1. Open the resource in the Azure portal, then Access control (IAM) > Add > Add role assignment.
  2. Select the role, then under Members select User, group, or service principal and search for Have I Been Squatted - Sentinel.
  3. Back in Have I Been Squatted, select Test on the workspace.

Role assignments can take up to 30 minutes to apply. A passing test clears the pending state.

Test on a workspace writes to it with the Have I Been Squatted application’s own credential, the same way deliveries do, because neither API has a read or dry-run call:

  • Notify sends one row with EventType connection.test and no finding. Exclude it from your own analytics with where EventType != "connection.test".
  • Detect uploads one indicator for sentinel-connection-check.haveibeensquatted.com whose validity ended before it was created, so it never matches. Repeated tests update the same indicator.

The settings page shows the result of each part:

Result Meaning
Consent missing The tenant has no Have I Been Squatted - Sentinel enterprise application. Reconnect.
Client rejected The Have I Been Squatted application credential was rejected. This is a platform problem; contact support.
Authentication Azure rejected the application’s token. Reconnect and test again.
Authorization The enterprise application lacks the role on the data collection rule or workspace, or it has not applied yet; allow 30 minutes.
Not found Azure did not find the data collection rule, or Sentinel did not find the workspace.
Rejected Azure rejected the test row or indicator.
Rate limited Azure throttled the test. Test again in a minute.
Unreachable Azure timed out or returned a server error. Test again later.
  1. Create or edit a rule and open the Response tab.
  2. Select Add action > Notify Microsoft Sentinel or Detect in Microsoft Sentinel.
  3. Select the workspace destination.
  4. Save the rule.

Workspaces are listed only after a connection check has passed. Detect needs at least one domain condition in the rule, because only cited lookalike domain records produce indicators. A rule can write to several workspaces.

One row per rule alert, with the columns above. Fqdns holds the distinct FQDNs from the records the alert cites. EventId and FindingId are the Have I Been Squatted alert ID. The Logs Ingestion API has no idempotency key, so a row is sent once and never resent after a timeout or server error; such a delivery is recorded as indeterminate. A throttled request is resent once when Azure asks to wait ten seconds or less.

For each active rule alert that cites lookalike domain records, one indicator per distinct cited domain, up to 10 per alert, in a single upload:

Field Value
id Stable per workspace and domain
pattern [domain-name:value = '<domain>']
indicator_types malicious-activity
valid_from The upload time
valid_until Seven days after the upload
description The Have I Been Squatted alert ID, the monitored domain, and the rule title
labels haveibeensquatted, lookalike-domain, and severity:<rule level>
external_references The alert ID and rule ID
Source Have I Been Squatted

Because the ID is stable, a later alert that cites the same domain updates the indicator and renews its expiry instead of adding another. Indicators that you or other sources created have other IDs and are never changed.

  • Only domains from cited domain (lookalike permutation) records are sent.
  • The monitored domain and its subdomains are never sent.
  • Email and canary evidence never produce indicators.

If Sentinel refuses some indicators, the others still apply and the delivery is recorded as partial. Sentinel indexes accepted indicators within minutes.

Have I Been Squatted stores the connected tenant ID, the connection time, the object ID of the enterprise application’s service principal in your tenant, and the time and outcome of the last connection check. For each workspace, it stores the workspace ID, name, region and resource ID, the data collection rule’s resource ID, immutable ID and logs ingestion endpoint, the state of each role assignment, and the time and outcome of the last test. For each alert and response, it records the delivery status, the event ID or the ID and domain of each indicator, refused domains, the expiry, and, when a delivery fails, a short error code. Your setup sign-in is stored encrypted only until the setup run ends. Azure response bodies are not stored.

Symptom What to do
Microsoft asks for administrator approval when you sign in Your tenant does not let users consent. Ask an administrator who can grant tenant-wide consent to approve the Have I Been Squatted - Sentinel application, then sign in again.
No workspaces are listed Your account cannot read any Log Analytics workspace. Sign in with an account that has at least Reader on the workspace.
A workspace cannot be selected Microsoft Sentinel is not enabled on it. Enable Sentinel on the workspace, then sign in again.
Setup reports that your account lacks permission Your account cannot create the table or data collection rule. Ask for Contributor, or Log Analytics Contributor and Monitoring Contributor, on the resource group.
Setup reports a rejected request Check that the subscription has the Microsoft.Insights resource provider registered, then sign in again and retry.
Setup did not finish in time Sign in again and set the workspace up again. Setup resumes where it stopped.
Roles pending on a workspace Make the role assignments shown on the settings page, wait up to 30 minutes, then select Test.
A test reports Authorization The role assignment is missing or has not applied yet. Wait up to 30 minutes and test again.
The add workspaces link asks you to sign in again The sign-in from setup has expired or was used. Sign in again; it lasts about an hour.

Earlier versions of this connector used an Entra application that you registered, or asked you to create the table, the data collection rule, and the role assignments yourself and enter their details on each rule response. Such a connection shows Reconnect required and sends nothing.

Select Connect with Microsoft to switch to automatic setup. Reconnecting removes the existing Notify and Detect responses from your rules and deletes any stored client secret. Add your workspaces, then add the responses again. If you registered your own application, delete it, or its client secret and role assignments, in Azure. Tables, data collection rules, and role assignments you created by hand keep working on their own but are no longer used; delete them once the new setup is in place.

Remove on a workspace stops rules writing to it and removes their Notify and Detect responses for that workspace. Have I Been Squatted holds no Azure access of yours at that point, so it changes nothing in Azure: the table, the data collection rule, and the role assignments stay. To remove them, in the Azure portal:

  1. On the workspace, open Access control (IAM) > Role assignments and remove Microsoft Sentinel Contributor for Have I Been Squatted - Sentinel.
  2. Delete the hibs-findings-… data collection rule, which also removes its role assignment.
  3. Delete the HaveIBeenSquattedFindings_CL table under the workspace’s Tables if you no longer need the rows in it.

Disable stops both responses and keeps the connection, the workspaces, and the rule responses. A passing connection test turns them back on.

Disconnect removes the connection, every workspace, and both responses from every rule, along with those responses’ delivery records.

Neither action deletes rows already ingested or indicators already uploaded. Indicators stop matching when they expire, within seven days.

Disconnecting does not revoke the consent, the role assignments, or the resources setup created. To remove the application’s access, remove its role assignments as described under Remove a workspace for each workspace, and delete the Have I Been Squatted - Sentinel enterprise application in the Microsoft Entra admin center. Deliveries and connection checks then fail with missing consent.

  • Azure public cloud only. Azure Government and Azure operated by 21Vianet use other endpoints and are not supported.
  • One Microsoft tenant per organization. Workspaces must be in that tenant.
  • Up to five workspaces per setup run, and the workspace list shows at most 5,000 workspaces.
  • Each delivery requests a new token and makes one ingestion request or one upload.
  • Indicators match domains only, and only in logs Sentinel collects.