Entra ID High-Risk Alerts: Graph + TheHive + Slack n8n
Entra ID High-Risk Alerts: Graph + TheHive + Slack n8n
Regular price
£45.99
Regular price
£45.99
Sale price
Unit price
/
per
⬇
Instant Digital Download
∞
Unlimited Downloads
★
Lifetime Access in Your Account
Couldn't load pickup availability
🔥
128+ Sold
Popular with n8n builders
âš¡
23 people viewing
High interest right now
✅
9 added today
Fast-moving digital product
Entra ID High-Risk Alerts: Graph + TheHive + Slack n8n
Regular price
£45.99
Regular price
£45.99
Sale price
Unit price
/
per
Catch Microsoft Entra ID Protection high-risk events fast—enriched with Graph context, tracked in TheHive, and broadcast to Slack
This n8n workflow monitors Microsoft Entra ID Protection for high-risk detections, enriches them using Microsoft Graph (risky user record + recent sign-ins), then creates or updates corresponding TheHive alerts and posts a clean summary to a selected Slack security channel.
What this workflow does
- Runs every 30 minutes on a schedule to stay ahead of identity threats.
- Queries Microsoft Graph Identity Protection for high risk detections from the last 20 minutes, following
@odata.nextLinkpagination. - Groups detections by user and aggregates key context (detection types, risk states, IPs, locations, and first/last detection timestamps).
- Fetches additional enrichment from Microsoft Graph by retrieving:
- the risky user record
- the user’s five most recent sign-in events
- Correlates deterministic signals (e.g., privileged roles, multiple countries, confirmed compromise state, or non-compliant devices) to classify severity and generate a detailed incident narrative.
- Checks TheHive 5 for existing open alerts of type entra-id-risk and then:
- updates the matching alert (by sourceRef), or
- creates a new alert with observables.
- Posts a formatted alert summary with the TheHive reference to a chosen Slack channel.
Use cases
- Security teams needing near-real-time visibility into Entra ID Protection high-risk detections.
- SaaS operators centralizing identity incident intake into TheHive while notifying analysts via Slack.
- Automation engineers building an identity-focused SOC triage pipeline with n8n, Graph enrichment, and case management.
Technical details
- Integrations: Microsoft Graph (IdentityRiskEvent.Read.All, IdentityRiskyUser.Read.All, AuditLog.Read.All), TheHive 5, Slack.
- Node/tooling: if, code, merge, Slack, HTTP Request, sticky note.
