Skip to product information

Entra ID High-Risk Alerts: Graph + TheHive + Slack n8n

Entra ID High-Risk Alerts: Graph + TheHive + Slack n8n

 (200+Reviews)
Regular price £45.99
Regular price £45.99 Sale price
SAVE Sold out
⬇
Instant Digital Download
∞
Unlimited Downloads
★
Lifetime Access in Your Account
🔥
128+ Sold
Popular with n8n builders
âš¡
23 people viewing
High interest right now
✅
9 added today
Fast-moving digital product
Entra ID High-Risk Alerts: Graph + TheHive + Slack n8n

Entra ID High-Risk Alerts: Graph + TheHive + Slack n8n

Regular price £45.99
Regular price £45.99 Sale price
SAVE Sold out

Catch Microsoft Entra ID Protection high-risk events fast—enriched with Graph context, tracked in TheHive, and broadcast to Slack

This n8n workflow monitors Microsoft Entra ID Protection for high-risk detections, enriches them using Microsoft Graph (risky user record + recent sign-ins), then creates or updates corresponding TheHive alerts and posts a clean summary to a selected Slack security channel.

What this workflow does

  • Runs every 30 minutes on a schedule to stay ahead of identity threats.
  • Queries Microsoft Graph Identity Protection for high risk detections from the last 20 minutes, following @odata.nextLink pagination.
  • Groups detections by user and aggregates key context (detection types, risk states, IPs, locations, and first/last detection timestamps).
  • Fetches additional enrichment from Microsoft Graph by retrieving:
    • the risky user record
    • the user’s five most recent sign-in events
  • Correlates deterministic signals (e.g., privileged roles, multiple countries, confirmed compromise state, or non-compliant devices) to classify severity and generate a detailed incident narrative.
  • Checks TheHive 5 for existing open alerts of type entra-id-risk and then:
    • updates the matching alert (by sourceRef), or
    • creates a new alert with observables.
  • Posts a formatted alert summary with the TheHive reference to a chosen Slack channel.

Use cases

  • Security teams needing near-real-time visibility into Entra ID Protection high-risk detections.
  • SaaS operators centralizing identity incident intake into TheHive while notifying analysts via Slack.
  • Automation engineers building an identity-focused SOC triage pipeline with n8n, Graph enrichment, and case management.

Technical details

  • Integrations: Microsoft Graph (IdentityRiskEvent.Read.All, IdentityRiskyUser.Read.All, AuditLog.Read.All), TheHive 5, Slack.
  • Node/tooling: if, code, merge, Slack, HTTP Request, sticky note.
View full details