Include Application in unwanted access log
jordan (CIT)
Our client deployment processes include a "tuning" period for a week at the start to review unwanted access escalations with the point of contact.
I recently had a client who wanted a copy of the Application or Client the user was attempting to use in the reported sign-in event. This is avaialble from the entra sign-in logs, but does not appear to be ingested by huntress.
This additional data can help us understand what the user was doing at the time of alert