Quick Overview
This workflow polls Microsoft Entra ID Protection for new high-risk risk detections, aggregates them per user, enriches them with risky-user and recent sign-in context from Microsoft Graph, then creates or updates matching alerts in TheHive and posts a summary to a Slack security channel.
How it works
- Runs every 30 minutes on a schedule.
- Queries Microsoft Graph Identity Protection for risk detections with risk level set to high from the last 20 minutes, following @odata.nextLink pagination.
- Groups detections by user and aggregates key context such as detection types, risk states, IP addresses, locations, and first/last detection timestamps.
- Retrieves additional user context from Microsoft Graph by fetching the risky user record and the user’s five most recent sign-in events.
- Correlates deterministic signals (for example privileged roles, multiple countries, confirmed compromise state, or non-compliant devices) to classify severity and build a detailed incident description.
- Queries TheHive for existing open alerts of type entra-id-risk and either updates the matching alert (by sourceRef) or creates a new alert with observables.
- Posts a formatted alert summary and TheHive reference to a chosen Slack channel.
Setup
- Create a Microsoft Entra ID (Microsoft Graph) OAuth2 credential with permissions for IdentityRiskEvent.Read.All, IdentityRiskyUser.Read.All, and AuditLog.Read.All.
- Add a TheHive 5 credential with permission to query, create, and update alerts, and ensure your TheHive instance is reachable from n8n.
- Add a Slack OAuth2 credential and select the security/SOC channel to post notifications to.
- Review and adjust the lookback filter (currently last 20 minutes) and schedule interval (every 30 minutes) to match your monitoring requirements.