Skip to content

Updated the CorrelateIPC_Unfamiliar-Atypical rule for Microsoft Entra ID Protection#14108

Merged
v-dvedak merged 8 commits into
masterfrom
v-kasghosh/issues_number/11510
May 12, 2026
Merged

Updated the CorrelateIPC_Unfamiliar-Atypical rule for Microsoft Entra ID Protection#14108
v-dvedak merged 8 commits into
masterfrom
v-kasghosh/issues_number/11510

Conversation

@v-kasghosh
Copy link
Copy Markdown
Contributor

@v-kasghosh v-kasghosh commented Apr 21, 2026

Change(s):

  • Updated the CorrelateIPC_Unfamiliar-Atypical rule for Microsoft Entra ID Protection

Reason for Change(s):

Version Updated:

  • 1.0.9
  • 3.0.4

Testing Completed:

image

@contentautomationbot
Copy link
Copy Markdown

Hello how are you I am GitHub bot
😀😀
I see that you changed templates under the detections/analytic rules folder. Did you remember to update the version of the templates you changed?
If not, and if you want customers to be aware that a new version of this template is available, please update the version property of the template you changed.

@v-atulyadav v-atulyadav added the Solution Solution specialty review needed label Apr 22, 2026
@v-kasghosh v-kasghosh marked this pull request as ready for review May 6, 2026 06:13
@v-kasghosh v-kasghosh requested review from a team as code owners May 6, 2026 06:13
@v-kasghosh v-kasghosh requested a review from a team as a code owner May 6, 2026 06:31
@v-shukore v-shukore requested a review from Copilot May 8, 2026 09:16
Copy link
Copy Markdown
Contributor

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Note

Copilot was unable to run its full agentic suite in this review.

Updates the Microsoft Entra ID Protection solution to a new version and refines the CorrelateIPC_Unfamiliar-Atypical analytic rule query logic.

Changes:

  • Added a new 3.0.4 entry to the solution release notes.
  • Updated the CorrelateIPC_Unfamiliar-Atypical analytic rule (v1.0.9) to parse Comments and filter out certain “admin” risk details.
  • Updated the KQL validation custom table schema to use AccountUPN.

Reviewed changes

Copilot reviewed 4 out of 5 changed files in this pull request and generated 3 comments.

File Description
Solutions/Microsoft Entra ID Protection/ReleaseNotes.md Adds the 3.0.4 release note entry for the updated analytic rule.
Solutions/Microsoft Entra ID Protection/Package/mainTemplate.json Version bumps and template text updates (skipped from detailed review per repo guidelines for Solutions/**/Package/**).
Solutions/Microsoft Entra ID Protection/Analytic Rules/CorrelateIPC_Unfamiliar-Atypical.yaml Updates the detection query to extract/filter RiskDetail and bumps rule version to 1.0.9.
.script/tests/KqlvalidationsTests/CustomTables/IdentityInfo.json Aligns the test schema column name with AccountUPN.

Comment thread Solutions/Microsoft Entra ID Protection/ReleaseNotes.md
Comment thread Solutions/Microsoft Entra ID Protection/ReleaseNotes.md
@v-dvedak v-dvedak merged commit eca179c into master May 12, 2026
36 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Solution Solution specialty review needed

Projects

None yet

Development

Successfully merging this pull request may close these issues.

False Positives from "Correlate Unfamiliar sign-in properties & atypical travel alerts" When Changing User Risk

5 participants